From 73ee3a37cbb6e8ae42915eee3e5df5a918cd2348 Mon Sep 17 00:00:00 2001
From: Rohan Garg <7731512+rohangarg@users.noreply.github.com>
Date: Wed, 23 Nov 2022 11:35:33 +0530
Subject: [PATCH] Port CVE suppressions from 24.0.1 (#13415)
* Suppress jackson-databind CVE-2022-42003 and CVE-2022-42004
(cherry picked from commit 1f4d892c9a2dbc3ce6df1481fd4c6d242ba0ea8d)
* Suppress CVEs
(cherry picked from commit ed55baa8fa7d7f914a0addabb072d9ed47e1cd9f)
* Suppress vulnerabilities from druid-website package
(cherry picked from commit c0fb364f8049d53cd704e414e2ffeab6c49b012e)
* Add more suppressions for website package
(cherry picked from commit 9bba569ebd52c5480bf4219c420ed78eb053701f)
---
owasp-dependency-check-suppressions.xml | 100 +++++++++++++++++++++++-
1 file changed, 97 insertions(+), 3 deletions(-)
diff --git a/owasp-dependency-check-suppressions.xml b/owasp-dependency-check-suppressions.xml
index 6ffb3b9f2e1f..a09ed507cc83 100644
--- a/owasp-dependency-check-suppressions.xml
+++ b/owasp-dependency-check-suppressions.xml
@@ -88,6 +88,17 @@
^pkg:maven/net\.minidev/accessors\-smart@.*$
CVE-2021-27568
+
+
+
+ ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$
+ CVE-2022-42003
+ CVE-2022-42004
+
@@ -209,6 +220,15 @@
CVE-2018-1320
CVE-2019-0205
+
+
+
+ ^pkg:maven/org\.codehaus\.jettison/jettison@1.*$
+ CVE-2022-40149
+ CVE-2022-40150
+
CVE-2019-12399
CVE-2018-17196
+
+
+ ^pkg:maven/org\.apache\.kafka/kafka\-clients@.*$
+ CVE-2022-34917
+
+
+ ^pkg:maven/org\.ini4j/ini4j@.*$
+ CVE-2022-41404
-
CVE-2022-36364
+ CVE-2022-39135
+
+
+
+ ^pkg:maven/org\.apache\.calcite/calcite\-core@.*$
+ CVE-2020-13955
-
CVE-2022-31197
-
1084597
+
+
+ ^pkg:npm/d3\-color@.*$
+ 1084597
+
+
+
+ ^pkg:maven/com\.google\.protobuf/protobuf\-java@.*$
+ CVE-2022-3171
+
+
+
+ ^pkg:maven/com\.google\.protobuf/protobuf\-java\-util@.*$
+ CVE-2022-3171
+
+
+
+ ^pkg:npm/ansi\-regex@.*$
+ 1084697
+ CVE-2021-3807
+
+
+
+ ^pkg:npm/glob\-parent@.*$
+ 1081884
+ CVE-2020-28469
+
+
+
+ ^pkg:npm/minimatch@.*$
+ 1084765
+
+
+
+ ^pkg:npm/y18n@.*$
+ 1070209
+ CVE-2020-7774
+