We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Describe the bug We do not use commons-beanutils-1.9.3.jar in the product image and ARM XRay version: 3.47.3 reported http://nvd.nist.gov/vuln/detail/CVE-2014-0114 on that package
To Reproduce Download ARM XRay version: 3.47.3 from https://www.jfrog.com/confluence/display/JFROG/Xray+Release+Notes#XrayReleaseNotes-Xray3.47.3 and scan an image without commons-beanutils-1.9.3.jar
Expected behavior As the product image does not have this 3PP, it should not be a vulnerability;
Screenshots scan tool: ARM XRay version: 3.47.3 3PP: commons-beanutils-1.9.3.jar
The text was updated successfully, but these errors were encountered:
No branches or pull requests
Describe the bug
We do not use commons-beanutils-1.9.3.jar in the product image and ARM XRay version: 3.47.3 reported http://nvd.nist.gov/vuln/detail/CVE-2014-0114 on that package
To Reproduce
Download ARM XRay version: 3.47.3 from https://www.jfrog.com/confluence/display/JFROG/Xray+Release+Notes#XrayReleaseNotes-Xray3.47.3 and scan an image without commons-beanutils-1.9.3.jar
Expected behavior
As the product image does not have this 3PP, it should not be a vulnerability;
Screenshots
scan tool: ARM XRay version: 3.47.3
3PP: commons-beanutils-1.9.3.jar
The text was updated successfully, but these errors were encountered: