[Aikido] Fix 1 critical issue in spring-security-core, spring-security-config, spring-security-web and 47 other issues - #7
Open
aikido-autofix[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Thank you for submitting a pull request to the WebGoat!
Summary / Description
Upgrade dependencies to fix critical RCE and arbitrary code execution vulnerabilities in XStream, Tomcat, Spring Security, Thymeleaf, and Jackson.
Security Impact — CVE vulnerabilities fixed by this PR
✅ 48 CVEs resolved by this upgrade, including 15 critical 🚨 CVEs
This PR will resolve the following CVEs:
Breaking Changes & Upgrade Impact
✅ No breaking changes for: org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-util, org.apache.tomcat.embed:tomcat-embed-websocket, org.springframework.security:spring-security-core, org.springframework.security:spring-security-config, org.springframework.security:spring-security-web, org.thymeleaf:thymeleaf-spring5, org.thymeleaf:thymeleaf-spring6, org.thymeleaf:thymeleaf, com.fasterxml.jackson.core:jackson-core
Fix Details / Technical Implementation
🤖 Remediation details
Fix multiple critical/high/medium security vulnerabilities in Jackson, XStream, Tomcat, Spring Security, and Thymeleaf dependencies
Short summary
This PR remediates security vulnerabilities affecting five vulnerable package families declared or transitively resolved in the root
pom.xml:com.thoughtworks.xstream:xstream,com.fasterxml.jackson.core:jackson-databind,com.fasterxml.jackson.core:jackson-core, Apache Tomcat (tomcat-embed-core,tomcat-embed-websocket,tomcat-coyote,tomcat-catalina,tomcat-util),org.springframework.security(spring-security-core,spring-security-config,spring-security-web), andorg.thymeleaf(thymeleaf,thymeleaf-spring5,thymeleaf-spring6). Three edits were made to the rootpom.xml: thespring-boot-starter-parentversion was bumped, thexstream.versionproperty was updated, and ajackson-bom.versionproperty override was added.com.thoughtworks.xstream:xstream
Declared directly in
<dependencyManagement>via the${xstream.version}property and consumed as a direct dependency. Thexstream.versionproperty was updated from1.4.5to1.4.20in<properties>, which is the minimum version that addresses the full range of XStream CVEs listed in this task (the highest patched floor across all advisories is1.4.20, required by CVE-2022-41966 and CVE-2022-40151).org.apache.tomcat.embed:tomcat-embed-core / org.apache.tomcat.embed:tomcat-embed-websocket / org.apache.tomcat:tomcat-coyote / org.apache.tomcat:tomcat-catalina / org.apache.tomcat:tomcat-util
All Tomcat artifacts are resolved transitively through
spring-boot-starter-parent, which manages them via${tomcat.version}. Bumping the parent from3.5.6to3.5.16advancestomcat.versionfrom10.1.46to10.1.55, satisfying the patched floor required by the Tomcat CVEs in this task (highest floor:10.1.55).org.springframework.security:spring-security-core / org.springframework.security:spring-security-config / org.springframework.security:spring-security-web
All Spring Security artifacts are resolved transitively through
spring-boot-starter-parentvia${spring-security.version}. The parent bump from3.5.6to3.5.16advancesspring-security.versionfrom6.5.5to6.5.11, satisfying the>= 6.5.9patched floor required by CVE-2026-22732.org.thymeleaf:thymeleaf / org.thymeleaf:thymeleaf-spring5 / org.thymeleaf:thymeleaf-spring6
Thymeleaf is resolved transitively through
spring-boot-starter-parentvia${thymeleaf.version}. The project previously declared a local<thymeleaf.version>3.1.2.RELEASE</thymeleaf.version>property that overrode the parent-managed version, holding it below the patched floor. The parent bump to3.5.16advances the managedthymeleaf.versionto3.1.5.RELEASE(satisfying the>= 3.1.5.RELEASEfloor for CVE-2026-40477, CVE-2026-41901, and CVE-2026-40478), and the now-redundant local override property was removed so the parent's patched version takes effect.com.fasterxml.jackson.core:jackson-databind / com.fasterxml.jackson.core:jackson-core
Both Jackson core artifacts are resolved transitively through
spring-boot-starter-parent, which importscom.fasterxml.jackson:jackson-bomusing the${jackson-bom.version}property. The parent3.5.16managesjackson-bom.version=2.21.4, which is below the2.21.5patched floor required by CVE-2026-59889 and GHSA-mhm7-754m-9p8w. The next Spring Boot release managing>= 2.21.5is4.0.8, a prohibited major-version jump, so a targeted<jackson-bom.version>2.21.5</jackson-bom.version>property override was added to<properties>in the rootpom.xml. This overrides the BOM import in the parent, causing all Jackson artifacts to resolve at2.21.5.Version changes
org.springframework.boot:spring-boot-starter-parent3.5.63.5.16com.thoughtworks.xstream:xstream1.4.51.4.20xstream.versionpropertyorg.apache.tomcat.embed:tomcat-embed-core10.1.4610.1.55spring-boot-starter-parent3.5.16)org.apache.tomcat.embed:tomcat-embed-websocket10.1.4610.1.55spring-boot-starter-parent3.5.16)org.apache.tomcat:tomcat-coyote10.1.4610.1.55spring-boot-starter-parent3.5.16)org.apache.tomcat:tomcat-catalina10.1.4610.1.55spring-boot-starter-parent3.5.16)org.apache.tomcat:tomcat-util10.1.4610.1.55spring-boot-starter-parent3.5.16)org.springframework.security:spring-security-core6.5.56.5.11spring-boot-starter-parent3.5.16)org.springframework.security:spring-security-config6.5.56.5.11spring-boot-starter-parent3.5.16)org.springframework.security:spring-security-web6.5.56.5.11spring-boot-starter-parent3.5.16)org.thymeleaf:thymeleaf3.1.2.RELEASE3.1.5.RELEASEorg.thymeleaf:thymeleaf-spring63.1.2.RELEASE3.1.5.RELEASEcom.fasterxml.jackson.core:jackson-databind2.21.42.21.5jackson-bom.versionproperty override (parent major bump prohibited)com.fasterxml.jackson.core:jackson-core2.21.42.21.5jackson-bom.versionproperty override (same BOM as jackson-databind)