Fixing security vulnerability check errors#13956
Fixing security vulnerability check errors#13956AmatyaAvadhanula merged 3 commits intoapache:masterfrom
Conversation
|
@abhagraw could you please add more details regarding the CVEs and why they do not affect Druid? |
I have added a comment for Is there any specific information you are looking for? |
|
Closed by mistake. Reopening. |
|
Suppressing following CVEs - CVE-2022-45688 - This does not affect us as we do not use XML CVE-2020-11612 - To suppress this need to update to netty 4 (A lot of other dependencies waiting on this) CVE-2021-28170 - Updated to jakarta.el 3.0.4 CVE-2023-1370 - Druid only parses json with expected formats. |
|
Thank you for adding the details! |
Fixing security vulnerability check errors.