From e4648e570d6aafd10a9cb9f9681de3855982f52b Mon Sep 17 00:00:00 2001 From: Brian Demers Date: Fri, 10 May 2019 13:31:58 -0400 Subject: [PATCH] Update dependency versions and suppress OWASP false positives --- pom.xml | 6 +++--- src/owasp/owasp-suppression.xml | 24 ++++++++++++++++++++++++ 2 files changed, 27 insertions(+), 3 deletions(-) diff --git a/pom.xml b/pom.xml index 63a37d3d8..1f95b15cf 100644 --- a/pom.xml +++ b/pom.xml @@ -31,10 +31,10 @@ pom - 2.1.2.RELEASE - 2.0.2.RELEASE + 2.1.4.RELEASE + 2.1.2.RELEASE okta/okta-spring-boot - 1.4.1 + 1.5.2 1.1.1 diff --git a/src/owasp/owasp-suppression.xml b/src/owasp/owasp-suppression.xml index 933f9ae03..6a5de883d 100644 --- a/src/owasp/owasp-suppression.xml +++ b/src/owasp/owasp-suppression.xml @@ -113,4 +113,28 @@ cpe:/a:netty_project:netty + + + + ^org\.springframework\.security:spring-security-.*:5.1.*$ + CVE-2018-1258 + + + + ^org\.springframework\.boot:spring-boot-starter-security:2.1.*$ + CVE-2018-1258 + + + + + + ^org\.apache\.tomcat\.embed:tomcat-embed-.*:.*$ + CVE-2019-0232 + + \ No newline at end of file