From 73ee3a37cbb6e8ae42915eee3e5df5a918cd2348 Mon Sep 17 00:00:00 2001 From: Rohan Garg <7731512+rohangarg@users.noreply.github.com> Date: Wed, 23 Nov 2022 11:35:33 +0530 Subject: [PATCH] Port CVE suppressions from 24.0.1 (#13415) * Suppress jackson-databind CVE-2022-42003 and CVE-2022-42004 (cherry picked from commit 1f4d892c9a2dbc3ce6df1481fd4c6d242ba0ea8d) * Suppress CVEs (cherry picked from commit ed55baa8fa7d7f914a0addabb072d9ed47e1cd9f) * Suppress vulnerabilities from druid-website package (cherry picked from commit c0fb364f8049d53cd704e414e2ffeab6c49b012e) * Add more suppressions for website package (cherry picked from commit 9bba569ebd52c5480bf4219c420ed78eb053701f) --- owasp-dependency-check-suppressions.xml | 100 +++++++++++++++++++++++- 1 file changed, 97 insertions(+), 3 deletions(-) diff --git a/owasp-dependency-check-suppressions.xml b/owasp-dependency-check-suppressions.xml index 6ffb3b9f2e1f..a09ed507cc83 100644 --- a/owasp-dependency-check-suppressions.xml +++ b/owasp-dependency-check-suppressions.xml @@ -88,6 +88,17 @@ ^pkg:maven/net\.minidev/accessors\-smart@.*$ CVE-2021-27568 + + + + ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$ + CVE-2022-42003 + CVE-2022-42004 + @@ -209,6 +220,15 @@ CVE-2018-1320 CVE-2019-0205 + + + + ^pkg:maven/org\.codehaus\.jettison/jettison@1.*$ + CVE-2022-40149 + CVE-2022-40150 + CVE-2019-12399 CVE-2018-17196 + + + ^pkg:maven/org\.apache\.kafka/kafka\-clients@.*$ + CVE-2022-34917 + + + ^pkg:maven/org\.ini4j/ini4j@.*$ + CVE-2022-41404 - CVE-2022-36364 + CVE-2022-39135 + + + + ^pkg:maven/org\.apache\.calcite/calcite\-core@.*$ + CVE-2020-13955 - CVE-2022-31197 - 1084597 + + + ^pkg:npm/d3\-color@.*$ + 1084597 + + + + ^pkg:maven/com\.google\.protobuf/protobuf\-java@.*$ + CVE-2022-3171 + + + + ^pkg:maven/com\.google\.protobuf/protobuf\-java\-util@.*$ + CVE-2022-3171 + + + + ^pkg:npm/ansi\-regex@.*$ + 1084697 + CVE-2021-3807 + + + + ^pkg:npm/glob\-parent@.*$ + 1081884 + CVE-2020-28469 + + + + ^pkg:npm/minimatch@.*$ + 1084765 + + + + ^pkg:npm/y18n@.*$ + 1070209 + CVE-2020-7774 +