Skip to content

[Backport] Port CVE suppressions from 24.0.1#13430

Merged
kfaraz merged 1 commit intoapache:25.0.0from
kfaraz:backport_cve_suppress
Nov 24, 2022
Merged

[Backport] Port CVE suppressions from 24.0.1#13430
kfaraz merged 1 commit intoapache:25.0.0from
kfaraz:backport_cve_suppress

Conversation

@kfaraz
Copy link
Contributor

@kfaraz kfaraz commented Nov 24, 2022

Backports #13415

* Suppress jackson-databind CVE-2022-42003 and CVE-2022-42004
(cherry picked from commit 1f4d892)
* Suppress CVEs
(cherry picked from commit ed55baa)
* Suppress vulnerabilities from druid-website package
(cherry picked from commit c0fb364)
* Add more suppressions for website package
(cherry picked from commit 9bba569)
@kfaraz kfaraz requested a review from rohangarg November 24, 2022 02:05
@kfaraz kfaraz merged commit cca9118 into apache:25.0.0 Nov 24, 2022
@kfaraz kfaraz added this to the 25.0 milestone Dec 16, 2022
@kfaraz kfaraz deleted the backport_cve_suppress branch May 3, 2023 15:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants