You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Probably Grype is comparing to NVD, anything less then 2.7.2 is at fault.
cpe:2.3:a:apache:xalan-java:::::::: Show Matching CPE(s) | Up to (including)2.7.2
What happened:
When scan a container that has xalan-2.7.1.redhat-00013.jar listed.
/modules/system/layers/base/.overlays/layer-base-jboss-eap-/org/apache/xalan/main/xalan-
2.7.1.redhat-00013.jar
It links to CVE-2022-34169.
What you expected to happen:
According to Red Hat JBOSS EAP, xalan-
2.7.1.redhat-00013.jar, CVE-2022-34169 is not affected.
See reference in Red Hat reference for that issue:
https://access.redhat.com/solutions/6994572
Probably Grype is comparing to NVD, anything less then 2.7.2 is at fault.
cpe:2.3:a:apache:xalan-java:::::::: Show Matching CPE(s) | Up to (including)2.7.2
Environment:
grype version
:Application: grype
Version: 0.69.1
BuildDate: 2023-09-28T00:36:53Z
GitCommit: dec5636
GitDescription: v0.69.1
Platform: linux/amd64
GoVersion: go1.21.1
Compiler: gc
Syft Version: v0.92.0
The text was updated successfully, but these errors were encountered: