Skip to content

[FP]: False positive finding in apache commons logging jar #8175

@ashu4

Description

@ashu4

Package URl

/opt/sign/EABss7024/lib/commons-logging-1.1.jar

CPE

cpe:2.3:a:apache:commons_net:1.1:::::::*

CVE

CVE-2021-37533

ODC Integration

{"label" => "Docker"}

ODC Version

12.1.3

Description

CVE-2021-37533 is specific to apache commons net 3pp. Although product includes apache commons logging jar at system path /opt/sign/EABss7024/lib/commons-logging-1.1.jar.
Dependency checker is incorrectly showing apache commons net vulnerability for apache commons logging jar.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions