From 07a3299bb7f8a7eeec00caaacd930b267df88685 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 18 Nov 2024 14:17:18 +0000 Subject: [PATCH 1/2] Bump org.springframework:spring-web from 6.1.14 to 6.2.0 Bumps [org.springframework:spring-web](https://github.com/spring-projects/spring-framework) from 6.1.14 to 6.2.0. - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](https://github.com/spring-projects/spring-framework/compare/v6.1.14...v6.2.0) --- updated-dependencies: - dependency-name: org.springframework:spring-web dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- spring/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/spring/pom.xml b/spring/pom.xml index d20ff757746..d9dc152dcc6 100644 --- a/spring/pom.xml +++ b/spring/pom.xml @@ -100,7 +100,7 @@ org.springframework spring-web - 6.1.14 + 6.2.0 provided From 8af6c1a2b50a94e657c5f0a441489cbe020786d8 Mon Sep 17 00:00:00 2001 From: Aaron Coburn Date: Mon, 18 Nov 2024 10:30:43 -0600 Subject: [PATCH 2/2] Adjust owasp configuration --- build-tools/owasp/suppressions.xml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/build-tools/owasp/suppressions.xml b/build-tools/owasp/suppressions.xml index 9d2f12c8536..4330c57685d 100644 --- a/build-tools/owasp/suppressions.xml +++ b/build-tools/owasp/suppressions.xml @@ -25,4 +25,11 @@ ^pkg:maven/org\.eclipse\.jetty/jetty-server@.*$ CVE-2024-8184 + + + ^pkg:maven/org\.springframework\..*@.*$ + CVE-2024-38828 +