Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FP]: CVE flagged for reporting the vulnerability on logback version in which it is already fixed. #7399

Open
vinay871 opened this issue Feb 12, 2025 · 4 comments

Comments

@vinay871
Copy link

Package URl

Package information not available in report.

CPE

cpe:2.3:a:qos:logback:1.0.15.53:::::::*

CVE

CVE-2017-5929

ODC Integration

{"label" => "Docker"}

ODC Version

7.1.0

Description

This vulnerability is reported on logback 3PP used in the apppliction. But this vulnerability is applicable on 3PP version <1.2.0. However the version of logback 3PP used in this context is 1.2.13.

@vinay871 vinay871 changed the title [FP]: CVE flagged for reporting the vulnerability on version in which it is already fixed. [FP]: CVE flagged for reporting the vulnerability on logback version in which it is already fixed. Feb 12, 2025
Copy link
Contributor

Error parsing package url: Package information not available in report..

Error: Error: Invalid purl: missing required "pkg" scheme component

Please correct the package URL - consider copying the package url from the HTML report.

Copy link
Contributor

Failed to automatically evaluate the false positive. See: https://github.com/jeremylong/DependencyCheck/actions/runs/13293041521

Copy link
Contributor

Error parsing package url: Package information not available in report..

Error: Error: Invalid purl: missing required "pkg" scheme component

Please correct the package URL - consider copying the package url from the HTML report.

Copy link
Contributor

Failed to automatically evaluate the false positive. See: https://github.com/jeremylong/DependencyCheck/actions/runs/13293047631

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant