Skip to content

Commit 1458a47

Browse files
Suppressions cleanup CVE-2021-29425 (Again)
Removing suppression entry for listed cve. commons-io has been updated beyond the 2.6 vulnerability. Duplication of commit 770f80c Snuck back in while tracking down and testing log4j1.x cves
1 parent 112ef50 commit 1458a47

File tree

1 file changed

+0
-12
lines changed

1 file changed

+0
-12
lines changed

suppressions.xml

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -109,18 +109,6 @@ MISSING Security Bulletin content!
109109
<cve>CVE-2022-23302</cve>
110110
</suppress>
111111
-->
112-
<suppress>
113-
<notes><![CDATA[
114-
FIXME: Once we switch to Java 8 as the minimal JDK, update commons-io to the latest and delete this.
115-
116-
This CVE is path traversal issue in FileNameUtils.normalize(). That class is not used directly or indirectly
117-
by ESAPI. We are required to use an older version of Commons-IO because of a direct dependency on Antisamy.
118-
119-
file name: commons-io-2.6.jar
120-
]]></notes>
121-
<packageUrl regex="true">^pkg:maven/commons\-io/commons\-io@.*$</packageUrl>
122-
<cve>CVE-2021-29425</cve>
123-
</suppress>
124112
<suppress>
125113
<notes><![CDATA[
126114
ESAPI does not use this jar directly. It is a transitive dependency of AntiSamy and (as per Dave Wichers on

0 commit comments

Comments
 (0)