From 50cda9a2e6edfad281ad827f116f56d103d58977 Mon Sep 17 00:00:00 2001 From: exceptionfactory Date: Sat, 1 Apr 2023 18:02:38 -0500 Subject: [PATCH] NIFI-11371 Upgraded Ranger from 2.3.0 to 2.4.0 - Updated Elasticsearch client false positive vulnerability suppressions for new Ranger transitive dependencies Signed-off-by: Pierre Villard This closes #7109. --- nifi-dependency-check-maven/suppressions.xml | 13 +++++++++---- pom.xml | 2 +- 2 files changed, 10 insertions(+), 5 deletions(-) diff --git a/nifi-dependency-check-maven/suppressions.xml b/nifi-dependency-check-maven/suppressions.xml index e348670685..83c36fae39 100644 --- a/nifi-dependency-check-maven/suppressions.xml +++ b/nifi-dependency-check-maven/suppressions.xml @@ -106,17 +106,17 @@ Elasticsearch Server vulnerabilities do not apply to Elasticsearch Plugin - ^pkg:maven/org\.elasticsearch\.plugin/.*?@7.6.0$ + ^pkg:maven/org\.elasticsearch\.plugin/.*?@7.*$ ^cpe:/a:elastic.*$ Elasticsearch Server vulnerabilities do not apply to elasticsearch-core - ^pkg:maven/org\.elasticsearch/elasticsearch\-core@7.6.0$ + ^pkg:maven/org\.elasticsearch/elasticsearch\-core@7.*$ ^cpe:/a:elastic.*$ Elasticsearch Server vulnerabilities do not apply to elasticsearch - ^pkg:maven/org\.elasticsearch/elasticsearch@7.6.0$ + ^pkg:maven/org\.elasticsearch/elasticsearch@7.*$ ^cpe:/a:elastic.*$ @@ -129,9 +129,14 @@ ^pkg:maven/org\.elasticsearch/elasticsearch.*$ CVE-2020-7014 + + CVE-2021-22145 applies to Elasticsearch Server not client libraries + ^pkg:maven/org\.elasticsearch/elasticsearch@.*$ + CVE-2021-22145 + Elasticsearch Server vulnerabilities do not apply to elasticsearch libraries - ^pkg:maven/org\.elasticsearch/elasticsearch\-.*?@7.6.0$ + ^pkg:maven/org\.elasticsearch/elasticsearch\-.*?@7.*$ ^cpe:/a:elastic.*$ diff --git a/pom.xml b/pom.xml index b1c0003ecb..0416019679 100644 --- a/pom.xml +++ b/pom.xml @@ -119,7 +119,7 @@ 1.71 1.17.6 2.0.7 - 2.3.0 + 2.4.0 9.4.50.v20221201 2.14.2 1.11.1