Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False positives on the spring boot 1.4.3 dependencies #642

ltoublanc opened this issue Jan 11, 2017 · 3 comments


Copy link

commented Jan 11, 2017

It looks like the dependency check mismatch the version of the spring artifacts (e.g. spring-boot) and the version of the spring-core artifact, which is vulnerable on a version older than 4.3.5.

The spring framework release to fix the CVE-2016-9878 is 4.3.5, as announced here and this version is included as part of the spring boot 1.4.3 release.

Dependency location:


  • cpe:/a:pivotal:spring_framework:1.4.3
  • cpe:/a:pivotal_software:spring_framework:1.4.3

Below is a screenshot of the report, the false positive is for all the spring dependencies using spring-core, so the list is non exhaustive.
screen shot 2017-01-11 at 12 18 47


This comment has been minimized.

Copy link

commented Jan 14, 2017

Fixed in commit 8733a85. This will be included in the next release.

@jeremylong jeremylong closed this Jan 14, 2017


This comment has been minimized.

Copy link

commented Feb 6, 2017


Looks like this is solved for springboot dependency, but springcloud, which i dont believe is affected by this vulnerability, is still being reported


This comment has been minimized.

Copy link

commented Sep 28, 2018

This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@lock lock bot locked and limited conversation to collaborators Sep 28, 2018

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
None yet
3 participants
You can’t perform that action at this time.