Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added a suppression for derby database #1038

Merged
merged 1 commit into from
Jan 4, 2024

Conversation

sparkhi
Copy link
Collaborator

@sparkhi sparkhi commented Jan 4, 2024

As per https://nvd.nist.gov/vuln/detail/CVE-2022-46337
We have a dependency that we use with high vulnerability, however the vulnerability is associated with using LDAP for login. We do not use LDAP for our derby database (the db that stores the results), hence suppressing the check is easier than rebuilding the jar ourselves or move to a newer version of java.

While at it, also removed all the spring vulnerabilities that had anyways expired in 2022 and we had moved to a newer version of spring.

Copy link

@steve-daly steve-daly left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Happy with this. No issue supressing the LDAP-related vulnerability as we're not using this authentication method.

@sparkhi sparkhi merged commit 07c8318 into master Jan 4, 2024
10 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants