Skip to content

Commit 85e198f

Browse files
authored
2 new CVEs popped in the druid34 release process (#18227)
Proposing to supress both as the druid dependencies that they are coming from have no versions that fix them
1 parent 16ff547 commit 85e198f

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

owasp-dependency-check-suppressions.xml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -142,6 +142,7 @@
142142
<cve>CVE-2024-47561</cve> <!-- This seems to be a legitimate vulnerability. We would need to go to hadoop-client 3.4 which required aws sdk v2 dependency work to finish -->
143143
<cve>CVE-2024-29131</cve> <!-- This seems to be a legitimate vulnerability. We would need to go to hadoop-client 3.4 which required aws sdk v2 dependency work to finish -->
144144
<cve>CVE-2024-22201</cve> <!-- This seems to be a legitimate vulnerability. We would need to go to a hadoop-client which was not yet released -->
145+
<cve>CVE-2025-52999</cve> <!-- This is vulneraability in all versions of hadoop-client-runtime and has not been fixed by hadoop yet -->
145146
</suppress>
146147

147148
<!-- those are false positives, no other tools report any of those CVEs in the hadoop package -->
@@ -192,6 +193,7 @@
192193
<cve>CVE-2022-34917</cve>
193194
<cve>CVE-2023-25194</cve>
194195
<cve>CVE-2024-31141</cve>
196+
<cve>CVE-2025-27818</cve> <!-- not fixed in any version of ranger dependency. I don't think it is exploitable in Druid within this extension -->
195197
</suppress>
196198

197199
<suppress>

0 commit comments

Comments
 (0)