Skip to content

Commit

Permalink
suppress cve (apache#16997)
Browse files Browse the repository at this point in the history
  • Loading branch information
LakshSingla authored Sep 4, 2024
1 parent e28424e commit b698440
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions owasp-dependency-check-suppressions.xml
Original file line number Diff line number Diff line change
Expand Up @@ -699,4 +699,13 @@
]]></notes>
<vulnerabilityName>CVE-2024-25638</vulnerabilityName>
</suppress>
<suppress>
<!-- The CVE is also not applicable to xz-java because it does not implement xzgrep and therefore is not vulnerable
~ to the filename validation problem. Druid does not use xzgrep but this CVE is popping up because the CPE matches the
~ Java package too. -->
<notes><![CDATA[
file name: xz-1.9.jar
]]></notes>
<vulnerabilityName>CVE-2022-1271</vulnerabilityName>
</suppress>
</suppressions>

0 comments on commit b698440

Please sign in to comment.