Skip to content

Commit ab3b5e5

Browse files
authored
Merge pull request #303 from hmcts/CCD-1246-master
CCD-1246 CVE-2021-22112 (AAC Manage Case Assignment)
2 parents 5e61567 + e748ae3 commit ab3b5e5

File tree

2 files changed

+6
-7
lines changed

2 files changed

+6
-7
lines changed

build.gradle

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -273,10 +273,14 @@ dependencies {
273273
implementation group: 'uk.gov.hmcts.reform', name: 'idam-client', version: '1.5.5'
274274
implementation group: 'org.springframework.cloud', name: 'spring-cloud-starter-netflix-zuul', version: '2.2.3.RELEASE'
275275

276+
implementation "org.springframework.boot:spring-boot-starter-oauth2-client:2.3.8.RELEASE"
277+
implementation "com.nimbusds:nimbus-jose-jwt:7.9"
278+
implementation "net.minidev:json-smart:2.3"
276279
implementation "org.springframework.security:spring-security-web:5.4.5"
277280
implementation "org.springframework.security:spring-security-config:5.4.5"
278281
implementation "org.springframework.boot:spring-boot-starter-oauth2-client:2.4.5"
279282
implementation "org.springframework.boot:spring-boot-starter-oauth2-resource-server:2.4.5"
283+
280284
implementation "io.github.openfeign:feign-httpclient:11.0"
281285
testCompile 'io.github.openfeign:feign-jackson:10.7.0'
282286
testCompile group: 'io.github.openfeign.form', name: 'feign-form', version: '3.8.0'

config/owasp/suppressions.xml

Lines changed: 2 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
<?xml version="1.0" encoding="UTF-8"?>
22
<suppressions
33
xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
4+
45
<suppress until="2021-06-25">
56
<notes><![CDATA[
67
It's a false positive - spring-security version is 5.3.x (see: https://pivotal.io/security/cve-2018-1258)
@@ -24,11 +25,5 @@
2425
<cve>CVE-2007-1651</cve>
2526
<cve>CVE-2007-1652</cve>
2627
</suppress>
27-
28-
<suppress>
29-
<notes>Temporary suppression</notes>
30-
<cve>CVE-2021-22112</cve>
31-
<cve>CVE-2021-22118</cve>
32-
</suppress>
33-
28+
3429
</suppressions>

0 commit comments

Comments
 (0)