Skip to content

Commit 4264df8

Browse files
committed
Update OWASP dependency check, onderdruk CVE-2022-45688
1 parent 54e0d26 commit 4264df8

File tree

1 file changed

+14
-11
lines changed

1 file changed

+14
-11
lines changed

.mvn/owasp-suppression.xml

+14-11
Original file line numberDiff line numberDiff line change
@@ -43,8 +43,8 @@
4343
<gav regex="true">^com\.itextpdf:kernel:7\.2\.5.*$</gav>
4444
<vulnerabilityName>CVE-2022-24198</vulnerabilityName>
4545
</suppress>
46-
<suppress until="2023-02-28+02:00">
47-
<notes><![CDATA[
46+
<suppress until="2023-03-31+02:00">
47+
<notes><![CDATA[
4848
file name: commons-jxpath-1.3.jar
4949
5050
Het zal even duren voor er patch versies zijn, zie:
@@ -56,9 +56,9 @@
5656
- alleen vertrouwde gegevens verwerken
5757
- we zelf geen JXPath gebruiken
5858
]]></notes>
59-
<packageUrl regex="true">^pkg:maven/commons\-jxpath/commons\-jxpath@.*$</packageUrl>
60-
<cve>CVE-2022-40159</cve>
61-
<cve>CVE-2022-40160</cve>
59+
<packageUrl regex="true">^pkg:maven/commons\-jxpath/commons\-jxpath@.*$</packageUrl>
60+
<cve>CVE-2022-40159</cve>
61+
<cve>CVE-2022-40160</cve>
6262
</suppress>
6363
<suppress>
6464
<notes><![CDATA[
@@ -73,12 +73,15 @@
7373
<packageUrl regex="true">^pkg:maven/commons\-jxpath/commons\-jxpath@.*$</packageUrl>
7474
<cve>CVE-2022-41852</cve>
7575
</suppress>
76-
<suppress base="true">
77-
<notes><![CDATA[
78-
FP per issue https://github.com/jeremylong/DependencyCheck/issues/5121
79-
fix for commons
76+
<suppress>
77+
<notes><![CDATA[
78+
file name: json-20220924.jar
79+
80+
CVE is voor hutool-json v5.8.10 die doorverwijst naar org.json:json.
81+
We gebruiken de XML.toJSONObject(...) functie niet en sowieso wordt er alleen vertrouwde data geparsed.
82+
zie: https://github.com/stleary/JSON-java/issues/708
8083
]]></notes>
81-
<packageUrl regex="true">^(?!pkg:maven/commons-net/commons-net).*$</packageUrl>
82-
<cpe>cpe:/a:apache:commons_net</cpe>
84+
<packageUrl regex="true">^pkg:maven/org\.json/json@.*$</packageUrl>
85+
<vulnerabilityName>CVE-2022-45688</vulnerabilityName>
8386
</suppress>
8487
</suppressions>

0 commit comments

Comments
 (0)