Skip to content

Suppress CVEs#14291

Merged
abhishekagarwal87 merged 14 commits intoapache:masterfrom
tejaswini-imply:fix-flagged-cve-issues
Jul 10, 2023
Merged

Suppress CVEs#14291
abhishekagarwal87 merged 14 commits intoapache:masterfrom
tejaswini-imply:fix-flagged-cve-issues

Conversation

@tejaswini-imply
Copy link
Copy Markdown
Member

@tejaswini-imply tejaswini-imply commented May 16, 2023

Security vulnerabilities check Cron job failure - https://github.com/apache/druid/actions/runs/4976066408/jobs/8903803838

Comment thread owasp-dependency-check-suppressions.xml Outdated
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we need better reasoning here. Yes, they are shaded but it could still be a problem though?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have gone through the Hadoop repository and found no instance of usage of com.google.common.io.FileBackedOutputStream which is responsible for CVE-2023-2976. I'll update the description.

@tejaswini-imply tejaswini-imply force-pushed the fix-flagged-cve-issues branch from 1254502 to 47cc31f Compare July 6, 2023 04:57
Comment thread owasp-dependency-check-suppressions.xml Outdated
https://github.com/FasterXML/jackson-databind/issues/3328
-->
<cve>CVE-2021-46877</cve>
<!-- according to jackson community, this is not a security issue, see https://github.com/FasterXML/jackson-databind/issues/3972#issuecomment-1596193098, https://github.com/jeremylong/DependencyCheck/issues/5779 -->
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
<!-- according to jackson community, this is not a security issue, see https://github.com/FasterXML/jackson-databind/issues/3972#issuecomment-1596193098, https://github.com/jeremylong/DependencyCheck/issues/5779 -->
<!-- According to jackson community, this is not a security issue, see https://github.com/FasterXML/jackson-databind/issues/3972#issuecomment-1596193098, https://github.com/jeremylong/DependencyCheck/issues/5779 -->

Comment thread owasp-dependency-check-suppressions.xml Outdated
Comment on lines +858 to +860
<!--
~ TODO: Update guava to any version after 29.0
-->
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

let's remove this.

@tejaswini-imply
Copy link
Copy Markdown
Member Author

Thanks for the review @abhishekagarwal87. I have addressed your comments in the latest commit.

@abhishekagarwal87 abhishekagarwal87 added this to the 27.0 milestone Jul 10, 2023
@abhishekagarwal87 abhishekagarwal87 merged commit c3f84f9 into apache:master Jul 10, 2023
abhishekagarwal87 pushed a commit that referenced this pull request Jul 11, 2023
Address various CVEs by upgrading dependencies or adding suppression with a justification
sergioferragut pushed a commit to sergioferragut/druid that referenced this pull request Jul 21, 2023
Address various CVEs by upgrading dependencies or adding suppression with a justification
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants