Skip to content

Commit b987d5d

Browse files
committed
Add more detailed, improved notes regarding CVE-2017-10355.
1 parent 0b0f86c commit b987d5d

File tree

1 file changed

+5
-3
lines changed

1 file changed

+5
-3
lines changed

suppressions.xml

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -11,13 +11,15 @@
1111
We are suppressing this because it is believed by the ESAPI and AntiSamy teams that it is a false positive.
1212
Dependency Check itself doesn't flag this and neither does Snyk. Dependency Check reports it because it is reported
1313
directly by Sonatype's OSS Index. For futher details, see
14-
https://ossindex.sonatype.org/vulnerability/sonatype-2017-0348?component-type=maven&component-name=xerces%2FxercesImpl
14+
https://ossindex.sonatype.org/vulnerability/CVE-2017-10355?component-type=maven&component-name=xerces/xercesImpl
15+
and https://github.com/OSSIndex/vulns/issues/328#issuecomment-1287175491.
1516
1617
OSS Index seems to have the wrong CPE. They have 'cpe:2.3:a:xerces:xercesImpl:2.12.2:*:*:*:*:*:*:*', whereas the CPE IDs
1718
associated with NVD are 'cpe:2.3:a:apache:xerces-j:2.12.2:*:*:*:*:*:*:*' and
18-
'cpe:2.3:a:apache:xerces2_java:2.12.2:*:*:*:*:*:*:*'.
19+
'cpe:2.3:a:apache:xerces2_java:2.12.2:*:*:*:*:*:*:*'. (Note: as of Nov 2024, none of the CPEs even mention Xerces, but
20+
rather seem to only refer to the JREs.)
1921
20-
Note also that this has been reported as GitHub issue #a 4614
22+
Note also that this has been reported as GitHub issue # 4614 for OWASP Dependency Check. For details, see
2123
https://github.com/jeremylong/DependencyCheck/issues/4614
2224
]]></notes>
2325
<sha1>f051f988aa2c9b4d25d05f95742ab0cc3ed789e2</sha1>

0 commit comments

Comments
 (0)