Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CORE-18636: Add Waivers for investigated CVE's #5200

Merged
merged 2 commits into from
Dec 4, 2023
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
62 changes: 62 additions & 0 deletions .snyk
Original file line number Diff line number Diff line change
Expand Up @@ -27,4 +27,66 @@ ignore:
through Javalin which is configuring Jetty programmatically.
expires: 2023-12-13T12:08:30.514Z
created: 2023-07-13T12:08:30.517Z
SNYK-JAVA-ORGAPACHEAVRO-5926693:
- '*':
reason: >-
This vulnerability does not apply to C5 as it is not exposed i.e
user input is not feed into AVRO messages.
expires: 2024-12-13T12:16:30.514Z
created: 2023-12-04T12:16:30.517Z
SNYK-JAVA-ORGECLIPSEJETTYHTTP2-5958918:
- '*':
reason: >-
C5 is not exposed to this vulnerability it doesn’t use the HTTP/2 protocol.
expires: 2024-12-13T12:16:30.514Z
created: 2023-12-04T12:16:30.517Z
SNYK-JAVA-ORGXERIALSNAPPY-5918282:
- '*':
reason: >-
C5 does not use the Snappy algorithm for compression in our existing Kafka setup.
Furthermore, this package is used internally and we don't send data to Snappy directly.
expires: 2024-12-13T12:16:30.514Z
created: 2023-12-04T12:16:30.517Z
SNYK-JAVA-ORGECLIPSEJETTY-5958847:
- '*':
reason: >-
C5 is not exposed to this vulnerability it doesn’t use the HTTP/2 protocol.
expires: 2024-12-13T12:16:30.514Z
created: 2023-12-04T12:16:30.517Z
SNYK-JAVA-ORGECLIPSEJETTYHTTP2-5958845:
- '*':
reason: >-
C5 is not exposed to this vulnerability it doesn’t use the HTTP/2 protocol.
expires: 2024-12-13T12:16:30.514Z
created: 2023-12-04T12:16:30.517Z
SNYK-JAVA-ORGECLIPSEJETTY-5902998:
- '*':
reason: >-
This vulnerability is fixed in Corda 5.1.
expires: 2024-12-13T12:16:30.514Z
created: 2023-12-04T12:16:30.517Z
SNYK-JAVA-ORGPF4J-5862957:
- '*':
reason: >-
In Corda-cli we do not allow deployment of custom plugins.
If the attacker writes their own plugin, they are not going to
gain any advantage as they will be running on their own computer.
expires: 2024-12-13T12:16:30.514Z
created: 2023-12-04T12:16:30.517Z
SNYK-JAVA-ORGPF4J-5862950:
- '*':
reason: >-
In Corda-cli we do not allow deployment of custom plugins.
If the attacker writes their own plugin, they are not going to
gain any advantage as they will be running on their own computer.
expires: 2024-12-13T12:16:30.514Z
created: 2023-12-04T12:16:30.517Z
SNYK-JAVA-ORGPF4J-5871275:
- '*':
reason: >-
In Corda-cli we do not allow deployment of custom plugins.
If the attacker writes their own plugin, they are not going to
gain any advantage as they will be running on their own computer.
expires: 2024-12-13T12:16:30.514Z
created: 2023-12-04T12:16:30.517Z
patch: {}