From 6c6cb99b3808ea76f56c14899691c48ee5756ad9 Mon Sep 17 00:00:00 2001 From: exceptionfactory Date: Tue, 14 Jun 2022 15:51:22 -0500 Subject: [PATCH] NIFI-10118 Upgraded OWASP Dependency Check from 7.1.0 to 7.1.1 This closes #6127 Signed-off-by: David Handermann --- nifi-dependency-check-maven/suppressions.xml | 35 ++++++++++++++++++++ pom.xml | 2 +- 2 files changed, 36 insertions(+), 1 deletion(-) diff --git a/nifi-dependency-check-maven/suppressions.xml b/nifi-dependency-check-maven/suppressions.xml index 9b1b2cdf2e..a48534c8f8 100644 --- a/nifi-dependency-check-maven/suppressions.xml +++ b/nifi-dependency-check-maven/suppressions.xml @@ -59,4 +59,39 @@ ^pkg:maven/org\.apache\.twill/twill\-zookeeper@.*$ cpe:/a:apache:zookeeper + + H2 1.4.200 is shaded and repackaged without vulnerable components in nifi-h2-database for migration + pkg:maven/com.h2database/h2@1.4.200 + ^CVE.*$ + + + H2 2 is not vulnerable to CVE-2018-14335 + ^pkg:maven/com\.h2database/h2@2.*$ + CVE-2018-14335 + + + Jetty apache-jsp is not part of Apache Tomcat server + pkg:maven/org.mortbay.jasper/apache-jsp@8.5.70 + cpe:/a:apache:tomcat + + + CVE-2016-1000027 does not apply to Spring Web 5.3.20 and later + ^pkg:maven/org\.springframework/spring\-web@.*$ + CVE-2016-1000027 + + + CVE-2020-5408 does not apply to Spring Security Crypto 5.7.1 and later + ^pkg:maven/org\.springframework\.security/spring\-security\-crypto@.*$ + CVE-2020-5408 + + + Spring Security Kerberos Core is an extension of the Spring Security project + ^pkg:maven/org\.springframework\.security\.kerberos/spring\-security\-kerberos.*$ + cpe:/a:vmware:spring_security + + + Servlet API 2.5 does not include Jetty Server vulnerabilities + ^pkg:maven/org\.mortbay\.jetty/servlet\-api@.*$ + ^cpe:.*$ + diff --git a/pom.xml b/pom.xml index 2a3bf2e828..add3eaa21d 100644 --- a/pom.xml +++ b/pom.xml @@ -1245,7 +1245,7 @@ org.owasp dependency-check-maven - 7.1.0 + 7.1.1 false