From 2de26c7357e648a3f4a40dce9209806b9a34d445 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 18 Nov 2024 13:51:10 +0000 Subject: [PATCH 1/2] Bump org.springframework:spring-web from 6.1.14 to 6.2.0 Bumps [org.springframework:spring-web](https://github.com/spring-projects/spring-framework) from 6.1.14 to 6.2.0. - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](https://github.com/spring-projects/spring-framework/compare/v6.1.14...v6.2.0) --- updated-dependencies: - dependency-name: org.springframework:spring-web dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- spring/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/spring/pom.xml b/spring/pom.xml index c817280bddf..a89e4273952 100644 --- a/spring/pom.xml +++ b/spring/pom.xml @@ -95,7 +95,7 @@ org.springframework spring-web - 6.1.14 + 6.2.0 provided From 4d79218e4ca26ed858ff3092d6aa95fe015f1f4a Mon Sep 17 00:00:00 2001 From: Aaron Coburn Date: Mon, 18 Nov 2024 10:28:17 -0600 Subject: [PATCH 2/2] Adjust owasp configuration --- build-tools/owasp/suppressions.xml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/build-tools/owasp/suppressions.xml b/build-tools/owasp/suppressions.xml index 9d2f12c8536..4330c57685d 100644 --- a/build-tools/owasp/suppressions.xml +++ b/build-tools/owasp/suppressions.xml @@ -25,4 +25,11 @@ ^pkg:maven/org\.eclipse\.jetty/jetty-server@.*$ CVE-2024-8184 + + + ^pkg:maven/org\.springframework\..*@.*$ + CVE-2024-38828 +