From 388d5ecf78de51cbe81a7076a2b23250bff7b8fa Mon Sep 17 00:00:00 2001
From: Tejaswini Bandlamudi <96047043+tejaswini-imply@users.noreply.github.com>
Date: Thu, 24 Aug 2023 19:28:55 +0530
Subject: [PATCH] Fix reported CVEs (#14882)
Suppress CVEs from dependencies with no available fix or false positives
hadoop-annotations: CVE-2022-25168, CVE-2021-33036
hadoop-client-runtime: CVE-2023-1370, CVE-2023-37475
okio: CVE-2023-3635
Upgrade grpc version to fix CVE-2023-33953
---
extensions-contrib/opentelemetry-emitter/pom.xml | 2 +-
owasp-dependency-check-suppressions.xml | 15 +++++++++++++++
2 files changed, 16 insertions(+), 1 deletion(-)
diff --git a/extensions-contrib/opentelemetry-emitter/pom.xml b/extensions-contrib/opentelemetry-emitter/pom.xml
index 2f1cd06055c..58415e7ea3e 100644
--- a/extensions-contrib/opentelemetry-emitter/pom.xml
+++ b/extensions-contrib/opentelemetry-emitter/pom.xml
@@ -39,7 +39,7 @@
32.0.1-jre
- 1.41.3
+ 1.57.2
diff --git a/owasp-dependency-check-suppressions.xml b/owasp-dependency-check-suppressions.xml
index 1eb7c5a72d7..4fcf5605334 100644
--- a/owasp-dependency-check-suppressions.xml
+++ b/owasp-dependency-check-suppressions.xml
@@ -359,6 +359,9 @@
]]>
CVE-2022-45855
CVE-2022-42009
+
+ CVE-2022-25168
+ CVE-2021-33036
CVE-2023-25613
CVE-2023-2976
+
+ CVE-2023-1370
+ CVE-2023-37475
@@ -785,4 +792,12 @@
^pkg:maven/.*/.*@.*$
CVE-2021-4277
+
+
+
+ ^pkg:maven/com\.squareup\.okio/okio@1..*$
+ CVE-2023-3635
+