Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Wrong CPE for org.evolvis.tartools:background-jobs #6638

Closed
mirabilos opened this issue May 2, 2024 · 2 comments
Closed

Wrong CPE for org.evolvis.tartools:background-jobs #6638

mirabilos opened this issue May 2, 2024 · 2 comments
Labels

Comments

@mirabilos
Copy link

Describe the bug
I get a bogus report:

background-jobs-1.27.jar (pkg:maven/org.evolvis.tartools/[email protected], cpe:2.3:a:jobs-plugin_project:jobs-plugin:1.27:::::::*) : CVE-2014-125035

The CPE is wrong. Jobs-Plugin is https://github.com/mrbobbybryant/Jobs-Plugin and a PHP project.

Version of dependency-check used
org.owasp:dependency-check-maven:9.1.0:aggregate

Log file
There’s nothing in the full log that stands out, this is just a CPE mismapping issue. I can provide it on request if you really want it, but…

@mirabilos mirabilos added the bug label May 2, 2024
@jeremylong
Copy link
Owner

@jeremylong
Copy link
Owner

If you are going to report this again after I close this issue - please use the false positive template.

@jeremylong jeremylong added question and removed bug labels May 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants