Skip to content

[FP]: False positive findings in Dependency Checker for Apache Kafka #8131

@va699

Description

@va699

Package URl

pkg:maven/org.apache.kafka/[email protected]

CPE

cpe:2.3:a:scala-lang:scala:2.10.0:::::::*

CVE

CVE-2017-15288

ODC Integration

{"label" => "Docker"}

ODC Version

12

Description

Hi Team,

We are getting vulnerability CVE-2017-15288 in Dependency Checker Tool findings, although as per our analysis we consider it as false positive.

Kindly check and get it fixed in Dependency Checker tool. So, this false positive does not appear in scan report.

Dependency Checker tool is scanning below mentioned path
pkg:maven/org.apache.kafka/[email protected]

Justification: This vulnerability is reported on kafka version 3.6.2, 3.7.1, 3.8.1 However in product, kafka 3.9.0 version is present.

Hence this vulnerability is false positive.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions