suppression.xml 2.0 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253
  1. <?xml version="1.0" encoding="UTF-8"?>
  2. <!-- This file lists false positives found by org.owasp:dependency-check-maven build plugin -->
  3. <suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
  4. <suppress>
  5. <notes><![CDATA[ Suppress known vulnerabilities in FUSE libraries for fuse-nio-adapter. For more info, see suppression.xml of https://github.com/cryptomator/fuse-nio-adapter ]]></notes>
  6. <gav regex="true">^org\.cryptomator:fuse-nio-adapter:.*$</gav>
  7. <cvssBelow>9</cvssBelow>
  8. </suppress>
  9. <suppress>
  10. <notes><![CDATA[ Suppress known vulnerabilities in FUSE libraries for jnr-fuse (dependency of fuse-nio-adapter). ]]></notes>
  11. <gav regex="true">^com\.github\.serceman:jnr-fuse:.*$</gav>
  12. <cvssBelow>9</cvssBelow>
  13. </suppress>
  14. <!-- Jetty false positives below -->
  15. <suppress>
  16. <notes><![CDATA[ Affects jetty < 6.1.22 ]]></notes>
  17. <gav>org.eclipse.jetty.toolchain:jetty-servlet-api:4.0.6</gav>
  18. <cve>CVE-2009-5045</cve>
  19. </suppress>
  20. <suppress>
  21. <notes><![CDATA[ Affects jetty < 6.1.22 ]]></notes>
  22. <gav>org.eclipse.jetty.toolchain:jetty-servlet-api:4.0.6</gav>
  23. <cve>CVE-2009-5046</cve>
  24. </suppress>
  25. <suppress>
  26. <notes><![CDATA[ Affects jetty-server 9.x ]]></notes>
  27. <gav>org.eclipse.jetty.toolchain:jetty-servlet-api:4.0.6</gav>
  28. <cve>CVE-2017-9735</cve>
  29. </suppress>
  30. <suppress>
  31. <notes><![CDATA[ Affects jetty-server 9.x ]]></notes>
  32. <gav>org.eclipse.jetty.toolchain:jetty-servlet-api:4.0.6</gav>
  33. <cve>CVE-2017-7656</cve>
  34. </suppress>
  35. <suppress>
  36. <notes><![CDATA[ Affects jetty-server 9.x ]]></notes>
  37. <gav>org.eclipse.jetty.toolchain:jetty-servlet-api:4.0.6</gav>
  38. <cve>CVE-2017-7657</cve>
  39. </suppress>
  40. <suppress>
  41. <notes><![CDATA[ Affects jetty-server 9.x ]]></notes>
  42. <gav>org.eclipse.jetty.toolchain:jetty-servlet-api:4.0.6</gav>
  43. <cve>CVE-2017-7658</cve>
  44. </suppress>
  45. <suppress>
  46. <notes><![CDATA[ Fixed since jetty-server 10.0.0.beta2 ]]></notes>
  47. <gav>org.eclipse.jetty.toolchain:jetty-servlet-api:4.0.6</gav>
  48. <cve>CVE-2020-27216</cve>
  49. </suppress>
  50. </suppressions>