Skip to content

[FP]: False positive findings in Dependency Checker for Logback #7873

@va699

Description

@va699

Package URl

pkg:maven/ch.qos.logback/logback-core@1.2.13

CPE

cpe:2.3:a:qos:logback:1.0.15.56:::::::*

CVE

CVE-2017-5929

ODC Integration

{"label" => "Docker"}

ODC Version

12.1.0

Description

CVE-2017-5929 is erroneously reported for the product. Product is using logback version 1.2.13 and CVE could only impact wehre version < 1.2.0

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions