Skip to content

[FP]: CVE-2018-11788 on cxf-karaf-commands-3.6.9 #8339

@prabutdr

Description

@prabutdr

Package URl

pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.6.9

CPE

cpe:2.3:a:apache:karaf:::::::: versions up to (excluding) 4.1.7

CVE

CVE-2018-11788

ODC Integration

None

ODC Version

12.2.0

Description

This CVE-2018-11788 impacts only on "apache:karaf" packages as per cpe provided by NVD. But tool is reporting CVE-2018-11788 on "org.apache.cxf.karaf/cxf-karaf-commands" jars as well, this is all together different package, which is wrong.

From Dependency Check tool team, we need confirmation on these false positives. Could you please validate and confirm?

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions