You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Accept the risk for DoS Attack for now and apply dependabot fixes as they arrive (then remove this)
CVE-2022-25857
# resource exhaustion attack on jackson-databind, a transitive dependency of problem-spring-web-starter (api) remove when problem-spring-web-starter updates dependency to 2.14.0-rc1 or greater
CVE-2022-42003
CVE-2022-42004
# Accept the risk as a transitive dependency of mockserver and so only used for tests remove when upgrade mockserver > 5.14.0 (as yet unrelease)
CVE-2022-42889
# Even the latest version of springboot-starter-web 3.0.2 have transitive dependencies: tomcat-embed-core-9.0.68.jar and spring-web-5.3.23.jar with these issues