File tree Expand file tree Collapse file tree 1 file changed +5
-3
lines changed
Expand file tree Collapse file tree 1 file changed +5
-3
lines changed Original file line number Diff line number Diff line change 1111 We are suppressing this because it is believed by the ESAPI and AntiSamy teams that it is a false positive.
1212 Dependency Check itself doesn't flag this and neither does Snyk. Dependency Check reports it because it is reported
1313 directly by Sonatype's OSS Index. For futher details, see
14- https://ossindex.sonatype.org/vulnerability/sonatype-2017-0348?component-type=maven&component-name=xerces%2FxercesImpl
14+ https://ossindex.sonatype.org/vulnerability/CVE-2017-10355?component-type=maven&component-name=xerces/xercesImpl
15+ and https://github.com/OSSIndex/vulns/issues/328#issuecomment-1287175491.
1516
1617 OSS Index seems to have the wrong CPE. They have 'cpe:2.3:a:xerces:xercesImpl:2.12.2:*:*:*:*:*:*:*', whereas the CPE IDs
1718 associated with NVD are 'cpe:2.3:a:apache:xerces-j:2.12.2:*:*:*:*:*:*:*' and
18- 'cpe:2.3:a:apache:xerces2_java:2.12.2:*:*:*:*:*:*:*'.
19+ 'cpe:2.3:a:apache:xerces2_java:2.12.2:*:*:*:*:*:*:*'. (Note: as of Nov 2024, none of the CPEs even mention Xerces, but
20+ rather seem to only refer to the JREs.)
1921
20- Note also that this has been reported as GitHub issue #a 4614
22+ Note also that this has been reported as GitHub issue # 4614 for OWASP Dependency Check. For details, see
2123 https://github.com/jeremylong/DependencyCheck/issues/4614
2224 ]]> </notes >
2325 <sha1 >f051f988aa2c9b4d25d05f95742ab0cc3ed789e2</sha1 >
You can’t perform that action at this time.
0 commit comments