Pārlūkot izejas kodu

Suppress a CVE false-positive for jackson-databind 2.14.2

Also see https://github.com/cryptomator/cryptomator/pull/2961#issuecomment-1597652134.
Sebastian Schuberth 1 gadu atpakaļ
vecāks
revīzija
4d09728880
1 mainītis faili ar 9 papildinājumiem un 1 dzēšanām
  1. 9 1
      suppression.xml

+ 9 - 1
suppression.xml

@@ -55,4 +55,12 @@
 		<cve>CVE-2022-45688</cve>
 	</suppress>
 
-</suppressions>
+	<suppress>
+		<notes><![CDATA[
+		False positive for jackson-databind-2.14.2.jar, see https://github.com/FasterXML/jackson-databind/issues/3972
+   ]]></notes>
+		<packageUrl regex="true">^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$</packageUrl>
+		<cve>CVE-2023-35116</cve>
+	</suppress>
+
+</suppressions>