File tree Expand file tree Collapse file tree 1 file changed +11
-0
lines changed
Expand file tree Collapse file tree 1 file changed +11
-0
lines changed Original file line number Diff line number Diff line change 70807080 <packageUrl regex =" true" >^pkg:maven/(?!.*org\.eclipse\.equinox\.p2).*$</packageUrl >
70817081 <cve >CVE-2021-41033</cve >
70827082 </suppress >
7083+ <suppress base =" true" >
7084+ <notes ><![CDATA[
7085+ FP per issue #7854 - protobuf-java has its own dedicated CPE at cpe:/a:google:protobuf-java - other language vulns are
7086+ managed within the core CPE for those based on native implementations.
7087+ Correct CPE vulns: https://nvd.nist.gov/vuln/search#/nvd/home?cpeFilterMode=applicability&cpeName=cpe:2.3:a:*:protobuf-java:*:*:*:*:*:*:*:*&resultType=records
7088+ Wrong CPE vulns: https://nvd.nist.gov/vuln/search#/nvd/home?cpeFilterMode=applicability&cpeName=cpe:2.3:a:*:protobuf:*:*:*:*:*:*:*:*&resultType=records
7089+ ]]> </notes >
7090+ <packageUrl regex =" true" >^pkg:maven/com\.google\.protobuf/protobuf-.*@.*$</packageUrl >
7091+ <cpe >cpe:/a:protobuf:protobuf:</cpe >
7092+ <cpe >cpe:/a:google:protobuf:</cpe >
7093+ </suppress >
70837094</suppressions >
You can’t perform that action at this time.
0 commit comments