FrankChen021 commented on code in PR #19808:
URL: https://github.com/apache/druid/pull/19808#discussion_r3703838478
##########
owasp-dependency-check-suppressions.xml:
##########
@@ -241,39 +241,14 @@
<cve>CVE-2023-0833</cve> <!-- Suppressed since okhttp requests in Druid
are internal, and not user-facing -->
</suppress>
- <suppress>
- <!-- TODO: Fix by updating ambari-metrics-emitter's transitive hadoop
dependency -->
- <notes><![CDATA[
- file name: jackson-mapper-asl-1.9.13.jar
- ]]></notes>
- <packageUrl
regex="true">^pkg:maven/org\.codehaus\.jackson/jackson\-mapper\[email protected]$</packageUrl>
- <cvssBelow>10</cvssBelow> <!-- suppress all CVEs for
jackson-mapper-asl:1.9.13; pulled in (test scope only) via
ambari-metrics-emitter -->
- </suppress>
-
<suppress>
<!-- TODO: Fix by updating
org.apache.druid.java.util.http.client.NettyHttpClient to use netty 4 -->
<notes><![CDATA[
file name: netty-3.10.6.Final.jar
]]></notes>
<packageUrl
regex="true">^pkg:maven/io\.netty/[email protected]$</packageUrl>
- <cve>CVE-2019-16869</cve>
- <cve>CVE-2019-20444</cve>
- <cve>CVE-2019-20445</cve>
- <cve>CVE-2020-11612</cve>
- <cve>CVE-2021-21290</cve> <!-- We don't use HttpPostRequestDecoder or
HttpPostMultiPartRequestDecoder which uses vulnerable AbstractDiskHttpData -
https://github.com/advisories/GHSA-5mcr-gq6c-3hq2 -->
- <cve>CVE-2021-21295</cve> <!-- We don't use HTTP2MultiplexCodec or
Http2FrameCodec or Http2StreamFrameToHttpObjectCodec affected or convert HTTP/2
to HTTP/1.1 requests - https://github.com/advisories/GHSA-wm47-8v5p-wjpj -->
- <cve>CVE-2021-21409</cve> <!-- We don't use Http2HeaderFrame or convert
HTTP/2 to HTTP/1.1 requests https://github.com/advisories/GHSA-f256-j965-7f32
-->
- <cve>CVE-2021-37136</cve>
- <cve>CVE-2021-37137</cve>
- <cve>CVE-2021-43797</cve> <!-- We don't decode user HTTP requests nor
forward them to remote systems, we also don't support for java 6 or lower -
https://github.com/advisories/GHSA-wx5j-54mm-rqqq -->
- <cve>CVE-2022-24823</cve> <!-- We don't decode user HTTP requests nor
forward them to remote systems, we also don't support for java 6 or lower -
https://github.com/advisories/GHSA-269q-hmxg-m83q -->
- <cve>CVE-2022-41881</cve>
- <cve>CVE-2023-34462</cve> <!-- Suppressed since netty requests in Druid
are internal, and not user-facing -->
- <cve>CVE-2025-55163</cve> <!-- Netty 3.x not affected; HTTP/2 issues only
in 4.x -->
- <cve>CVE-2025-58056</cve>
- <cve>CVE-2025-58057</cve> <!-- Netty 3.x not affected; compression issue
only in 4.x -->
- <cve>CVE-2026-33870</cve> <!-- We don't use HttpPostRequestDecoder -->
- <cve>CVE-2026-33871</cve> <!-- Netty 3.x not affected; HTTP/2 issues only
in 4.x -->
+ <!-- Netty 3 is EOL and cannot be upgraded independently. Replacing
Druid's NettyHttpClient with Netty 4 is required. -->
+ <vulnerabilityName regex="true">.*</vulnerabilityName>
Review Comment:
[P2] Keep future Netty 3 advisories visible
The `.*` vulnerability-name rule suppresses every current and future
advisory for `io.netty:netty:3.10.6.Final`. Druid still executes this EOL
dependency through `NettyHttpClient`, so a newly disclosed vulnerability
affecting a reachable runtime path would silently pass OWASP CI. Retain
individually assessed CVE suppressions, optionally with expirations, so new
advisories remain visible.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]