From 28870c702ae08a8e677dc97da72f642c650441bf Mon Sep 17 00:00:00 2001 From: Tejaswini Bandlamudi <96047043+tejaswini-imply@users.noreply.github.com> Date: Wed, 4 Oct 2023 11:59:01 +0530 Subject: [PATCH] Resolve reported CVEs (#15081) --- owasp-dependency-check-suppressions.xml | 10 ++++++++++ pom.xml | 2 +- 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/owasp-dependency-check-suppressions.xml b/owasp-dependency-check-suppressions.xml index 2813623f7a70..e33231ea9ee3 100644 --- a/owasp-dependency-check-suppressions.xml +++ b/owasp-dependency-check-suppressions.xml @@ -758,6 +758,7 @@ https://github.com/apache/hadoop/commit/ad49ddda0e1d9632c8c9fcdc78fca8244e1248c9 --> CVE-2023-1370 CVE-2023-37475 + CVE-2023-39410 @@ -801,4 +802,13 @@ CVE-2023-4785 CVE-2023-33953 + + + + + ^pkg:maven/org\.codehaus\.plexus/plexus-interpolation@.*$ + CVE-2022-4244 + diff --git a/pom.xml b/pom.xml index fcd4cca3003f..6be27033ff92 100644 --- a/pom.xml +++ b/pom.xml @@ -810,7 +810,7 @@ org.xerial.snappy snappy-java - 1.1.10.3 + 1.1.10.4 com.google.protobuf