diff --git a/.build/owasp/dependency-check-suppressions.xml b/.build/owasp/dependency-check-suppressions.xml index 16e9a81915..a2c92ebde3 100644 --- a/.build/owasp/dependency-check-suppressions.xml +++ b/.build/owasp/dependency-check-suppressions.xml @@ -26,6 +26,12 @@ CVE-2023-44487 + + + ^pkg:maven/io\.netty/netty\-.*@.*$ + CVE-2025-25193 + + ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$ diff --git a/.snyk b/.snyk index e111ff3e10..aae9ae4084 100644 --- a/.snyk +++ b/.snyk @@ -16,3 +16,5 @@ ignore: - reason: Suppressed due to internal review, see project's .build/dependency-check-suppressions.xml CVE-2024-45772: - reason: https://issues.apache.org/jira/browse/CASSANDRA-20024 -- ^pkg:maven/org\.apache\.lucene/lucene\-.*@9.7.0$ + CVE-2025-25193: + - reason: https://issues.apache.org/jira/browse/CASSANDRA-20504 -- ^pkg:maven/io\.netty/netty\-.*@.*$ diff --git a/CHANGES.txt b/CHANGES.txt index c1ee79f162..9bf7069174 100644 --- a/CHANGES.txt +++ b/CHANGES.txt @@ -215,6 +215,7 @@ Merged from 4.1: * Enforce CQL message size limit on multiframe messages (CASSANDRA-20052) * Fix race condition in DecayingEstimatedHistogramReservoir during rescale (CASSANDRA-19365) Merged from 4.0: + * Suppress CVE-2025-25193 (CASSANDRA-20504) * Include in source tree and build packages a Snyk policy file that lists known false positives (CASSANDRA-20319) * Update zstd-jni to 1.5.7-2 (CASSANDRA-20453) * Suppress CVE-2024-12801 (CASSANDRA-20412)