This message was deleted.
# general
s
This message was deleted.
a
that is the intention, yes. If you think a suppression should be removed, let us know.
o
No ok for me, just an exemple for CVE-2019-20444 and CVE-2019-20445, how can we justify these supresses ? there is no specific comment for those 2 in the file.
l
Can you check the patch when they were added and see if there’s any justification in the corresponding PR?
o
Hello @Laksh Singla @Abhishek Agarwal back to this thread, I didn't find any relevent explanation on 20444 and 20445 exepct this PR which is not clear enough for me : https://github.com/apache/druid/pull/9300
Copy code
This change fixes the CVEs, CVE-2019-20445 and CVE-2019-20444, introduced into druid by netty. The vulnerabilities were fixed in a netty version 4 update, so the version of netty 4 has been updated. For Version 3 however, no fix exists, so the vulnerabilities were suppressed for version 3.
Why we still this thoses 2 VUL if version of netty 4 has been updated ?