Skip to content

VulnerableGavs.csv #11

@henrikplate

Description

@henrikplate

Dear Andreas, all,

Great tool, thank you for taking this initiative!

I just had a quick look at VulnerableGavs.csv and noticed that groupId and artifactId are confused for some of the GAVs (e.g. io.apiman:apiman-gateway-platforms-vertx3).

Also, I wondered whether you think it is useful to add an additional column indicating whether the respective GAV declares a dependency on the original log4j-core, or whether it re-bundles the vulnerable code. The presence of a classifier may be an approximation, but does not cover all cases (e.g. org.ops4j.pax.logging:pax-logging-log4j2 re-bundles a vulnerable log4j-core version, but does not have a classifier).

Cheers, Henrik

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions