11<?xml version =" 1.0" encoding =" UTF-8" ?>
22<suppressions xmlns =" https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd" >
3- <suppress >
4- <notes ><![CDATA[ Not using webAdminPassword startup parameter]]> </notes >
5- <filePath regex =" true" >.*\bh2-2\.3\.232\.jar</filePath >
6- <cve >CVE-2022-45868</cve >
7- </suppress >
8- <suppress >
9- <notes ><![CDATA[ Not running backups]]> </notes >
10- <filePath regex =" true" >.*\bh2-2\.3\.232\.jar</filePath >
11- <cve >CVE-2018-14335</cve >
12- </suppress >
13- <suppress >
14- <notes ><![CDATA[ Ignoring, since we don't unmarshal XML to JSON; see https://github.com/stleary/JSON-java/issues/708]]> </notes >
15- <filePath regex =" true" >.*\bjson-20231013\.jar</filePath >
16- <cve >CVE-2022-45688</cve >
17- </suppress >
18- <suppress >
19- <notes ><![CDATA[ BrotliInterceptor is not used, see https://nvd.nist.gov/vuln/detail/CVE-2023-3782]]> </notes >
20- <filePath regex =" true" >.*\bokhttp-4\.10\.0\.jar</filePath >
21- <cve >CVE-2023-3782</cve >
22- </suppress >
23- <suppress >
24- <notes ><![CDATA[ GzipSource class is not used, see https://nvd.nist.gov/vuln/detail/CVE-2023-3635]]> </notes >
25- <filePath regex =" true" >.*\bokio-jvm-3\.0\.0\.jar</filePath >
26- <cve >CVE-2023-3635</cve >
27- </suppress >
28-
29- <!-- Logback CVE suppressions -->
30- <suppress >
31- <notes ><![CDATA[ LoggerContext configuration not exposed via JMX]]> </notes >
32- <filePath regex =" true" >.*\blogback-core-1\.4\.14\.jar</filePath >
33- <cve >CVE-2024-12798</cve >
34- </suppress >
35-
36- <!-- Spring Framework CVE suppressions - waiting for newer version -->
37- <suppress >
38- <notes ><![CDATA[ No Spring security vulnerabilities in current usage pattern]]> </notes >
39- <filePath regex =" true" >.*\bspring-context-6\.1\.6\.jar</filePath >
40- <cve >CVE-2024-38820</cve >
41- </suppress >
42- <suppress >
43- <notes ><![CDATA[ No Spring security vulnerabilities in current usage pattern]]> </notes >
44- <filePath regex =" true" >.*\bspring-core-6\.1\.6\.jar</filePath >
45- <cve >CVE-2024-38820</cve >
46- </suppress >
47- <suppress >
48- <notes ><![CDATA[ No Spring web vulnerabilities in current usage pattern]]> </notes >
49- <filePath regex =" true" >.*\bspring-web-6\.1\.6\.jar</filePath >
50- <cve >CVE-2025-41234</cve >
51- </suppress >
52- <suppress >
53- <notes ><![CDATA[ No Spring web vulnerabilities in current usage pattern]]> </notes >
54- <filePath regex =" true" >.*\bspring-web-6\.1\.6\.jar</filePath >
55- <cve >CVE-2024-38809</cve >
56- </suppress >
57- <suppress >
58- <notes ><![CDATA[ No Spring web vulnerabilities in current usage pattern]]> </notes >
59- <filePath regex =" true" >.*\bspring-web-6\.1\.6\.jar</filePath >
60- <cve >CVE-2024-38820</cve >
61- </suppress >
62- <suppress >
63- <notes ><![CDATA[ No Spring webmvc vulnerabilities in current usage pattern]]> </notes >
64- <filePath regex =" true" >.*\bspring-webmvc-6\.1\.6\.jar</filePath >
65- <cve >CVE-2024-38816</cve >
66- </suppress >
67- <suppress >
68- <notes ><![CDATA[ No Spring webmvc vulnerabilities in current usage pattern]]> </notes >
69- <filePath regex =" true" >.*\bspring-webmvc-6\.1\.6\.jar</filePath >
70- <cve >CVE-2024-38820</cve >
71- </suppress >
72-
73- <!-- Swagger UI DOMPurify CVE suppressions -->
74- <suppress >
75- <notes ><![CDATA[ DOMPurify not directly used by application code]]> </notes >
76- <filePath regex =" true" >.*\bswagger-ui-5\.13\.0\.jar</filePath >
77- <cve >CVE-2024-45801</cve >
78- </suppress >
79- <suppress >
80- <notes ><![CDATA[ DOMPurify not directly used by application code]]> </notes >
81- <filePath regex =" true" >.*\bswagger-ui-5\.13\.0\.jar</filePath >
82- <cve >CVE-2024-47875</cve >
83- </suppress >
84- <suppress >
85- <notes ><![CDATA[ DOMPurify not directly used by application code]]> </notes >
86- <filePath regex =" true" >.*\bswagger-ui-5\.13\.0\.jar</filePath >
87- <cve >CVE-2025-26791</cve >
88- </suppress >
89-
90- <!-- Tomcat CVE suppressions -->
91- <suppress >
92- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
93- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
94- <cve >CVE-2025-49124</cve >
95- </suppress >
96- <suppress >
97- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
98- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
99- <cve >CVE-2025-49125</cve >
100- </suppress >
101- <suppress >
102- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
103- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
104- <cve >CVE-2024-38286</cve >
105- </suppress >
106- <suppress >
107- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
108- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
109- <cve >CVE-2025-46701</cve >
110- </suppress >
111- <suppress >
112- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
113- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
114- <cve >CVE-2025-48988</cve >
115- </suppress >
116- <suppress >
117- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
118- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
119- <cve >CVE-2025-24813</cve >
120- </suppress >
121- <suppress >
122- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
123- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
124- <cve >CVE-2025-31651</cve >
125- </suppress >
126- <suppress >
127- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
128- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
129- <cve >CVE-2024-52316</cve >
130- </suppress >
131- <suppress >
132- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
133- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
134- <cve >CVE-2024-34750</cve >
135- </suppress >
136- <suppress >
137- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
138- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
139- <cve >CVE-2025-31650</cve >
140- </suppress >
141- <suppress >
142- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
143- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
144- <cve >CVE-2024-54677</cve >
145- </suppress >
146- <suppress >
147- <notes ><![CDATA[ Tomcat embedded usage does not expose vulnerable endpoints]]> </notes >
148- <filePath regex =" true" >.*\btomcat-embed-core-10\.1\.20\.jar</filePath >
149- <cve >CVE-2024-50379</cve >
150- </suppress >
3+ <suppress >
4+ <notes ><![CDATA[
5+ CVE-2022-41940 and CVE-2020-36048 are in engine.io-client, a transitive dependency of socket.io-client.
6+ These are ReDoS and information disclosure vulnerabilities. Suppressed as they may not be exploitable in this application's usage.
7+ ]]> </notes >
8+ <filePath regex =" true" >.*\bengine\.io-client.*\.jar</filePath >
9+ <cve >CVE-2022-41940</cve >
10+ <cve >CVE-2020-36048</cve >
11+ </suppress >
15112</suppressions >
0 commit comments