mirror of https://github.com/apache/cassandra
Upgrade to OWASP 8.3.1
Patch by brandonwilliams; reviewed by edimitrova for CASSANDRA-18650
This commit is contained in:
parent
7150cc5b99
commit
493d15fffa
|
@ -17,7 +17,7 @@
|
|||
~ limitations under the License.
|
||||
-->
|
||||
<project basedir="." name="apache-cassandra-owasp-tasks">
|
||||
<property name="dependency-check.version" value="6.3.2"/>
|
||||
<property name="dependency-check.version" value="8.3.1"/>
|
||||
<property name="dependency-check.home" value="${build.dir}/dependency-check-ant-${dependency-check.version}"/>
|
||||
|
||||
<condition property="is.dependency.check.jar">
|
||||
|
|
|
@ -116,6 +116,14 @@
|
|||
<cve>CVE-2018-11798</cve>
|
||||
<cve>CVE-2019-0205</cve>
|
||||
</suppress>
|
||||
<suppress>
|
||||
<packageUrl regex="true">^pkg:maven/com\.thinkaurelius\.thrift/thrift-server@.*$</packageUrl>
|
||||
<cve>CVE-2015-3254</cve>
|
||||
<cve>CVE-2016-5397</cve>
|
||||
<cve>CVE-2018-1320</cve>
|
||||
<cve>CVE-2018-11798</cve>
|
||||
<cve>CVE-2019-0205</cve>
|
||||
</suppress>
|
||||
|
||||
<!-- https://issues.apache.org/jira/browse/CASSANDRA-16056 -->
|
||||
<!-- https://issues.apache.org/jira/browse/CASSANDRA-15416 -->
|
||||
|
@ -138,6 +146,8 @@
|
|||
<suppress>
|
||||
<packageUrl regex="true">^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$</packageUrl>
|
||||
<cve>CVE-2023-35116</cve>
|
||||
<cve>CVE-2022-42003</cve>
|
||||
<cve>CVE-2022-42004</cve>
|
||||
</suppress>
|
||||
|
||||
</suppressions>
|
||||
|
|
|
@ -1,4 +1,5 @@
|
|||
3.0.30
|
||||
* Upgrade OWASP to 8.3.1 (CASSANDRA-18650)
|
||||
* Suppress CVE-2023-34462 (CASSANDRA-18649)
|
||||
* Add support for AWS Ec2 IMDSv2 (CASSANDRA-16555)
|
||||
* Suppress CVE-2023-35116 (CASSANDRA-18630)
|
||||
|
|
Loading…
Reference in New Issue