Skip to content

[FP]: False positive for apache-el-11.0.0.jar against multiple jetty 11 CVE's #7835

@vbode

Description

@vbode

Package URl

Package URI does not show up in Report

CPE

cpe:2.3:a:eclipse:jetty:11.0.9:::::::*

CVE

Multiple CVE's

ODC Integration

None

ODC Version

12.1.3

Description

This report is very similar to:
#7145

However now, I can't the suppression working on PackageURL, just on SHA, since the packageUrl does not show up in the report.
Possibly this is also why the FP is no longer suppressed by the hosted suppression.

This is how it shows up in the report:

Image

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions