diff --git a/buildscripts/dependency-check-suppressions.xml b/buildscripts/dependency-check-suppressions.xml index 8d3d79c55b7..5548d5106dc 100644 --- a/buildscripts/dependency-check-suppressions.xml +++ b/buildscripts/dependency-check-suppressions.xml @@ -1,18 +1,10 @@ - commons-codec should not be matched to commons_net - ^pkg:maven/commons-codec/commons-codec@.*$ - cpe:/a:apache:commons_net - - - commons-text should not be matched to commons_net - ^pkg:maven/org.apache.commons/commons-text@.*$ - cpe:/a:apache:commons_net - - - jcl-over-slf4j should not be matched to commons_net - ^pkg:maven/org.slf4j/jcl-over-slf4j@.*$ - cpe:/a:apache:commons_net + + CVE-2023-35116 is not a valid CVE, see comment from library maintainer + https://github.com/FasterXML/jackson-databind/issues/3972#issuecomment-1596308216 + + CVE-2023-35116