Skip to content

Supress CVE 2022 26612#12463

Merged
suneet-s merged 6 commits intoapache:masterfrom
tejaswini-imply:supress-CVE-2022-26612
Apr 21, 2022
Merged

Supress CVE 2022 26612#12463
suneet-s merged 6 commits intoapache:masterfrom
tejaswini-imply:supress-CVE-2022-26612

Conversation

@tejaswini-imply
Copy link
Member

Description

Suppressing this CVE since we are only using hadoop client.

This PR has:

  • been self-reviewed.

</suppress>

<suppress>
<!-- Suppress cves that aren't applicable to hadoop client -->
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It looks like we already have a section for suppressions like this in

<suppress>
<notes><![CDATA[
file name: hadoop-*-2.8.5.jar
]]></notes>
<packageUrl regex="true">^pkg:maven/org\.apache\.hadoop/hadoop\-.*@.*$</packageUrl>
<cve>CVE-2018-11765</cve>
<cve>CVE-2020-9492</cve>
</suppress>

Can you combine this with that section.

This comment explaining why the CVE is being suppressed is great!

Copy link
Contributor

@suneet-s suneet-s left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @tejaswini-imply !

@suneet-s suneet-s merged commit 65d00c7 into apache:master Apr 21, 2022
@abhishekagarwal87 abhishekagarwal87 added this to the 0.23.0 milestone May 11, 2022
@tejaswini-imply tejaswini-imply deleted the supress-CVE-2022-26612 branch June 22, 2022 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants