New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
False positive with Netty #1653
Comments
asfgit
pushed a commit
to apache/zookeeper
that referenced
this issue
Feb 2, 2019
- Upgrade Jetty to 9.4.14.v20181114 - Upgrade Jackson to 2.9.8 - Suppress a false positive about Netty (jeremylong/DependencyCheck#1653) - Suppress false positives against ZooKeeper itself: CVE-2018-8012 and CVE-2016-5017 Author: Enrico Olivelli <eolivelli@apache.org> Reviewers: phunt@apache.org Closes #792 from eolivelli/fix/ZOOKEEPER-3262 Change-Id: I6152ee061765a6eb7e4b9ac19db79d11bee4f4c5
eolivelli
added a commit
to eolivelli/zookeeper
that referenced
this issue
Feb 6, 2019
- Upgrade Jetty to 9.4.14.v20181114 - Upgrade Jackson to 2.9.8 - Suppress a false positive about Netty (jeremylong/DependencyCheck#1653) - Suppress false positives against ZooKeeper itself: CVE-2018-8012 and CVE-2016-5017 Author: Enrico Olivelli <eolivelli@apache.org>
eolivelli
added a commit
to eolivelli/zookeeper
that referenced
this issue
Feb 6, 2019
- Upgrade Jetty to 9.4.14.v20181114 - Upgrade Jackson to 2.9.8 - Suppress a false positive about Netty (jeremylong/DependencyCheck#1653) - Suppress false positives against ZooKeeper itself: CVE-2018-8012 and CVE-2016-5017 Author: Enrico Olivelli <eolivelli@apache.org>
asfgit
pushed a commit
to apache/zookeeper
that referenced
this issue
Feb 7, 2019
- Upgrade Jetty to 9.4.14.v20181114 - Upgrade Jackson to 2.9.8 - Suppress a false positive about Netty (jeremylong/DependencyCheck#1653) - Suppress false positives against ZooKeeper itself: CVE-2018-8012 and CVE-2016-5017 Author: Enrico Olivelli <eolivelliapache.org> Author: Enrico Olivelli <eolivelli@gmail.com> Author: Enrico Olivelli <eolivelli@apache.org> Reviewers: andor@apache.org Closes #805 from eolivelli/fix/owasp-35 and squashes the following commits: 811bfef [Enrico Olivelli] Merge branch 'branch-3.5' into fix/owasp-35 e7089a0 [Enrico Olivelli] ZOOKEEPER-3262: Update dependencies flagged by OWASP report
This has been fixed with the 5.x release. |
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
There is a false positive for Netty, where it is reporting an issue in another project:
netty-all-4.0.44.Final.jar (cpe:/a:netty_project:netty:4.0.44, cpe:/a:all-for-one:all_for_one:4.0.44, io.netty:netty-all:4.0.44.Final) : CVE-2018-12056
The text was updated successfully, but these errors were encountered: