Skip to content

Commit fd1a888

Browse files
committed
MSK CVE issues fix.
1 parent f98295b commit fd1a888

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

pom.xml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -382,6 +382,15 @@
382382
<exclude>META-INF/maven/com.google.api.grpc/grpc-google-cloud-bigquerystorage-v1/pom.properties</exclude>
383383
<exclude>META-INF/maven/com.google.api.grpc/proto-google-cloud-bigquerystorage-v1/pom.xml</exclude>
384384
<exclude>META-INF/maven/com.google.api.grpc/proto-google-cloud-bigquerystorage-v1/pom.properties</exclude>
385+
<!-- 10. Fix for CVE-2022-3510: proto-google-common-protos declares old protobuf-java -->
386+
<exclude>META-INF/maven/com.google.api.grpc/proto-google-common-protos/pom.xml</exclude>
387+
<exclude>META-INF/maven/com.google.api.grpc/proto-google-common-protos/pom.properties</exclude>
388+
<!-- 11. Fix for CVE-2025-48734: Exclude commons-validator metadata that declares vulnerable commons-beanutils -->
389+
<exclude>META-INF/maven/commons-validator/commons-validator/pom.xml</exclude>
390+
<exclude>META-INF/maven/commons-validator/commons-validator/pom.properties</exclude>
391+
<!-- 12. Fix for CVE-2025-48734: Exclude commons-digester metadata that declares vulnerable commons-beanutils -->
392+
<exclude>META-INF/maven/commons-digester/commons-digester/pom.xml</exclude>
393+
<exclude>META-INF/maven/commons-digester/commons-digester/pom.properties</exclude>
385394
</excludes>
386395
</filter>
387396
</filters>

0 commit comments

Comments
 (0)