Skip to content

Commit a9615e2

Browse files
committed
add suppressions for relevant projects
1 parent 718c626 commit a9615e2

File tree

4 files changed

+142
-0
lines changed

4 files changed

+142
-0
lines changed
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
3+
<suppress>
4+
<notes><![CDATA[
5+
file name: instrumentation-logback-0.14.2.jar
6+
]]></notes>
7+
<packageUrl regex="true">^pkg:maven/org\.glowroot\.instrumentation/instrumentation\-logback@.*$</packageUrl>
8+
<cve>CVE-2017-5929</cve>
9+
</suppress>
10+
</suppressions>
Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
3+
<suppress>
4+
<notes><![CDATA[
5+
file name: jackson-databind-2.8.11.3.jar
6+
Dependency of spring-boot-starter-web.
7+
No XML parsing/databinding used in our starter implementation.
8+
]]></notes>
9+
<packageUrl regex="true">^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$</packageUrl>
10+
<cve>CVE-2018-1000873</cve>
11+
<cve>CVE-2018-14719</cve>
12+
<cve>CVE-2018-14720</cve>
13+
<cve>CVE-2018-14721</cve>
14+
<cve>CVE-2018-19360</cve>
15+
<cve>CVE-2018-19361</cve>
16+
<cve>CVE-2018-19362</cve>
17+
<cve>CVE-2019-12086</cve>
18+
<cve>CVE-2019-12384</cve>
19+
<cve>CVE-2019-12814</cve>
20+
</suppress>
21+
<suppress>
22+
<notes><![CDATA[
23+
file name: tomcat-embed-websocket-8.5.40.jar
24+
Dependency of spring-boot-starter-web.
25+
Not applicable to our starter implementation.
26+
]]></notes>
27+
<packageUrl regex="true">^pkg:maven/org\.apache\.tomcat\.embed/tomcat\-embed\-websocket@.*$</packageUrl>
28+
<cve>CVE-2019-10072</cve>
29+
</suppress>
30+
<suppress>
31+
<notes><![CDATA[
32+
file name: tomcat-embed-core-8.5.40.jar
33+
Dependency of spring-boot-starter-web.
34+
Not applicable to our starter implementation.
35+
]]></notes>
36+
<packageUrl regex="true">^pkg:maven/org\.apache\.tomcat\.embed/tomcat\-embed\-core@.*$</packageUrl>
37+
<cve>CVE-2019-10072</cve>
38+
</suppress>
39+
</suppressions>
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
3+
<suppress>
4+
<notes><![CDATA[
5+
file name: spring-boot-autoconfigure-1.4.0.RELEASE.jar
6+
Independent of our usage.
7+
]]></notes>
8+
<packageUrl regex="true">^pkg:maven/org\.springframework\.boot/spring\-boot\-autoconfigure@.*$</packageUrl>
9+
<cve>CVE-2017-8046</cve>
10+
<cve>CVE-2018-1196</cve>
11+
</suppress>
12+
<suppress>
13+
<notes><![CDATA[
14+
file name: spring-boot-1.4.0.RELEASE.jar
15+
Same as autoconfigure
16+
]]></notes>
17+
<packageUrl regex="true">^pkg:maven/org\.springframework\.boot/spring\-boot@.*$</packageUrl>
18+
<cve>CVE-2017-8046</cve>
19+
<cve>CVE-2018-1196</cve>
20+
</suppress>
21+
</suppressions>
Lines changed: 72 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,72 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
3+
<suppress>
4+
<notes><![CDATA[
5+
file name: xwork-2.0.4.jar
6+
This is only used for API interfaces to provide com.microsoft.applicationinsights.web.struts.RequestNameInterceptor.
7+
No OGNL parsing; independent of XSS vector.
8+
]]></notes>
9+
<packageUrl regex="true">^pkg:maven/com\.opensymphony/xwork@.*$</packageUrl>
10+
<cve>CVE-2007-4556</cve>
11+
<cve>CVE-2008-6504</cve>
12+
<cve>CVE-2011-1772</cve>
13+
</suppress>
14+
<suppress>
15+
<notes><![CDATA[
16+
file name: ognl-2.6.11.jar
17+
This is only included because it's a dependency of xwork-*.jar.
18+
No OGNL parsing used.
19+
]]></notes>
20+
<packageUrl regex="true">^pkg:maven/opensymphony/ognl@.*$</packageUrl>
21+
<cve>CVE-2016-3093</cve>
22+
</suppress>
23+
<suppress>
24+
<notes><![CDATA[
25+
file name: spring-webmvc-3.1.0.RELEASE.jar
26+
Required for interfaces to implement com.microsoft.applicationinsights.web.spring.RequestNameHandlerInterceptorAdapter.
27+
XSS does not apply. Not related to directory traversal.
28+
]]></notes>
29+
<packageUrl regex="true">^pkg:maven/org\.springframework/spring\-webmvc@.*$</packageUrl>
30+
<vulnerabilityName>CVE-2014-1904</vulnerabilityName>
31+
<vulnerabilityName>CVE-2016-9878</vulnerabilityName>
32+
</suppress>
33+
<suppress>
34+
<notes><![CDATA[
35+
file name: spring-web-3.1.0.RELEASE.jar
36+
Dependency of spring-webmvc
37+
Usage is independent of springs XML parsing.
38+
]]></notes>
39+
<packageUrl regex="true">^pkg:maven/org\.springframework/spring\-web@.*$</packageUrl>
40+
<vulnerabilityName>CVE-2013-4152</vulnerabilityName>
41+
<vulnerabilityName>CVE-2014-0054</vulnerabilityName>
42+
<vulnerabilityName>CVE-2014-0225</vulnerabilityName>
43+
</suppress>
44+
<suppress>
45+
<notes><![CDATA[
46+
file name: spring-core-3.1.0.RELEASE.jar
47+
Dependency of spring-webmvc.
48+
Classes from this jar are not used.
49+
]]></notes>
50+
<packageUrl regex="true">^pkg:maven/org\.springframework/spring\-core@.*$</packageUrl>
51+
<cve>CVE-2013-4152</cve>
52+
<cve>CVE-2013-6429</cve>
53+
<cve>CVE-2013-7315</cve>
54+
<cve>CVE-2014-0054</cve>
55+
<cve>CVE-2014-0225</cve>
56+
<cve>CVE-2014-1904</cve>
57+
<vulnerabilityName>CVE-2014-3578</vulnerabilityName>
58+
<cve>CVE-2014-3625</cve>
59+
<cve>CVE-2016-9878</cve>
60+
<cve>CVE-2018-1270</cve>
61+
<cve>CVE-2018-1271</cve>
62+
<cve>CVE-2018-1272</cve>
63+
</suppress>
64+
<suppress>
65+
<notes><![CDATA[
66+
file name: cdi-api-1.1.jar
67+
This CVE is JBoss specific. Not explicitly used by our code.
68+
]]></notes>
69+
<packageUrl regex="true">^pkg:maven/javax\.enterprise/cdi\-api@.*$</packageUrl>
70+
<cve>CVE-2014-8122</cve>
71+
</suppress>
72+
</suppressions>

0 commit comments

Comments
 (0)