FrankChen021 commented on code in PR #19808:
URL: https://github.com/apache/druid/pull/19808#discussion_r3703838478


##########
owasp-dependency-check-suppressions.xml:
##########
@@ -241,39 +241,14 @@
     <cve>CVE-2023-0833</cve>  <!-- Suppressed since okhttp requests in Druid 
are internal, and not user-facing -->
   </suppress>
 
-  <suppress>
-    <!-- TODO: Fix by updating ambari-metrics-emitter's transitive hadoop 
dependency -->
-    <notes><![CDATA[
-   file name: jackson-mapper-asl-1.9.13.jar
-   ]]></notes>
-    <packageUrl 
regex="true">^pkg:maven/org\.codehaus\.jackson/jackson\-mapper\[email protected]$</packageUrl>
-    <cvssBelow>10</cvssBelow>  <!-- suppress all CVEs for 
jackson-mapper-asl:1.9.13; pulled in (test scope only) via 
ambari-metrics-emitter -->
-  </suppress>
-
   <suppress>
     <!-- TODO: Fix by updating 
org.apache.druid.java.util.http.client.NettyHttpClient to use netty 4 -->
     <notes><![CDATA[
    file name: netty-3.10.6.Final.jar
    ]]></notes>
     <packageUrl 
regex="true">^pkg:maven/io\.netty/[email protected]$</packageUrl>
-    <cve>CVE-2019-16869</cve>
-    <cve>CVE-2019-20444</cve>
-    <cve>CVE-2019-20445</cve>
-    <cve>CVE-2020-11612</cve>
-    <cve>CVE-2021-21290</cve> <!-- We don't use HttpPostRequestDecoder or 
HttpPostMultiPartRequestDecoder which uses vulnerable AbstractDiskHttpData - 
https://github.com/advisories/GHSA-5mcr-gq6c-3hq2 -->
-    <cve>CVE-2021-21295</cve> <!-- We don't use HTTP2MultiplexCodec or 
Http2FrameCodec or Http2StreamFrameToHttpObjectCodec affected or convert HTTP/2 
to HTTP/1.1 requests - https://github.com/advisories/GHSA-wm47-8v5p-wjpj -->
-    <cve>CVE-2021-21409</cve> <!-- We don't use Http2HeaderFrame or convert 
HTTP/2 to HTTP/1.1 requests https://github.com/advisories/GHSA-f256-j965-7f32 
-->
-    <cve>CVE-2021-37136</cve>
-    <cve>CVE-2021-37137</cve>
-    <cve>CVE-2021-43797</cve> <!-- We don't decode user HTTP requests nor 
forward them to remote systems, we also don't support for java 6 or lower - 
https://github.com/advisories/GHSA-wx5j-54mm-rqqq -->
-    <cve>CVE-2022-24823</cve> <!-- We don't decode user HTTP requests nor 
forward them to remote systems, we also don't support for java 6 or lower - 
https://github.com/advisories/GHSA-269q-hmxg-m83q -->
-    <cve>CVE-2022-41881</cve>
-    <cve>CVE-2023-34462</cve>  <!-- Suppressed since netty requests in Druid 
are internal, and not user-facing -->
-    <cve>CVE-2025-55163</cve> <!-- Netty 3.x not affected; HTTP/2 issues only 
in 4.x -->
-    <cve>CVE-2025-58056</cve>
-    <cve>CVE-2025-58057</cve> <!-- Netty 3.x not affected; compression issue 
only in 4.x -->
-    <cve>CVE-2026-33870</cve> <!-- We don't use HttpPostRequestDecoder -->
-    <cve>CVE-2026-33871</cve> <!-- Netty 3.x not affected; HTTP/2 issues only 
in 4.x -->
+    <!-- Netty 3 is EOL and cannot be upgraded independently. Replacing 
Druid's NettyHttpClient with Netty 4 is required. -->
+    <vulnerabilityName regex="true">.*</vulnerabilityName>

Review Comment:
   [P2] Keep future Netty 3 advisories visible
   
   The `.*` vulnerability-name rule suppresses every current and future 
advisory for `io.netty:netty:3.10.6.Final`. Druid still executes this EOL 
dependency through `NettyHttpClient`, so a newly disclosed vulnerability 
affecting a reachable runtime path would silently pass OWASP CI. Retain 
individually assessed CVE suppressions, optionally with expirations, so new 
advisories remain visible.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to