File tree 2 files changed +19
-12
lines changed
2 files changed +19
-12
lines changed Original file line number Diff line number Diff line change 1
1
<?xml version =" 1.0" encoding =" UTF-8" ?>
2
2
<suppressions xmlns =" https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd" >
3
- <suppress >
4
- <notes ><![CDATA[
3
+ <suppress >
4
+ <notes ><![CDATA[
5
5
https://nvd.nist.gov/vuln/detail/CVE-2020-8022 marks it as vulnerable as it has version ranges without a lower bound for both tomcat 8 and 9.
6
6
Reported at https://github.com/jeremylong/DependencyCheck/issues/3661.
7
7
]]> </notes >
8
- <packageUrl regex =" true" >^pkg:maven/org\.apache\.tomcat/tomcat\-jasper\-el@.*$</packageUrl >
9
- <cve >CVE-2020-8022</cve >
10
- </suppress >
11
- <suppress >
12
- <notes ><![CDATA[
13
- file name: tomcat-jasper-el-10.0.21.jar
8
+ <packageUrl regex =" true" >^pkg:maven/org\.apache\.tomcat/tomcat\-jasper\-el@.*$</packageUrl >
9
+ <cve >CVE-2020-8022</cve >
10
+ </suppress >
11
+ <suppress >
12
+ <notes ><![CDATA[
13
+ file name: tomcat-jasper-el-10.0.21.jar
14
+ ]]> </notes >
15
+ <packageUrl regex =" true" >^pkg:maven/org\.apache\.tomcat/tomcat\-jasper\-el@.*$</packageUrl >
16
+ <cve >CVE-2022-34305</cve ><!-- only affects examples web app (https://lists.apache.org/thread/k04zk0nq6w57m72w5gb0r6z9ryhmvr4k) -->
17
+ </suppress >
18
+ <suppress >
19
+ <notes ><![CDATA[
20
+ file name: snakeyaml-1.32.jar, 1.32 has the CVE issue fixed, reported at https://github.com/jeremylong/DependencyCheck/issues/4839
14
21
]]> </notes >
15
- <packageUrl regex =" true" >^pkg:maven/org\.apache\.tomcat/tomcat\-jasper\-el @.*$</packageUrl >
16
- < cve >CVE-2022-34305</ cve > <!-- only affects examples web app (https://lists.apache.org/thread/k04zk0nq6w57m72w5gb0r6z9ryhmvr4k) -- >
17
- </suppress >
22
+ <packageUrl regex =" true" >^pkg:maven/org\.yaml/snakeyaml @.*$</packageUrl >
23
+ < vulnerabilityName >CVE-2022-38752</ vulnerabilityName >
24
+ </suppress >
18
25
</suppressions >
Original file line number Diff line number Diff line change 114
114
<dependency >
115
115
<groupId >org.yaml</groupId >
116
116
<artifactId >snakeyaml</artifactId >
117
- <version >1.28 </version >
117
+ <version >1.32 </version >
118
118
</dependency >
119
119
<!-- due to https://bugs.openjdk.java.net/browse/JDK-8231581 OOTB JRE is not sufficient -->
120
120
<dependency >
You can’t perform that action at this time.
0 commit comments