|
18 | 18 | under the License. |
19 | 19 | --> |
20 | 20 | <suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd"> |
21 | | - <suppress> |
22 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
23 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
| 21 | + <suppress until="2026-06-30"> |
| 22 | + <notes><![CDATA[ |
| 23 | + file name: jasperreports-7.0.6.jar |
| 24 | + https://community.jaspersoft.com/knowledgebase/faq/update-details-about-the-java-vulnerability-r4897/ |
| 25 | + One way to prevent such an attack would be to make sure the parent Java application runs on Java 17 or later, where this type of attack is blocked by some changes made to the Java platform itself. |
| 26 | + ]]></notes> |
| 27 | + <packageUrl regex="true">^pkg:maven/net\.sf\.jasperreports/jasperreports@.*$</packageUrl> |
| 28 | + <cve>CVE-2025-10492</cve> |
| 29 | + </suppress> |
| 30 | + <suppress> |
| 31 | + <notes><![CDATA[false positive due to naming to close to apache tiles |
| 32 | + cpe:2.3:a:apache:tiles:*:*:*:*:*:*:*:* versions from (including) 2.0]]></notes> |
| 33 | + <cve>CVE-2023-49735</cve> |
24 | 34 | <cpe>cpe:/a:apache:struts</cpe> |
25 | 35 | </suppress> |
26 | 36 | <suppress> |
27 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
28 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
29 | | - <vulnerabilityName>CVE-2011-5057</vulnerabilityName> |
30 | | - </suppress> |
31 | | - <suppress> |
32 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
33 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
34 | | - <vulnerabilityName>CVE-2012-0391</vulnerabilityName> |
35 | | - </suppress> |
36 | | - <suppress> |
37 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
38 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
39 | | - <vulnerabilityName>CVE-2012-0392</vulnerabilityName> |
40 | | - </suppress> |
41 | | - <suppress> |
42 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
43 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
44 | | - <vulnerabilityName>CVE-2012-0393</vulnerabilityName> |
45 | | - </suppress> |
46 | | - <suppress> |
47 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
48 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
49 | | - <vulnerabilityName>CVE-2012-0394</vulnerabilityName> |
50 | | - </suppress> |
51 | | - <suppress> |
52 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
53 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
54 | | - <vulnerabilityName>CVE-2012-0838</vulnerabilityName> |
55 | | - </suppress> |
56 | | - <suppress> |
57 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
58 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
59 | | - <vulnerabilityName>CVE-2013-1965</vulnerabilityName> |
60 | | - </suppress> |
61 | | - <suppress> |
62 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
63 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
64 | | - <vulnerabilityName>CVE-2013-1966</vulnerabilityName> |
65 | | - </suppress> |
66 | | - <suppress> |
67 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
68 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
69 | | - <vulnerabilityName>CVE-2013-2115</vulnerabilityName> |
70 | | - </suppress> |
71 | | - <suppress> |
72 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
73 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
74 | | - <vulnerabilityName>CVE-2013-2134</vulnerabilityName> |
75 | | - </suppress> |
76 | | - <suppress> |
77 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
78 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
79 | | - <vulnerabilityName>CVE-2013-2135</vulnerabilityName> |
80 | | - </suppress> |
81 | | - <suppress> |
82 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
83 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
84 | | - <vulnerabilityName>CVE-2014-0094</vulnerabilityName> |
85 | | - </suppress> |
86 | | - <suppress> |
87 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
88 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
89 | | - <vulnerabilityName>CVE-2014-0113</vulnerabilityName> |
90 | | - </suppress> |
91 | | - <suppress> |
92 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
93 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
94 | | - <vulnerabilityName>CVE-2015-5169</vulnerabilityName> |
95 | | - </suppress> |
96 | | - <suppress> |
97 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
98 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
99 | | - <vulnerabilityName>CVE-2016-0785</vulnerabilityName> |
100 | | - </suppress> |
101 | | - <suppress> |
102 | | - <notes><![CDATA[file name: struts-core-1.3.8.jar]]></notes> |
103 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-core@.*$</packageUrl> |
104 | | - <vulnerabilityName>CVE-2016-4003</vulnerabilityName> |
105 | | - </suppress> |
106 | | - <suppress> |
107 | | - <notes><![CDATA[file name: struts-annotations-1.0.6.jar]]></notes> |
108 | | - <packageUrl regex="true">^pkg:maven/org\.apache\.struts/struts\-annotations@.*$</packageUrl> |
109 | | - <cpe>cpe:/a:apache:struts</cpe> |
110 | | - </suppress> |
111 | | - <suppress> |
112 | | - <notes><![CDATA[file name: struts-tiles-1.3.8.jar]]></notes> |
113 | | - <gav regex="true">^org\.apache\.struts:struts\-tiles\:1\.3\.8.*$</gav> |
114 | | - <cpe>cpe:/a:apache:struts</cpe> |
115 | | - </suppress> |
116 | | - <suppress> |
117 | | - <notes><![CDATA[file name: struts-taglib-1.3.8.jar]]></notes> |
118 | | - <gav regex="true">^org\.apache\.struts:struts\-taglib\:1\.3\.8.*$</gav> |
119 | | - <cpe>cpe:/a:apache:struts</cpe> |
120 | | - </suppress> |
121 | | - <suppress> |
122 | | - <notes><![CDATA[file name: dom4j-1.1.jar]]></notes> |
123 | | - <packageUrl regex="true">^pkg:maven/dom4j/dom4j@.*$</packageUrl> |
124 | | - <vulnerabilityName>CVE-2018-1000632</vulnerabilityName> |
125 | | - </suppress> |
126 | | - <suppress> |
127 | | - <notes><![CDATA[file name: bsh-2.0b4.jar]]></notes> |
128 | | - <packageUrl regex="true">^pkg:maven/org\.beanshell/bsh@.*$</packageUrl> |
129 | | - <vulnerabilityName>CVE-2016-2510</vulnerabilityName> |
130 | | - </suppress> |
131 | | - <suppress> |
132 | | - <notes><![CDATA[ file name: plexus-utils-1.2.jar]]></notes> |
133 | | - <packageUrl regex="true">^pkg:maven/org\.codehaus\.plexus/plexus\-utils@.*$</packageUrl> |
134 | | - <cpe>cpe:/a:plexus-utils_project:plexus-utils</cpe> |
135 | | - <cve>CVE-2022-4244</cve> |
136 | | - <cve>CVE-2022-4245</cve> |
137 | | - <cve>CVE-2017-1000487</cve> |
138 | | - </suppress> |
139 | | - <suppress> |
140 | | - <notes><![CDATA[ file name: plexus-container-default-1.0-alpha-10.jar]]></notes> |
141 | | - <packageUrl regex="true">^pkg:maven/org\.codehaus\.plexus\/plexus\-container\-default@.*$</packageUrl> |
142 | | - <cpe>cpe:/a:plexus-utils_project:plexus-utils</cpe> |
143 | | - <cve>CVE-2022-4244</cve> |
144 | | - <cve>CVE-2022-4245</cve> |
145 | | - </suppress> |
146 | | - <!-- TestNG --> |
147 | | - <suppress> |
148 | | - <notes><![CDATA[file name: guava-19.0.jar]]></notes> |
149 | | - <packageUrl regex="true">^pkg:maven/com\.google\.guava/guava@.*$</packageUrl> |
150 | | - <cve>CVE-2018-10237</cve> |
151 | | - </suppress> |
152 | | - <suppress> |
153 | | - <notes><![CDATA[file name: snakeyaml-1.21.jar]]></notes> |
154 | | - <packageUrl regex="true">^pkg:maven/org\.yaml/snakeyaml@.*$</packageUrl> |
155 | | - <cve>CVE-2017-18640</cve> |
156 | | - </suppress> |
157 | | - <suppress> |
158 | | - <notes><![CDATA[file name: testng-7.1.0.jar: jquery-3.4.1.min.js]]></notes> |
| 37 | + <notes><![CDATA[apps showcase demos with jquery-2.1.4.min.js]]></notes> |
159 | 38 | <packageUrl regex="true">^pkg:javascript/jquery@.*$</packageUrl> |
160 | 39 | <cve>CVE-2020-11022</cve> |
161 | | - </suppress> |
162 | | - <suppress> |
163 | | - <notes><![CDATA[file name: testng-7.1.0.jar: jquery-3.4.1.min.js]]></notes> |
164 | | - <packageUrl regex="true">^pkg:javascript/jquery@.*$</packageUrl> |
165 | 40 | <cve>CVE-2020-11023</cve> |
166 | | - </suppress> |
167 | | - <suppress> |
168 | | - <notes><![CDATA[file name: testng-7.5.jar]]></notes> |
169 | | - <packageUrl regex="true">^pkg:maven/org\.testng/testng@.*$</packageUrl> |
170 | | - <cve>CVE-2022-4065</cve> |
171 | | - </suppress> |
172 | | - <suppress> |
173 | | - <notes><![CDATA[file name: spring-core-4.3.30.RELEASE.jar, spring-aop-4.3.30.RELEASE.jar]]></notes> |
174 | | - <packageUrl regex="true">^pkg:maven/org\.springframework/spring\-.*@.*$</packageUrl> |
175 | | - <cve>CVE-2022-22965</cve> |
176 | | - <cve>CVE-2022-22950</cve> |
177 | | - <cve>CVE-2022-22968</cve> |
178 | | - <cve>CVE-2022-22970</cve> |
179 | | - </suppress> |
180 | | - <suppress> |
181 | | - <notes><![CDATA[file name: spring-web-5.3.23.jar]]></notes> |
182 | | - <packageUrl regex="true">^pkg:maven/org\.springframework/spring\-web@.*$</packageUrl> |
183 | | - <cve>CVE-2016-1000027</cve> |
| 41 | + <cve>CVE-2015-9251</cve> |
| 42 | + <cve>CVE-2019-11358</cve> |
| 43 | + <vulnerabilityName>jquery issue: 11974</vulnerabilityName> |
| 44 | + <vulnerabilityName>jquery issue: 162</vulnerabilityName> |
| 45 | + </suppress> |
| 46 | + <suppress> |
| 47 | + <notes><![CDATA[apps showcase demos with Bootstrap v3.3.4]]></notes> |
| 48 | +<!-- <packageUrl regex="true">^pkg:javascript/bootstrap@.*$</packageUrl>--> |
| 49 | + <sha1>253711c6d825de55a8360552573be950da180614</sha1> |
| 50 | + <cve>CVE-2016-10735</cve> |
| 51 | + <cve>CVE-2018-14040</cve> |
| 52 | + <cve>CVE-2018-14041</cve> |
| 53 | + <cve>CVE-2018-14042</cve> |
| 54 | + <cve>CVE-2018-20676</cve> |
| 55 | + <cve>CVE-2018-20677</cve> |
| 56 | + <cve>CVE-2019-8331</cve> |
| 57 | + <cve>CVE-2024-6485</cve> |
| 58 | + <vulnerabilityName>Bootstrap before 4.0.0 is end-of-life and no longer maintained.</vulnerabilityName> |
184 | 59 | </suppress> |
185 | 60 | </suppressions> |
0 commit comments