Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FP]: False positive findings in Dependency Checker of Java Component #7384

Open
ashu4 opened this issue Feb 10, 2025 · 1 comment
Open

[FP]: False positive findings in Dependency Checker of Java Component #7384

ashu4 opened this issue Feb 10, 2025 · 1 comment

Comments

@ashu4
Copy link

ashu4 commented Feb 10, 2025

Package URl

pkg:Java8/1.8.0.421/1/fast/jdk1.8.0.421/jre/lib/jfr.jar

CPE

cpe:2.3:a:oracle:jrockit:1.8.0.421:::::::*

CVE

No response

ODC Integration

{"label" => "Docker"}

ODC Version

7.1.0

Description

Hi Team,

We are getting following vulnerabilities (CVEs) in Dependency Checker Tool findings, although as per our analysis we consider them as false positive.
CVEs details and our justification for false positive for each CVE is mentioned below.
Kindly check and get it fixed in Dependency Checker tool. So these false positive does not appear in scan report.

<CVE-2009-1006,CVE-2011-3545,CVE-2013-2380,CVE-2013-5782,CVE-2013-5830,CVE-2011-3556,CVE-2013-5802,CVE-2011-3551>
Dependency Checker tool is scanning below mentioned path
File Path:Java8/1.8.0.421/1/fast/jdk1.8.0.421/jre/lib/jfr.jar

Justification: These vulnerabilities are related to Oracle JAVA 7, JAVA 6, JAVA 5 and earlier and Oracle Fusion Middleware and Java Jrockit. We have JAVA 8 only and also does not include Oracle Fusion Middleware and Java Jrockit.
Hence these vulnerabilities are false positive.

@aikebah
Copy link
Collaborator

aikebah commented Feb 12, 2025

Seems to be not reproducible with an up-to-date CLI, but due to Oracle licensing its JVM I can only validate with openJDK builds - update your CLI and if still there report back with full evidence list of the library

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants