Skip to content

Story #15307: update swagger api version#3724

Open
bbenaissa wants to merge 1 commit into
developfrom
story_15307_update_swagger_api_version
Open

Story #15307: update swagger api version#3724
bbenaissa wants to merge 1 commit into
developfrom
story_15307_update_swagger_api_version

Conversation

@bbenaissa

Copy link
Copy Markdown
Collaborator

Description

Update internal version declared on Swagger API

Contributeur

  • VAS (Vitam Accessible en Service)

@bbenaissa bbenaissa added this to the IT 169 milestone May 6, 2026
@bbenaissa bbenaissa self-assigned this May 6, 2026
@bbenaissa bbenaissa added bug Something isn't working small pr embarquant peu de changements et à review rapide, ne nécessitant qu'un reviewer labels May 6, 2026
@bbenaissa bbenaissa marked this pull request as ready for review May 6, 2026 12:07
@bbenaissa bbenaissa force-pushed the story_15307_update_swagger_api_version branch from f574ff3 to 0997f88 Compare May 6, 2026 12:08
@vitam-prg

vitam-prg commented May 6, 2026

Copy link
Copy Markdown
Collaborator

Logo
Checkmarx One – Scan Summary & Detailscb28bfe2-7422-46cc-85b6-c7bfa17638b1


New Issues (13) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 HIGH CVE-2026-33750 Npm-brace-expansion-2.0.2
detailsRecommended version: 2.0.3
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.13, 2.0.0 prior to 2.0.3, 3...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 HIGH CVE-2026-33750 Npm-brace-expansion-1.1.12
detailsRecommended version: 1.1.13
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.13, 2.0.0 prior to 2.0.3, 3...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
3 HIGH CVE-2026-33750 Npm-brace-expansion-5.0.4
detailsRecommended version: 5.0.5
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.13, 2.0.0 prior to 2.0.3, 3...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
4 HIGH CVE-2026-41907 Npm-uuid-11.1.0
detailsRecommended version: 11.1.1
Description: uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. 11.0.0 prior to 11.1.1, 12.0.0 prior to 12.0.1, 13.0.0 prior to 13.0.1, v3, v5, and v...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
5 MEDIUM CVE-2026-40895 Npm-follow-redirects-1.15.11
detailsRecommended version: 1.16.0
Description: follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to versio...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
6 MEDIUM Parameter_Tampering api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 239
detailsMethod getUser at line 239 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java gets user input from element embe...
Attack Vector
7 MEDIUM Parameter_Tampering api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 301
detailsMethod logout at line 301 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java gets user input from element authT...
Attack Vector
8 MEDIUM Parameter_Tampering api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CustomerController.java: 199
detailsMethod create at line 199 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CustomerController.java gets user input from element ...
Attack Vector
9 MEDIUM Parameter_Tampering api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 221
detailsMethod getUsersByEmail at line 221 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java gets user input from elem...
Attack Vector
10 MEDIUM Parameter_Tampering api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CustomerController.java: 199
detailsMethod create at line 199 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CustomerController.java gets user input from element ...
Attack Vector
11 MEDIUM Parameter_Tampering api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CustomerController.java: 199
detailsMethod create at line 199 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CustomerController.java gets user input from element ...
Attack Vector
12 MEDIUM Parameter_Tampering api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 301
detailsMethod logout at line 301 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java gets user input from element authT...
Attack Vector
13 MEDIUM Parameter_Tampering api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/TenantController.java: 130
detailsMethod create at line 130 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/TenantController.java gets user input from element dt...
Attack Vector

Fixed Issues (265) Great job! The following issues were fixed in this Pull Request
Severity Issue Source File / Package
CRITICAL CVE-2019-17571 Maven-log4j:log4j-1.2.17
CRITICAL CVE-2022-23305 Maven-log4j:log4j-1.2.17
CRITICAL CVE-2022-28890 Maven-org.apache.jena:jena-core-2.11.2
CRITICAL CVE-2024-38821 Maven-org.springframework.security:spring-security-web-6.2.1
CRITICAL CVE-2025-14813 Maven-org.bouncycastle:bcprov-jdk18on-1.77
CRITICAL CVE-2025-41243 Maven-org.springframework.cloud:spring-cloud-gateway-server-4.3.0
CRITICAL CVE-2026-22732 Maven-org.springframework.security:spring-security-web-6.5.8
CRITICAL CVE-2026-22732 Maven-org.springframework.security:spring-security-web-6.2.1
HIGH CVE-2017-9096 Maven-com.lowagie:itext-2.1.7
HIGH CVE-2021-39239 Maven-org.apache.jena:jena-core-2.11.2
HIGH CVE-2021-4104 Maven-log4j:log4j-1.2.17
HIGH CVE-2022-23302 Maven-log4j:log4j-1.2.17
HIGH CVE-2022-23307 Maven-log4j:log4j-1.2.17
HIGH CVE-2023-26464 Maven-log4j:log4j-1.2.17
HIGH CVE-2024-22233 Maven-org.springframework:spring-core-6.1.2
HIGH CVE-2024-22234 Maven-org.springframework.security:spring-security-core-6.2.1
HIGH CVE-2024-22234 Maven-org.springframework.security:spring-security-web-6.2.1
HIGH CVE-2024-22234 Maven-org.springframework.security:spring-security-cas-6.2.1
HIGH CVE-2024-22243 Maven-org.springframework:spring-web-6.1.2
HIGH CVE-2024-22257 Maven-org.springframework.security:spring-security-core-6.2.1
HIGH CVE-2024-22259 Maven-org.springframework:spring-web-6.1.2
HIGH CVE-2024-22262 Maven-org.springframework:spring-web-6.1.2
HIGH CVE-2024-29371 Maven-org.bitbucket.b_c:jose4j-0.9.4
HIGH CVE-2024-38816 Maven-org.springframework:spring-webmvc-6.1.2
HIGH CVE-2024-38819 Maven-org.springframework:spring-webmvc-6.1.2
HIGH CVE-2024-57699 Maven-net.minidev:json-smart-2.5.0
HIGH CVE-2025-22228 Maven-org.springframework.security:spring-security-crypto-6.2.1
HIGH CVE-2025-22235 Maven-org.springframework.boot:spring-boot-actuator-autoconfigure-3.2.1
HIGH CVE-2025-24970 Maven-io.netty:netty-handler-4.1.104.Final
HIGH CVE-2025-41249 Maven-org.springframework:spring-core-6.1.2
HIGH CVE-2025-41253 Maven-org.springframework.cloud:spring-cloud-gateway-server-4.3.0
HIGH CVE-2025-48734 Maven-commons-beanutils:commons-beanutils-1.9.4
HIGH CVE-2025-55163 Maven-io.netty:netty-codec-http2-4.1.104.Final
HIGH CVE-2026-22731 Maven-org.springframework.boot:spring-boot-starter-actuator-3.5.11
HIGH CVE-2026-22733 Maven-org.springframework.boot:spring-boot-starter-actuator-3.5.11
HIGH CVE-2026-24400 Maven-org.assertj:assertj-core-3.24.2
HIGH CVE-2026-27727 Maven-com.mchange:mchange-commons-java-0.2.15
HIGH CVE-2026-33870 Maven-io.netty:netty-codec-http-4.1.104.Final
HIGH CVE-2026-33870 Maven-io.netty:netty-codec-http-4.1.131.Final
HIGH CVE-2026-33871 Maven-io.netty:netty-codec-http2-4.1.131.Final
HIGH CVE-2026-33871 Maven-io.netty:netty-codec-http2-4.1.104.Final
HIGH CVE-2026-5598 Maven-org.bouncycastle:bcprov-jdk18on-1.77
HIGH Cx78f40514-81ff Maven-commons-collections:commons-collections-3.2.2
HIGH Cxfa47c4e4-5ef9 Maven-com.fasterxml.jackson.core:jackson-core-2.16.1
MEDIUM CVE-2023-33201 Maven-org.bouncycastle:bcprov-jdk15on-1.70
MEDIUM CVE-2023-33202 Maven-org.bouncycastle:bcprov-jdk15on-1.70
MEDIUM CVE-2024-12798 Maven-ch.qos.logback:logback-core-1.4.14
MEDIUM CVE-2024-12798 Maven-ch.qos.logback:logback-classic-1.4.14
MEDIUM CVE-2024-29025 Maven-io.netty:netty-codec-http-4.1.104.Final
MEDIUM CVE-2024-29857 Maven-org.bouncycastle:bcprov-jdk18on-1.77
MEDIUM CVE-2024-29857 Maven-org.bouncycastle:bcprov-jdk15on-1.70
MEDIUM CVE-2024-30171 Maven-org.bouncycastle:bcprov-jdk15on-1.70
MEDIUM CVE-2024-30171 Maven-org.bouncycastle:bcprov-jdk18on-1.77
MEDIUM CVE-2024-30172 Maven-org.bouncycastle:bcpkix-jdk18on-1.77
MEDIUM CVE-2024-30172 Maven-org.bouncycastle:bcprov-jdk15on-1.70
MEDIUM CVE-2024-30172 Maven-org.bouncycastle:bcprov-jdk18on-1.77
MEDIUM CVE-2024-38809 Maven-org.springframework:spring-web-6.1.2
MEDIUM CVE-2024-38827 Maven-org.springframework.security:spring-security-web-6.2.1
MEDIUM CVE-2024-38827 Maven-org.springframework.security:spring-security-cas-6.2.1
MEDIUM CVE-2024-38827 Maven-org.springframework.security:spring-security-crypto-6.2.1
MEDIUM CVE-2024-38827 Maven-org.springframework.security:spring-security-core-6.2.1
MEDIUM CVE-2024-38827 Maven-org.springframework.security:spring-security-config-6.2.1
MEDIUM CVE-2024-47535 Maven-io.netty:netty-common-4.1.104.Final
MEDIUM CVE-2025-11226 Maven-ch.qos.logback:logback-core-1.4.14
MEDIUM CVE-2025-41234 Maven-org.springframework:spring-web-6.1.2
MEDIUM CVE-2025-41242 Maven-org.springframework:spring-webmvc-6.1.2
MEDIUM CVE-2025-46392 Maven-commons-configuration:commons-configuration-1.10
MEDIUM CVE-2025-48924 Maven-commons-lang:commons-lang-2.6
MEDIUM CVE-2025-48924 Maven-org.apache.commons:commons-lang3-3.14.0
MEDIUM CVE-2025-53864 Maven-com.nimbusds:nimbus-jose-jwt-9.37.3
MEDIUM CVE-2025-58057 Maven-io.netty:netty-codec-http2-4.1.104.Final
MEDIUM CVE-2025-58057 Maven-io.netty:netty-codec-http-4.1.104.Final
MEDIUM CVE-2025-58057 Maven-io.netty:netty-codec-4.1.104.Final
MEDIUM CVE-2025-67735 Maven-io.netty:netty-codec-http-4.1.104.Final
MEDIUM CVE-2025-7962 Maven-org.eclipse.angus:jakarta.mail-2.0.2
MEDIUM CVE-2025-8885 Maven-org.bouncycastle:bcprov-jdk18on-1.77
MEDIUM CVE-2025-8916 Maven-org.bouncycastle:bcprov-jdk18on-1.77
MEDIUM CVE-2025-8916 Maven-org.bouncycastle:bcpkix-jdk18on-1.77
MEDIUM Parameter_Tampering api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CustomerController.java: 199
MEDIUM Privacy_Violation api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java: 85
MEDIUM Privacy_Violation api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java: 175
LOW CVE-2024-12801 Maven-ch.qos.logback:logback-core-1.4.14
LOW CVE-2024-38820 Maven-org.springframework:spring-context-6.1.2
LOW CVE-2024-38820 Maven-org.springframework:spring-context-support-6.1.2
LOW CVE-2024-38820 Maven-org.springframework:spring-beans-6.1.2
LOW CVE-2024-38820 Maven-org.springframework:spring-test-6.1.2
LOW CVE-2024-38820 Maven-org.springframework:spring-jms-6.1.2
LOW CVE-2024-38820 Maven-org.springframework:spring-jdbc-6.1.2
LOW CVE-2024-38820 Maven-org.springframework:spring-webmvc-6.1.2
LOW CVE-2024-38820 Maven-org.springframework:spring-web-6.1.2
LOW CVE-2024-38820 Maven-org.springframework:spring-expression-6.1.2
LOW CVE-2024-38820 Maven-org.springframework:spring-core-6.1.2
LOW CVE-2025-22233 Maven-org.springframework:spring-context-6.1.2
LOW CVE-2025-58056 Maven-io.netty:netty-codec-http-4.1.104.Final
LOW CVE-2026-1225 Maven-ch.qos.logback:logback-classic-1.4.14
LOW CVE-2026-1225 Maven-ch.qos.logback:logback-core-1.4.14
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/GroupController.java: 195
LOW Log_Forging api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 309
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 235
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 238
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 239
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 236
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 237
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 235
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 303
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 302
LOW Log_Forging api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 309
LOW Log_Forging api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 309
LOW Log_Forging api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 309
LOW Log_Forging api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 309
LOW Log_Forging api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 309
LOW Log_Forging api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 309
LOW Log_Forging api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 309
LOW Log_Forging cas/cas-server/src/main/java/fr/gouv/vitamui/cas/authentication/LoginPwdAuthenticationHandler.java: 195
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CustomerController.java: 199
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CustomerController.java: 210
LOW Log_Forging api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/rest/CasController.java: 266

More results are available on the CxOne platform


Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

@bbenaissa bbenaissa changed the title Story_15307: update swagger api version Story #15307: update swagger api version May 6, 2026
servers:
- url: https://dev.vitamui.com:8083
description: Generated server url
- url: https://dev.vitamui.com:8083

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bizarre le formatage du yaml, habituellement on met pas 3 espaces après un -

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working small pr embarquant peu de changements et à review rapide, ne nécessitant qu'un reviewer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants