You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CVE-2023-4586 and sonatype-2020-0026 are reported in io.netty:netty-handler:4.1.109.Final.
Official reports such as GHSA-57m8-f3v5-hm5m flags up to 4.1.99.Final but it is still reporting in 4.1.109 also.
Can one of the maintainers confirm whether 4.1.109.Final is vulnerable or not?
The text was updated successfully, but these errors were encountered:
We can confirm nor deny, DependencyCheck simply reports on the information retrieved from OSSIndex and NVD data. Our automated scan however did not surface the issues, so it appears the attribution to unrelated versions has been fixed in the meanwhile in the OSSINDEX API.
I would expect on the next cache expiry of the OSSINDEX cache entry your false positive would disappear
Package URl
pkg:maven/io.netty/[email protected]
CPE
cpe:2.3:a:netty:netty:4.1.109:::::::*
CVE
CVE-2023-4586 and sonatype-2020-0026
ODC Integration
{"label"=>"Gradle Plugin"}
ODC Version
8.4.0
Description
CVE-2023-4586 and sonatype-2020-0026 are reported in io.netty:netty-handler:4.1.109.Final.
Official reports such as GHSA-57m8-f3v5-hm5m flags up to 4.1.99.Final but it is still reporting in 4.1.109 also.
Can one of the maintainers confirm whether 4.1.109.Final is vulnerable or not?
The text was updated successfully, but these errors were encountered: