diff --git a/build.gradle b/build.gradle index d4137ed23..865331995 100644 --- a/build.gradle +++ b/build.gradle @@ -553,6 +553,10 @@ dependencyManagement { entry 'jackson-core' entry 'jackson-annotations' } + // CVE-2023-3635 override okio dependency in azure-servicebus:3.6.7 + dependencySet(group: 'com.squareup.okio', version: '3.5.0') { + entry 'okio' + } } } diff --git a/config/owasp/suppressions.xml b/config/owasp/suppressions.xml index a866b0379..48019c376 100644 --- a/config/owasp/suppressions.xml +++ b/config/owasp/suppressions.xml @@ -9,8 +9,4 @@ https://tools.hmcts.net/jira/browse/AM-2839 jackson-databind CVE-2023-35116 - - https://tools.hmcts.net/jira/browse/AM-2885 okio - CVE-2023-3635 -