Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FP]: False positive findings in Dependency Checker for Product specific authenticator component #7388

Closed
ashu4 opened this issue Feb 10, 2025 · 3 comments

Comments

@ashu4
Copy link

ashu4 commented Feb 10, 2025

Package URl

pkg:[email protected]

CPE

cpe:2.3:a:authenticator:authenticator:0.1.0:snapshot::::::

CVE

CVE-2024-45394

ODC Integration

{"label" => "Docker"}

ODC Version

7.1.0

Description

Hi Team,

We are getting following vulnerabilities (CVEs) in Dependency Checker Tool findings, although as per our analysis we consider them as false positive.
CVEs details and our justification for false positive for each CVE is mentioned below.
Kindly check and get it fixed in Dependency Checker tool. So these false positive does not appear in scan report.

CVE-2024-45394

Justification: This vulnerability is related to Authenticator, a browser extension tool that adds two-factor authentication (2FA) functionality directly into your web browser.
We do not include authenticator tool although scanner is falsely identifying.
We include some jar file named as authenticator and not the authenticator tool.
Hence considering this vulnerability as false positive.

Copy link
Contributor

Error parsing package url: pkg:[email protected].

Error: Error: Invalid purl: type "[email protected]" contains an illegal character

Please correct the package URL - consider copying the package url from the HTML report.

Copy link
Contributor

Failed to automatically evaluate the false positive. See: https://github.com/jeremylong/DependencyCheck/actions/runs/13236472356

@aikebah
Copy link
Collaborator

aikebah commented Feb 12, 2025

Sounds like a proprietary library of your own (as your report does not have a valid packageURL as well as a SNAPSHOT version. Such FP's are to be expected by users due to how dependencycheck works and should be suppressed by yourself as documented - http://jeremylong.github.io/DependencyCheck/general/suppression.html

@aikebah aikebah closed this as not planned Won't fix, can't repro, duplicate, stale Feb 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants