From e2dce46a69a14ca9357dd54d00e2b7ec39824b50 Mon Sep 17 00:00:00 2001 From: Kashif Faraz Date: Thu, 20 Oct 2022 21:37:25 +0530 Subject: [PATCH 1/4] Suppress jackson-databind CVE-2022-42003 and CVE-2022-42004 (cherry picked from commit 1f4d892c9a2dbc3ce6df1481fd4c6d242ba0ea8d) --- owasp-dependency-check-suppressions.xml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/owasp-dependency-check-suppressions.xml b/owasp-dependency-check-suppressions.xml index 6ffb3b9f2e1f..f9ff2f7963e1 100644 --- a/owasp-dependency-check-suppressions.xml +++ b/owasp-dependency-check-suppressions.xml @@ -88,6 +88,17 @@ ^pkg:maven/net\.minidev/accessors\-smart@.*$ CVE-2021-27568 + + + + ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$ + CVE-2022-42003 + CVE-2022-42004 + From b9ae56eb401234845d81b051bb6489eb1d0e40e8 Mon Sep 17 00:00:00 2001 From: Kashif Faraz Date: Wed, 2 Nov 2022 14:33:46 +0530 Subject: [PATCH 2/4] Suppress CVEs (cherry picked from commit ed55baa8fa7d7f914a0addabb072d9ed47e1cd9f) Conflicts: owasp-dependency-check-suppressions.xml --- owasp-dependency-check-suppressions.xml | 58 +++++++++++++++++++++++-- 1 file changed, 55 insertions(+), 3 deletions(-) diff --git a/owasp-dependency-check-suppressions.xml b/owasp-dependency-check-suppressions.xml index f9ff2f7963e1..4afeee84aa50 100644 --- a/owasp-dependency-check-suppressions.xml +++ b/owasp-dependency-check-suppressions.xml @@ -220,6 +220,15 @@ CVE-2018-1320 CVE-2019-0205 + + + + ^pkg:maven/org\.codehaus\.jettison/jettison@1.*$ + CVE-2022-40149 + CVE-2022-40150 + CVE-2019-12399 CVE-2018-17196 + + + ^pkg:maven/org\.apache\.kafka/kafka\-clients@.*$ + CVE-2022-34917 + + + ^pkg:maven/org\.ini4j/ini4j@.*$ + CVE-2022-41404 - CVE-2022-36364 + CVE-2022-39135 + + + + ^pkg:maven/org\.apache\.calcite/calcite\-core@.*$ + CVE-2020-13955 - CVE-2022-31197 - 1084597 + + + ^pkg:npm/d3\-color@.*$ + 1084597 + + + + ^pkg:maven/com\.google\.protobuf/protobuf\-java@.*$ + CVE-2022-3171 + + + + ^pkg:maven/com\.google\.protobuf/protobuf\-java\-util@.*$ + CVE-2022-3171 + From e280427bfce243f3aa05153dadf27bc67fd8dcec Mon Sep 17 00:00:00 2001 From: Kashif Faraz Date: Sat, 5 Nov 2022 11:19:21 +0530 Subject: [PATCH 3/4] Suppress vulnerabilities from druid-website package (cherry picked from commit c0fb364f8049d53cd704e414e2ffeab6c49b012e) --- owasp-dependency-check-suppressions.xml | 28 +++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/owasp-dependency-check-suppressions.xml b/owasp-dependency-check-suppressions.xml index 4afeee84aa50..db72a1d6e982 100644 --- a/owasp-dependency-check-suppressions.xml +++ b/owasp-dependency-check-suppressions.xml @@ -729,4 +729,32 @@ ^pkg:maven/com\.google\.protobuf/protobuf\-java\-util@.*$ CVE-2022-3171 + + + ^pkg:npm/ansi\-regex@.*$ + 1084697 + + + + ^pkg:npm/glob\-parent@.*$ + 1081884 + + + + ^pkg:npm/minimatch@.*$ + 1084765 + + + + ^pkg:npm/y18n@.*$ + 1070209 + From a9ec5ecbc02aeef947802d0bb769c36c677ed270 Mon Sep 17 00:00:00 2001 From: Kashif Faraz Date: Sat, 5 Nov 2022 23:14:18 +0530 Subject: [PATCH 4/4] Add more suppressions for website package (cherry picked from commit 9bba569ebd52c5480bf4219c420ed78eb053701f) --- owasp-dependency-check-suppressions.xml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/owasp-dependency-check-suppressions.xml b/owasp-dependency-check-suppressions.xml index db72a1d6e982..a09ed507cc83 100644 --- a/owasp-dependency-check-suppressions.xml +++ b/owasp-dependency-check-suppressions.xml @@ -735,6 +735,7 @@ ]]> ^pkg:npm/ansi\-regex@.*$ 1084697 + CVE-2021-3807 ^pkg:npm/glob\-parent@.*$ 1081884 + CVE-2020-28469 ^pkg:npm/y18n@.*$ 1070209 + CVE-2020-7774