-
Notifications
You must be signed in to change notification settings - Fork 3.7k
[owasp] Suppress ZooKeeper 3.8.0 vulnerabilities #14630
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
lhotari
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Would it be possible to target specific vulnerabilities? Ignoring all would cause it to ignore all new vulnerabilities too.
|
We released 3.8.0 last week and the owasp checker passed (I actually cancelled one RC due to a owasp check failure) I am not aware of any security issue in ZooKeeper Please explain more |
eolivelli
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We should remove that exclusion at all.
There is no reported CVE against Apache ZooKeeper 3.8.0
|
I get this output For example |
|
I checked and ZK doesn't contain the mentioned libraries. I don't know how it is the process for that but is a ZooKeeper problem. For now I think we can keep the specific vulnerabilities; actually they are wrong (at a first glance at the ZK repo) so it makes sense to suppress them. btw they are already suppressed now, this will unblock the CI |
|
in the ZK project we added these exclusions due to false positives: So it is fine to add the same exclusions here |
eolivelli
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
the approach is good to me, I left some comments
|
/pulsarbot rerun-failure-checks |
2 similar comments
|
/pulsarbot rerun-failure-checks |
|
/pulsarbot rerun-failure-checks |
(cherry picked from commit 752abd9)
(cherry picked from commit 752abd9)
Motivation
After the ZK upgrade the OWASP check fails because ZK has known vulnerability. The owasp suppression aims ZK 3.6.2.
Modifications
no-need-doc