Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

node.js stax vulnerability showing up in java #1424

Closed
stephengroat opened this issue Aug 6, 2018 · 2 comments
Closed

node.js stax vulnerability showing up in java #1424

stephengroat opened this issue Aug 6, 2018 · 2 comments

Comments

@stephengroat
Copy link
Contributor

stephengroat commented Aug 6, 2018

False positive on library stax:stax-api:1.0.1 - reported as cpe:/a:st_project:st:1.0.1 for CVE-2017-16224 - seems to me like it should be node only

<dependency>
    <groupId>stax</groupId>
    <artifactId>stax-api</artifactId>
    <version>1.0.1</version>
</dependency>
@jeremylong
Copy link
Owner

Thanks for the report - I will cycle through all of the FP reports before the next release.

@lock
Copy link

lock bot commented Oct 16, 2018

This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@lock lock bot locked and limited conversation to collaborators Oct 16, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants