dependency-versions-upgrade and exclusion #144

Merged
hsh-michaelhoennig merged 7 commits from feature/dependency-versions-upgrade into master 2025-01-09 09:28:43 +01:00
Showing only changes of commit fdb3bd3897 - Show all commits

View File

@ -9,8 +9,12 @@
</suppress> </suppress>
<suppress> <suppress>
<notes><![CDATA[ <notes><![CDATA[
Malicious HTTP redirect in JAXB on a REST-endpoint is not that dangerous. file name: logback-core-1.5.12.jar
A successful attack requires the user to have write access to a configuration file or environment vars.
]]></notes> ]]></notes>
<cve>CVE-2024-9329</cve> <packageUrl regex="true">^pkg:maven/ch\.qos\.logback/logback-core@.*$</packageUrl>
<cpe>cpe:/a:qos:logback</cpe>
<cve>CVE-2024-12798</cve>
</suppress> </suppress>
</suppressions> </suppressions>