Summary
Catch-all bucket for GAVs that do not fit any other T2.x sub-task (commons-net, dom4j, jdom, jaxen, json, jsoup, gson, guava, httpclient, netty, jackson-dataformat-*, BouncyCastle JDK15to18 pin, Shiro 1.13.0 pin, jackrabbit-jcr-commons <2.21 pin, etc.). All CVEs are pinned at the latest Java 1.8 line; residual CVEs close when the Java 11+ migration epic lands. Per-GAV mitigations documented in docs/SECURITY-MITIGATIONS.md T2.20 entry.
Mitigation matrix
See docs/SECURITY-MITIGATIONS.md T2.20 entry for the per-GAV mitigation table.
OWASP suppressions
Per-GAV suppressions are in owasp-suppressions.xml with notes describing the per-GAV disposition.
Closing evidence
docs/SECURITY-MITIGATIONS.md T2.20 entry
owasp-suppressions.xml
References
Summary
Catch-all bucket for GAVs that do not fit any other T2.x sub-task (commons-net, dom4j, jdom, jaxen, json, jsoup, gson, guava, httpclient, netty, jackson-dataformat-*, BouncyCastle JDK15to18 pin, Shiro 1.13.0 pin, jackrabbit-jcr-commons <2.21 pin, etc.). All CVEs are pinned at the latest Java 1.8 line; residual CVEs close when the Java 11+ migration epic lands. Per-GAV mitigations documented in docs/SECURITY-MITIGATIONS.md T2.20 entry.
Mitigation matrix
See
docs/SECURITY-MITIGATIONS.mdT2.20 entry for the per-GAV mitigation table.OWASP suppressions
Per-GAV suppressions are in
owasp-suppressions.xmlwith notes describing the per-GAV disposition.Closing evidence
docs/SECURITY-MITIGATIONS.mdT2.20 entryowasp-suppressions.xmlReferences