Skip to content

CVE suppression#12535

Merged
abhishekagarwal87 merged 1 commit intoapache:masterfrom
AmatyaAvadhanula:feature-cve_suppression_18_05_2022
May 19, 2022
Merged

CVE suppression#12535
abhishekagarwal87 merged 1 commit intoapache:masterfrom
AmatyaAvadhanula:feature-cve_suppression_18_05_2022

Conversation

@AmatyaAvadhanula
Copy link
Copy Markdown
Contributor

@AmatyaAvadhanula AmatyaAvadhanula commented May 18, 2022

Suppress

  1. Ambari -> ambari-metrics-common-2.7.0.0.0.jar -> CVE-2021-4104, CVE-2020-9493, CVE-2022-23307, CVE-2022-23305, CVE-2022-23302
  • The CVEs are being suppressed since Ambari hasn't been updated in a long time. Might consider eliminating this dependency in the future
  1. GSON -> gson-*.jar -> CVE-2022-25647
  1. Jackson -> *jackson-*.jar -> CVE-2020-36518
  1. Jedis -> jedis-2.9.0.jar -> CVE-2021-32626, CVE-2022-24735
  • The Jedis vulnerabilities are due to lua script execution in Redis. This is not applicable to druid
  1. Solr -> solr-solrj-7.7.1.jar -> CVE-2021-44548
  • This CVE only affects Windows and is not applicable to druid

Copy link
Copy Markdown
Contributor

@cryptoe cryptoe left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM !!

@abhishekagarwal87 abhishekagarwal87 added this to the 0.23.0 milestone May 19, 2022
@abhishekagarwal87 abhishekagarwal87 merged commit 215b90d into apache:master May 19, 2022
@abhishekagarwal87
Copy link
Copy Markdown
Contributor

Thank you @AmatyaAvadhanula. can you also create a backport PR?

AmatyaAvadhanula added a commit to AmatyaAvadhanula/druid that referenced this pull request May 19, 2022
@AmatyaAvadhanula
Copy link
Copy Markdown
Contributor Author

Thank you @AmatyaAvadhanula. can you also create a backport PR?

@abhishekagarwal87 Please find it at #12543

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants