Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False positive with Netty #1653

Closed
coheigea opened this issue Jan 2, 2019 · 1 comment
Closed

False positive with Netty #1653

coheigea opened this issue Jan 2, 2019 · 1 comment

Comments

@coheigea
Copy link

coheigea commented Jan 2, 2019

There is a false positive for Netty, where it is reporting an issue in another project:

netty-all-4.0.44.Final.jar (cpe:/a:netty_project:netty:4.0.44, cpe:/a:all-for-one:all_for_one:4.0.44, io.netty:netty-all:4.0.44.Final) : CVE-2018-12056

asfgit pushed a commit to apache/zookeeper that referenced this issue Feb 2, 2019
- Upgrade Jetty to 9.4.14.v20181114
- Upgrade Jackson to 2.9.8
- Suppress a false positive about Netty  (jeremylong/DependencyCheck#1653)
- Suppress false positives against ZooKeeper itself: CVE-2018-8012 and  CVE-2016-5017

Author: Enrico Olivelli <eolivelli@apache.org>

Reviewers: phunt@apache.org

Closes #792 from eolivelli/fix/ZOOKEEPER-3262

Change-Id: I6152ee061765a6eb7e4b9ac19db79d11bee4f4c5
eolivelli added a commit to eolivelli/zookeeper that referenced this issue Feb 6, 2019
- Upgrade Jetty to 9.4.14.v20181114
- Upgrade Jackson to 2.9.8
- Suppress a false positive about Netty  (jeremylong/DependencyCheck#1653)
- Suppress false positives against ZooKeeper itself: CVE-2018-8012 and  CVE-2016-5017

Author: Enrico Olivelli <eolivelli@apache.org>
eolivelli added a commit to eolivelli/zookeeper that referenced this issue Feb 6, 2019
- Upgrade Jetty to 9.4.14.v20181114
- Upgrade Jackson to 2.9.8
- Suppress a false positive about Netty  (jeremylong/DependencyCheck#1653)
- Suppress false positives against ZooKeeper itself: CVE-2018-8012 and  CVE-2016-5017

Author: Enrico Olivelli <eolivelli@apache.org>
asfgit pushed a commit to apache/zookeeper that referenced this issue Feb 7, 2019
- Upgrade Jetty to 9.4.14.v20181114
- Upgrade Jackson to 2.9.8
- Suppress a false positive about Netty  (jeremylong/DependencyCheck#1653)
- Suppress false positives against ZooKeeper itself: CVE-2018-8012 and  CVE-2016-5017

Author: Enrico Olivelli <eolivelliapache.org>

Author: Enrico Olivelli <eolivelli@gmail.com>
Author: Enrico Olivelli <eolivelli@apache.org>

Reviewers: andor@apache.org

Closes #805 from eolivelli/fix/owasp-35 and squashes the following commits:

811bfef [Enrico Olivelli] Merge branch 'branch-3.5' into fix/owasp-35
e7089a0 [Enrico Olivelli] ZOOKEEPER-3262: Update dependencies flagged by OWASP report
@jeremylong
Copy link
Owner

This has been fixed with the 5.x release.

@lock lock bot locked and limited conversation to collaborators Oct 21, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants