Skip to content

[Aikido] Fix 6 security issues in org.apache.maven.plugins:maven-dependency-plugin, ch.qos.logback:logback-core, ch.qos.logback:logback-classic and 2 more#67

Closed
aikido-autofix[bot] wants to merge 1 commit intomasterfrom
fix/aikido-security-update-packages-10057704-fMF5
Closed

[Aikido] Fix 6 security issues in org.apache.maven.plugins:maven-dependency-plugin, ch.qos.logback:logback-core, ch.qos.logback:logback-classic and 2 more#67
aikido-autofix[bot] wants to merge 1 commit intomasterfrom
fix/aikido-security-update-packages-10057704-fMF5

Conversation

@aikido-autofix
Copy link

This pull request addresses identified vulnerabilities and implements the necessary fixes to strengthen our security posture. Please review and approve so we can merge these changes promptly and reduce potential risk.

Thanks , The security team.

This PR will resolve the following CVEs:

CVE ID Severity Description
CVE-2022-45688
HIGH
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
CVE-2023-5072
HIGH
Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
CVE-2025-48924
MEDIUM
Uncontrolled Recursion vulnerability in Apache Commons Lang.

This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.

The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inpu
CVE-2025-11226
MEDIUM
ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program e...
AIKIDO-2025-10694
MEDIUM
Affected versions of this package do not properly validate the logback.xml configuration file when both the Janino library and the Spring Framework are present on the classpath. An attacker can execute arbitrary code by compromising an existing configuration file or injecting a malicious environme...
CVE-2020-13956
MEDIUM
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

@aikido-autofix aikido-autofix bot requested a review from a team as a code owner November 11, 2025 14:13
@aikido-autofix aikido-autofix bot added the aikido Label created by Aikido AutoFix label Nov 11, 2025
@sonarqubecloud
Copy link

@aikido-autofix aikido-autofix bot closed this Nov 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aikido Label created by Aikido AutoFix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants