Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FP]: Very old CVE-2014-3576 detected for Apache ActiveMQ 5.17.0 #6474

Closed
Gouri-19 opened this issue Feb 16, 2024 · 2 comments
Closed

[FP]: Very old CVE-2014-3576 detected for Apache ActiveMQ 5.17.0 #6474

Gouri-19 opened this issue Feb 16, 2024 · 2 comments

Comments

@Gouri-19
Copy link

Package URl

pkg:maven/xx-activemq-log-plugin@2.112.2

CPE

cpe:2.3:a:apache:activemq:2.112.2:::::::*

CVE

CVE-2014-3576

ODC Integration

None

ODC Version

8.4.3

Description

The CVE-2014-3576 was detected and reported by Owasp Dependency Check scan for Aapche ActiveMQ 5.17.0. The vulnerability description clearly states that the vulnerability exists in Apache ActiveMQ 5.x before 5.14.0. This is because, in the application code, xx-activemq-log-plugin takes the version as the project version. The Owasp Dependency report is picking and detecting it as ActiveMQ version and reporting the CVE in the scan report. Therefore, it is a false positive.

Copy link
Contributor

Failed to automatically evaluate the false positive. See: https://github.com/jeremylong/DependencyCheck/actions/runs/7933177995

@aikebah
Copy link
Collaborator

aikebah commented Feb 22, 2024

your package is likely sone private package. FPs for such nane collisions are to be expected(see the documentation of DependencyCheck) and dealt with internally for non-public artifacts

@aikebah aikebah closed this as not planned Won't fix, can't repro, duplicate, stale Mar 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants