From 388d5ecf78de51cbe81a7076a2b23250bff7b8fa Mon Sep 17 00:00:00 2001 From: Tejaswini Bandlamudi <96047043+tejaswini-imply@users.noreply.github.com> Date: Thu, 24 Aug 2023 19:28:55 +0530 Subject: [PATCH] Fix reported CVEs (#14882) Suppress CVEs from dependencies with no available fix or false positives hadoop-annotations: CVE-2022-25168, CVE-2021-33036 hadoop-client-runtime: CVE-2023-1370, CVE-2023-37475 okio: CVE-2023-3635 Upgrade grpc version to fix CVE-2023-33953 --- extensions-contrib/opentelemetry-emitter/pom.xml | 2 +- owasp-dependency-check-suppressions.xml | 15 +++++++++++++++ 2 files changed, 16 insertions(+), 1 deletion(-) diff --git a/extensions-contrib/opentelemetry-emitter/pom.xml b/extensions-contrib/opentelemetry-emitter/pom.xml index 2f1cd06055c..58415e7ea3e 100644 --- a/extensions-contrib/opentelemetry-emitter/pom.xml +++ b/extensions-contrib/opentelemetry-emitter/pom.xml @@ -39,7 +39,7 @@ 32.0.1-jre - 1.41.3 + 1.57.2 diff --git a/owasp-dependency-check-suppressions.xml b/owasp-dependency-check-suppressions.xml index 1eb7c5a72d7..4fcf5605334 100644 --- a/owasp-dependency-check-suppressions.xml +++ b/owasp-dependency-check-suppressions.xml @@ -359,6 +359,9 @@ ]]> CVE-2022-45855 CVE-2022-42009 + + CVE-2022-25168 + CVE-2021-33036 CVE-2023-25613 CVE-2023-2976 + + CVE-2023-1370 + CVE-2023-37475 @@ -785,4 +792,12 @@ ^pkg:maven/.*/.*@.*$ CVE-2021-4277 + + + + ^pkg:maven/com\.squareup\.okio/okio@1..*$ + CVE-2023-3635 +