From cdac7abb37b9c5bcf5a61b0e9a122bdcb8eba7a0 Mon Sep 17 00:00:00 2001 From: Darran Lofthouse Date: Mon, 4 Mar 2024 17:32:04 +0000 Subject: [PATCH 1/3] [WFLY-18073] Add dependency-check to 31.x --- pom.xml | 28 ++++ sca-overrides/owasp-suppressions.xml | 200 +++++++++++++++++++++++++++ 2 files changed, 228 insertions(+) create mode 100644 sca-overrides/owasp-suppressions.xml diff --git a/pom.xml b/pom.xml index f780879e47a7..78008358f6a4 100644 --- a/pom.xml +++ b/pom.xml @@ -1402,6 +1402,34 @@ docs + + dependency-check + + + dependency-check + + + + + + org.owasp + dependency-check-maven + 9.0.9 + + nvd + ./sca-overrides/owasp-suppressions.xml + + + + + aggregate + + + + + + + + + + + ^pkg:maven/org\.glassfish\.expressly/expressly@.*$ + cpe:/a:eclipse:glassfish + + + + ^pkg:maven/org\.wildfly\.security\.jakarta/jakarta\-client\-resteasy@.*$ + cpe:/a:redhat:resteasy + + + + ^pkg:maven/org\.jboss/jboss\-iiop\-client@.*$ + cpe:/a:redhat:jboss-ejb-client + + + + ^pkg:maven/org\.wildfly/mvc\-krazo\-subsystem@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly/mvc\-krazo\-galleon\-shared@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly\.extras\.batavia/transformer\-api@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly\.security/wildfly\-elytron\-audit@.*$ + cpe:/a:linux_audit_project:linux_audit + + + + ^pkg:maven/org\.wildfly\.core/wildfly\-.*@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly\.plugins/wildfly\-plugin\-core@.*$ + cpe:/a:redhat:wildfly + cpe:/a:redhat:wildfly_core + + + + ^pkg:maven/org\.wildfly\.galleon\-plugins/transformer@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly\.deployment/wildfly\-ee\-9\-deployment\-transformer@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly\.galleon\-plugins/wildfly\-galleon\-plugins@.*$ + cpe:/a:redhat:wildfly + + + + + + + + + + + ^pkg:maven/org\.apache\.directory\.server/apacheds\-.*@.*$ + CVE-2010-1151 + + + + ^pkg:maven/org\.apache\.mina/mina\-core@.*$ + CVE-2021-41973 + + + + ^pkg:maven/io\.grpc/grpc\-api@.*$ + CVE-2023-44487 + + + + ^pkg:maven/com\.h2database/h2@.*$ + + CVE-2018-14335 + + + + ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$ + + CVE-2023-35116 + + + + ^pkg:maven/org\.glassfish\.soteria/jakarta\.security\.enterprise@.*$ + CVE-2020-1732 + + + + ^pkg:maven/org\.jgroups\.aws/jgroups\-aws@.*$ + CVE-2016-2141 + + + + ^pkg:maven/org\.apache\.commons/commons\-compress@.*$ + CVE-2024-25710 + CVE-2024-26308 + CVE-2023-42503 + + + + ^pkg:maven/io\.opentelemetry\.proto/opentelemetry\-proto@.*$ + CVE-2023-43810 + CVE-2023-45142 + CVE-2023-47108 + + + + ^pkg:maven/org\.jboss\.resteasy\.spring/resteasy\-spring@.*$ + CVE-2016-9606 + CVE-2014-3490 + CVE-2020-1695 + CVE-2020-10688 + CVE-2023-0482 + CVE-2020-25633 + CVE-2021-20289 + + + + ^pkg:maven/org\.jboss\.resteasy/resteasy\-tracing\-api@.*$ + CVE-2016-9606 + CVE-2020-10688 + CVE-2023-0482 + CVE-2020-25633 + CVE-2021-20289 + CVE-2011-5245 + CVE-2012-0818 + + + + ^pkg:maven/io\.undertow/undertow\-core@.*$ + CVE-2016-6311 + + From 5d89c21ccf96fd627f590afbd95569f95a481f03 Mon Sep 17 00:00:00 2001 From: Darran Lofthouse Date: Fri, 8 Mar 2024 17:23:29 +0000 Subject: [PATCH 2/3] [WFLY-18073] Ignore CVE-2021-20293 for two reasons: 1. It is not matched against the correct components. 2. It was decided this is not a CVE and is the user's responsibility. --- sca-overrides/owasp-suppressions.xml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/sca-overrides/owasp-suppressions.xml b/sca-overrides/owasp-suppressions.xml index 7731ff4ecd8b..4202838a4458 100644 --- a/sca-overrides/owasp-suppressions.xml +++ b/sca-overrides/owasp-suppressions.xml @@ -197,4 +197,18 @@ ^pkg:maven/io\.undertow/undertow\-core@.*$ CVE-2016-6311 + + + ^pkg:maven/org\.jboss\.resteasy\.spring/resteasy\-spring@.*$ + CVE-2021-20293 + + + + ^pkg:maven/org\.jboss\.resteasy/resteasy\-tracing\-api@.*$ + CVE-2021-20293 + From b862dbb078fbf11a06754a671a4629b463036de7 Mon Sep 17 00:00:00 2001 From: Darran Lofthouse Date: Wed, 10 Apr 2024 16:22:24 +0100 Subject: [PATCH 3/3] [WFLY-19224] Suppress CVE-2023-1973 as WildFly no longer uses Undertow's authentication mechanisms. --- sca-overrides/owasp-suppressions.xml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/sca-overrides/owasp-suppressions.xml b/sca-overrides/owasp-suppressions.xml index 4202838a4458..a219162a486e 100644 --- a/sca-overrides/owasp-suppressions.xml +++ b/sca-overrides/owasp-suppressions.xml @@ -211,4 +211,21 @@ ^pkg:maven/org\.jboss\.resteasy/resteasy\-tracing\-api@.*$ CVE-2021-20293 + + + ^pkg:maven/org\.jboss\.resteasy\.spring/resteasy\-spring@.*$ + CVE-2018-1051 + + + + ^pkg:maven/io\.undertow/undertow\-core@.*$ + CVE-2023-1973 +