FrankChen021 commented on code in PR #20236:
URL: https://github.com/apache/druid/pull/20236#discussion_r3999608441


##########
owasp-dependency-check-suppressions.xml:
##########
@@ -732,4 +759,150 @@
     <packageUrl regex="true">^pkg:maven/io\.grpc/grpc-.*@.*$</packageUrl>
     <cve>CVE-2026-33186</cve> <!-- Only applicable to gRPC Go 
(google.golang.org/grpc < 1.79.3), not gRPC Java - 
https://nvd.nist.gov/vuln/detail/CVE-2026-33186 -->
   </suppress>
+
+
+  <suppress>
+    <!-- GHSA-w5hq-g745-h8pq: Missing bounds check in uuid v3/v5/v6 when the 
optional buf
+         argument is provided. Druid's web console uses only uuidv4() with no 
buf argument
+         (web-console/src/druid-models/workbench-query/workbench-query.ts), so 
the
+         vulnerable code path is never exercised.
+         Update to version 11.1.1 or 12.0.1 to remove this suppression
+          -->
+    <notes><![CDATA[
+      file name: package-lock.json (pkg:npm/[email protected])
+    ]]></notes>
+    <packageUrl regex="true">^pkg:npm/uuid@.*$</packageUrl>
+    <vulnerabilityName>GHSA-w5hq-g745-h8pq</vulnerabilityName>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-53914: Unsafe deserialization in Kotlin's build cache 
metadata (Kotlin compiler/Gradle plugin).
+         This is a build-toolchain vulnerability, not a runtime stdlib issue. 
Druid has no Kotlin source files;
+         kotlin-stdlib is a transitive runtime dependency (via Iceberg) and 
Druid never invokes Kotlin's build cache. -->
+    <notes><![CDATA[
+      file name: kotlin-stdlib-2.4.10.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/org\.jetbrains\.kotlin/kotlin-stdlib@.*$</packageUrl>
+    <cve>CVE-2026-53914</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-33117: Vulnerability in Azure SDK for Java's Key Vault Keys 
local cryptographic verification path.
+         The CVE fires against azure-core, azure-core-http-netty, 
azure-identity, and azure-json due to broad CPE
+         matching, but none of these jars contain the vulnerable Key Vault 
code path. Druid uses these artifacts
+         for blob storage auth only and does not use the Key Vault 
cryptography client. -->
+    <notes><![CDATA[
+      file name: azure-core-1.58.1.jar azure-core-http-netty-1.16.5.jar 
azure-identity-1.18.4.jar azure-json-1.5.1.jar
+    ]]></notes>
+    <packageUrl regex="true">^pkg:maven/com\.azure/azure-.*@.*$</packageUrl>
+    <cve>CVE-2026-33117</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-49845: SQL injection in Hive Metastore partition-name 
resolution.
+         CVE-2026-53561: SAML bearer-token authentication bypass in 
HiveServer2.
+         CVE-2026-55976: SSRF via avro.schema.url in Avro SerDe schema 
resolution.
+         All three affect Apache Hive server components (Metastore, 
HiveServer2).
+         Druid uses hive-storage-api only for the Murmur3 hash utility
+         (BloomKFilter.java) and ORC/Parquet column type definitions — it does 
not
+         run or connect to a Hive Metastore or HiveServer2. -->
+    <notes><![CDATA[
+      file name: hive-storage-api-4.2.0.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/org\.apache\.hive/hive-storage-api@.*$</packageUrl>
+    <cve>CVE-2026-49845</cve>
+    <cve>CVE-2026-53561</cve>
+    <cve>CVE-2026-55976</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-54512, CVE-2026-54513: PolymorphicTypeValidator bypass in 
jackson-databind when
+         polymorphic typing is enabled with generic type parameters or array 
subtypes.
+         These CVEs affect jackson-databind shaded inside hadoop/parquet jars,
+         not Druid's own jackson-databind (2.22.x).
+         CVE-2026-68497: Not yet published in NVD, suppressed as appearing 
only inside shaded jars -->
+    <notes><![CDATA[
+      file name: hadoop-client-runtime-3.5.0.jar (shaded jackson-databind 
2.18.6)
+                 parquet-jackson-1.18.0.jar (shaded jackson-databind 2.22.1)
+    ]]></notes>
+    <filePath 
regex="true">.*/(hadoop-client-runtime|parquet-jackson)-[0-9][^/]*\.jar/META-INF/maven/com\.fasterxml\.jackson\.core/jackson-databind/pom\.xml$</filePath>
+    <cve>CVE-2026-54512</cve>
+    <cve>CVE-2026-54513</cve>
+    <cve>CVE-2026-68497</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-2332: Jetty HTTP/1.1 request smuggling via chunk extension 
quoted strings.
+         CVE-2026-10050: Jetty Digest auth password encoding using ISO-8859-1.
+         Both affect Jetty shaded inside hadoop-client-runtime-3.5.0.jar. 
Druid cannot upgrade
+         the Jetty version inside this shaded jar. The shaded Jetty is used 
only for Hadoop's
+         internal HTTP server (WebHDFS, etc.), not for Druid's own HTTP server 
(Jetty 12.x).
+         Druid does not use Hadoop's embedded Jetty server or Digest auth. -->
+    <notes><![CDATA[
+      file name: hadoop-client-runtime-3.5.0.jar (shaded org.eclipse.jetty* 
9.4.58.v20250814)
+    ]]></notes>
+    <filePath 
regex="true">.*/(hadoop-client-runtime)-[0-9][^/]*\.jar/META-INF/maven/org\.eclipse\.jetty[^/]*/[^/]*/pom\.xml$</filePath>
+    <cve>CVE-2026-2332</cve>
+    <cve>CVE-2026-10050</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-56741, CVE-2026-56740: DoS via JLine Telnet server (NAWS 
terminal dimensions and
+         NEW-ENVIRON flooding). JLine is shaded inside 
hadoop-client-runtime-3.5.0.jar and is used
+         only for Hadoop's interactive CLI shell. Druid does not expose a 
JLine Telnet server endpoint. -->
+    <notes><![CDATA[
+      file name: hadoop-client-runtime-3.5.0.jar (shaded jline 3.9.0)
+    ]]></notes>
+    <filePath 
regex="true">.*/(hadoop-client-runtime)-[0-9][^/]*\.jar/META-INF/maven/org\.jline/jline[^/]*/pom\.xml$</filePath>
+    <cve>CVE-2026-56741</cve>
+    <cve>CVE-2026-56740</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-24051, CVE-2026-39883, CVE-2026-29181: All three affect the 
OpenTelemetry Go SDK
+         (opentelemetry-go), not any Java library. The scanner matches 
opentelemetry-gcp-resources
+         (a Java artifact) against the Go SDK CPE due to the shared 
"opentelemetry" product name.
+         Druid's google-extensions use the Java opentelemetry-gcp-resources 
for GCP resource
+         detection; the vulnerable PATH hijacking and baggage-header 
amplification code exists
+         only in the Go implementation. -->
+    <notes><![CDATA[
+      file name: opentelemetry-gcp-resources-1.37.0-alpha.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/io\.opentelemetry\.contrib/opentelemetry-gcp-resources@.*$</packageUrl>
+    <cve>CVE-2026-24051</cve>
+    <cve>CVE-2026-39883</cve>
+    <cve>CVE-2026-29181</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-40542, CVE-2026-71290: Vulnerabilities in Apache HttpClient 
5 (SCRAM mutual auth
+         and async hostname verification). CVE-2026-54399, CVE-2026-54428: DoS 
in Apache HttpComponents
+         Core 5 (excessive headers and HTTP/2 HPACK). All four affect 
httpclient5/httpcore5 shaded
+         inside docker-java-transport-zerodep-3.7.1.jar (a test-scoped 
dependency used only by
+         druid-testcontainers for Docker container management in tests). These 
are not present in
+         Druid's production runtime classpath. -->
+    <notes><![CDATA[
+      file name: docker-java-transport-zerodep-3.7.1.jar (shaded httpclient5 
5.5.1 and httpcore5 5.3.6)
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/org\.apache\.httpcomponents\.(client5/httpclient5|core5/httpcore5)@.*$</packageUrl>

Review Comment:
   [P2] Include the separately shaded httpcore5-h2 artifact
   
   **Finding:** The alternation matches 
org.apache.httpcomponents.core5:httpcore5 but not 
org.apache.httpcomponents.core5:httpcore5-h2. 
docker-java-transport-zerodep-3.7.1.jar embeds httpcore5-h2 separately, and the 
current security-vulnerabilities job still reports CVE-2026-54399 and 
CVE-2026-54428 for that path, so this suppression does not make the documented 
test-only dependency clean.
   
   **Suggestion:** Add core5/httpcore5-h2 to the packageUrl alternation, or 
scope the CVEs to the verified docker-java shaded POM paths, then rerun the 
dependency-check job.



##########
owasp-dependency-check-suppressions.xml:
##########
@@ -732,4 +759,150 @@
     <packageUrl regex="true">^pkg:maven/io\.grpc/grpc-.*@.*$</packageUrl>
     <cve>CVE-2026-33186</cve> <!-- Only applicable to gRPC Go 
(google.golang.org/grpc < 1.79.3), not gRPC Java - 
https://nvd.nist.gov/vuln/detail/CVE-2026-33186 -->
   </suppress>
+
+
+  <suppress>
+    <!-- GHSA-w5hq-g745-h8pq: Missing bounds check in uuid v3/v5/v6 when the 
optional buf
+         argument is provided. Druid's web console uses only uuidv4() with no 
buf argument
+         (web-console/src/druid-models/workbench-query/workbench-query.ts), so 
the
+         vulnerable code path is never exercised.
+         Update to version 11.1.1 or 12.0.1 to remove this suppression
+          -->
+    <notes><![CDATA[
+      file name: package-lock.json (pkg:npm/[email protected])
+    ]]></notes>
+    <packageUrl regex="true">^pkg:npm/uuid@.*$</packageUrl>
+    <vulnerabilityName>GHSA-w5hq-g745-h8pq</vulnerabilityName>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-53914: Unsafe deserialization in Kotlin's build cache 
metadata (Kotlin compiler/Gradle plugin).
+         This is a build-toolchain vulnerability, not a runtime stdlib issue. 
Druid has no Kotlin source files;
+         kotlin-stdlib is a transitive runtime dependency (via Iceberg) and 
Druid never invokes Kotlin's build cache. -->
+    <notes><![CDATA[
+      file name: kotlin-stdlib-2.4.10.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/org\.jetbrains\.kotlin/kotlin-stdlib@.*$</packageUrl>
+    <cve>CVE-2026-53914</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-33117: Vulnerability in Azure SDK for Java's Key Vault Keys 
local cryptographic verification path.
+         The CVE fires against azure-core, azure-core-http-netty, 
azure-identity, and azure-json due to broad CPE
+         matching, but none of these jars contain the vulnerable Key Vault 
code path. Druid uses these artifacts
+         for blob storage auth only and does not use the Key Vault 
cryptography client. -->
+    <notes><![CDATA[
+      file name: azure-core-1.58.1.jar azure-core-http-netty-1.16.5.jar 
azure-identity-1.18.4.jar azure-json-1.5.1.jar
+    ]]></notes>
+    <packageUrl regex="true">^pkg:maven/com\.azure/azure-.*@.*$</packageUrl>

Review Comment:
   [P2] Narrow the Azure suppression to the reviewed artifacts
   
   **Finding:** This packageUrl matcher suppresses CVE-2026-33117 for every 
com.azure artifact, not just the four jars listed in the notes. It therefore 
also matches com.azure:azure-security-keyvault-keys, the artifact associated 
with the Key Vault Keys verification vulnerability, so a future dependency on 
that client would have its real finding silently suppressed.
   
   **Suggestion:** Replace the wildcard with exact packageUrl rules for the 
reviewed Azure artifacts (or a containing-jar/filePath matcher), and keep the 
vulnerable Key Vault artifacts outside the suppression scope.



##########
owasp-dependency-check-suppressions.xml:
##########
@@ -732,4 +759,150 @@
     <packageUrl regex="true">^pkg:maven/io\.grpc/grpc-.*@.*$</packageUrl>
     <cve>CVE-2026-33186</cve> <!-- Only applicable to gRPC Go 
(google.golang.org/grpc < 1.79.3), not gRPC Java - 
https://nvd.nist.gov/vuln/detail/CVE-2026-33186 -->
   </suppress>
+
+
+  <suppress>
+    <!-- GHSA-w5hq-g745-h8pq: Missing bounds check in uuid v3/v5/v6 when the 
optional buf
+         argument is provided. Druid's web console uses only uuidv4() with no 
buf argument
+         (web-console/src/druid-models/workbench-query/workbench-query.ts), so 
the
+         vulnerable code path is never exercised.
+         Update to version 11.1.1 or 12.0.1 to remove this suppression
+          -->
+    <notes><![CDATA[
+      file name: package-lock.json (pkg:npm/[email protected])
+    ]]></notes>
+    <packageUrl regex="true">^pkg:npm/uuid@.*$</packageUrl>
+    <vulnerabilityName>GHSA-w5hq-g745-h8pq</vulnerabilityName>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-53914: Unsafe deserialization in Kotlin's build cache 
metadata (Kotlin compiler/Gradle plugin).
+         This is a build-toolchain vulnerability, not a runtime stdlib issue. 
Druid has no Kotlin source files;
+         kotlin-stdlib is a transitive runtime dependency (via Iceberg) and 
Druid never invokes Kotlin's build cache. -->
+    <notes><![CDATA[
+      file name: kotlin-stdlib-2.4.10.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/org\.jetbrains\.kotlin/kotlin-stdlib@.*$</packageUrl>
+    <cve>CVE-2026-53914</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-33117: Vulnerability in Azure SDK for Java's Key Vault Keys 
local cryptographic verification path.
+         The CVE fires against azure-core, azure-core-http-netty, 
azure-identity, and azure-json due to broad CPE
+         matching, but none of these jars contain the vulnerable Key Vault 
code path. Druid uses these artifacts
+         for blob storage auth only and does not use the Key Vault 
cryptography client. -->
+    <notes><![CDATA[
+      file name: azure-core-1.58.1.jar azure-core-http-netty-1.16.5.jar 
azure-identity-1.18.4.jar azure-json-1.5.1.jar
+    ]]></notes>
+    <packageUrl regex="true">^pkg:maven/com\.azure/azure-.*@.*$</packageUrl>
+    <cve>CVE-2026-33117</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-49845: SQL injection in Hive Metastore partition-name 
resolution.
+         CVE-2026-53561: SAML bearer-token authentication bypass in 
HiveServer2.
+         CVE-2026-55976: SSRF via avro.schema.url in Avro SerDe schema 
resolution.
+         All three affect Apache Hive server components (Metastore, 
HiveServer2).
+         Druid uses hive-storage-api only for the Murmur3 hash utility
+         (BloomKFilter.java) and ORC/Parquet column type definitions — it does 
not
+         run or connect to a Hive Metastore or HiveServer2. -->
+    <notes><![CDATA[
+      file name: hive-storage-api-4.2.0.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/org\.apache\.hive/hive-storage-api@.*$</packageUrl>
+    <cve>CVE-2026-49845</cve>
+    <cve>CVE-2026-53561</cve>
+    <cve>CVE-2026-55976</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-54512, CVE-2026-54513: PolymorphicTypeValidator bypass in 
jackson-databind when
+         polymorphic typing is enabled with generic type parameters or array 
subtypes.
+         These CVEs affect jackson-databind shaded inside hadoop/parquet jars,
+         not Druid's own jackson-databind (2.22.x).
+         CVE-2026-68497: Not yet published in NVD, suppressed as appearing 
only inside shaded jars -->
+    <notes><![CDATA[
+      file name: hadoop-client-runtime-3.5.0.jar (shaded jackson-databind 
2.18.6)
+                 parquet-jackson-1.18.0.jar (shaded jackson-databind 2.22.1)
+    ]]></notes>
+    <filePath 
regex="true">.*/(hadoop-client-runtime|parquet-jackson)-[0-9][^/]*\.jar/META-INF/maven/com\.fasterxml\.jackson\.core/jackson-databind/pom\.xml$</filePath>
+    <cve>CVE-2026-54512</cve>
+    <cve>CVE-2026-54513</cve>
+    <cve>CVE-2026-68497</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-2332: Jetty HTTP/1.1 request smuggling via chunk extension 
quoted strings.
+         CVE-2026-10050: Jetty Digest auth password encoding using ISO-8859-1.
+         Both affect Jetty shaded inside hadoop-client-runtime-3.5.0.jar. 
Druid cannot upgrade
+         the Jetty version inside this shaded jar. The shaded Jetty is used 
only for Hadoop's
+         internal HTTP server (WebHDFS, etc.), not for Druid's own HTTP server 
(Jetty 12.x).
+         Druid does not use Hadoop's embedded Jetty server or Digest auth. -->
+    <notes><![CDATA[
+      file name: hadoop-client-runtime-3.5.0.jar (shaded org.eclipse.jetty* 
9.4.58.v20250814)
+    ]]></notes>
+    <filePath 
regex="true">.*/(hadoop-client-runtime)-[0-9][^/]*\.jar/META-INF/maven/org\.eclipse\.jetty[^/]*/[^/]*/pom\.xml$</filePath>
+    <cve>CVE-2026-2332</cve>
+    <cve>CVE-2026-10050</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-56741, CVE-2026-56740: DoS via JLine Telnet server (NAWS 
terminal dimensions and
+         NEW-ENVIRON flooding). JLine is shaded inside 
hadoop-client-runtime-3.5.0.jar and is used
+         only for Hadoop's interactive CLI shell. Druid does not expose a 
JLine Telnet server endpoint. -->
+    <notes><![CDATA[
+      file name: hadoop-client-runtime-3.5.0.jar (shaded jline 3.9.0)
+    ]]></notes>
+    <filePath 
regex="true">.*/(hadoop-client-runtime)-[0-9][^/]*\.jar/META-INF/maven/org\.jline/jline[^/]*/pom\.xml$</filePath>
+    <cve>CVE-2026-56741</cve>
+    <cve>CVE-2026-56740</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-24051, CVE-2026-39883, CVE-2026-29181: All three affect the 
OpenTelemetry Go SDK
+         (opentelemetry-go), not any Java library. The scanner matches 
opentelemetry-gcp-resources
+         (a Java artifact) against the Go SDK CPE due to the shared 
"opentelemetry" product name.
+         Druid's google-extensions use the Java opentelemetry-gcp-resources 
for GCP resource
+         detection; the vulnerable PATH hijacking and baggage-header 
amplification code exists
+         only in the Go implementation. -->
+    <notes><![CDATA[
+      file name: opentelemetry-gcp-resources-1.37.0-alpha.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/io\.opentelemetry\.contrib/opentelemetry-gcp-resources@.*$</packageUrl>
+    <cve>CVE-2026-24051</cve>
+    <cve>CVE-2026-39883</cve>
+    <cve>CVE-2026-29181</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-40542, CVE-2026-71290: Vulnerabilities in Apache HttpClient 
5 (SCRAM mutual auth
+         and async hostname verification). CVE-2026-54399, CVE-2026-54428: DoS 
in Apache HttpComponents
+         Core 5 (excessive headers and HTTP/2 HPACK). All four affect 
httpclient5/httpcore5 shaded
+         inside docker-java-transport-zerodep-3.7.1.jar (a test-scoped 
dependency used only by
+         druid-testcontainers for Docker container management in tests). These 
are not present in
+         Druid's production runtime classpath. -->
+    <notes><![CDATA[
+      file name: docker-java-transport-zerodep-3.7.1.jar (shaded httpclient5 
5.5.1 and httpcore5 5.3.6)
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/org\.apache\.httpcomponents\.(client5/httpclient5|core5/httpcore5)@.*$</packageUrl>
+    <cve>CVE-2026-40542</cve>
+    <cve>CVE-2026-71290</cve>
+    <cve>CVE-2026-54399</cve>
+    <cve>CVE-2026-54428</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-87823: Out-of-bounds memory read in ByteBuffer frame-size 
methods via negative offset values.
+         CVE-2026-87795: Out-of-bounds memory read in ZstdDictCompress 
constructor via unvalidated offset/length.
+         Both are fixed in zstd-jni 1.5.7-14. Suppressed until zstd-jni is 
upgraded.
+         Based on the analysis in 
https://github.com/apache/druid/pull/20236#issuecomment-5646494509,
+         this vulnerability should not affect Druid since the relevant code 
paths do not get activated
+          -->
+    <notes><![CDATA[
+      file name: zstd-jni-1.5.7-11.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/com\.github\.luben/zstd-jni@.*$</packageUrl>

Review Comment:
   [P2] Scope the zstd suppressions to the audited version
   
   **Finding:** The rule suppresses both zstd CVEs for every 
com.github.luben:zstd-jni version, while its notes identify only 
zstd-jni-1.5.7-11 and state that the fixes arrive in 1.5.7-14. A future 
downgrade or dependency-resolution change to another affected zstd-jni version 
would therefore be hidden without the call-path review documented here.
   
   **Suggestion:** Match the documented zstd-jni version explicitly (for 
example, 1.5.7-11), or use a verified containing-file/path matcher, and remove 
or revise the rule when upgrading to the fixed version.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to