summaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
authorAlbin <albin@mullvad.net>2022-12-08 11:07:48 +0100
committerAlbin <albin@mullvad.net>2022-12-08 11:07:48 +0100
commit35d7755d7d80195212b4dff7739ef531c4d9a1ca (patch)
treecafbb10da04abcadb302bc8120c581a1fbc887e8
parent05c8290c888c5e61fa76cb5d0346901c44d78e86 (diff)
parente160a6405c4219aabf55fabf340d2f603e2490e8 (diff)
downloadmullvadvpn-35d7755d7d80195212b4dff7739ef531c4d9a1ca.tar.xz
mullvadvpn-35d7755d7d80195212b4dff7739ef531c4d9a1ca.zip
Merge branch 'suppress-CVE-2021-37533'
-rw-r--r--android/config/dependency-check-suppression.xml15
-rw-r--r--android/e2e/e2e-suppression.xml15
2 files changed, 30 insertions, 0 deletions
diff --git a/android/config/dependency-check-suppression.xml b/android/config/dependency-check-suppression.xml
index c90c64c949..3aad669277 100644
--- a/android/config/dependency-check-suppression.xml
+++ b/android/config/dependency-check-suppression.xml
@@ -21,4 +21,19 @@
<packageUrl regex="true">^pkg:maven/com\.google\.protobuf/protobuf\-javalite@.*$</packageUrl>
<cve>CVE-2022-3171</cve>
</suppress>
+ <suppress>
+ <notes><![CDATA[
+ This CVE affects the Apache Commons Net's FTP client that this app doesn't use.
+ https://www.openwall.com/lists/oss-security/2022/12/03/1
+
+ File names:
+ - commons-beanutils-1.9.4.jar
+ - commons-collections-3.2.2.jar
+ - commons-digester-2.1.jar
+ - commons-logging-1.2.jar
+ - commons-validator-1.7.jar
+ ]]></notes>
+ <packageUrl regex="true">^pkg:maven/commons\-.*/commons\-.*@.*$</packageUrl>
+ <cve>CVE-2021-37533</cve>
+ </suppress>
</suppressions>
diff --git a/android/e2e/e2e-suppression.xml b/android/e2e/e2e-suppression.xml
index 86e10bebb2..4729d5da68 100644
--- a/android/e2e/e2e-suppression.xml
+++ b/android/e2e/e2e-suppression.xml
@@ -28,4 +28,19 @@
<packageUrl regex="true">^pkg:maven/com\.google\.protobuf/protobuf\-javalite@.*$</packageUrl>
<cve>CVE-2022-3171</cve>
</suppress>
+ <suppress>
+ <notes><![CDATA[
+ This CVE affects the Apache Commons Net's FTP client that this app doesn't use.
+ https://www.openwall.com/lists/oss-security/2022/12/03/1
+
+ File names:
+ - commons-beanutils-1.9.4.jar
+ - commons-collections-3.2.2.jar
+ - commons-digester-2.1.jar
+ - commons-logging-1.2.jar
+ - commons-validator-1.7.jar
+ ]]></notes>
+ <packageUrl regex="true">^pkg:maven/commons\-.*/commons\-.*@.*$</packageUrl>
+ <cve>CVE-2021-37533</cve>
+ </suppress>
</suppressions>