-
```
Severity Code Description Project Path File Line Source Suppression State Tool
Error jQuery 3.4.1: [CVE-2019-11358] Improper Neutralization of Input During Web Page Generation ("Cross-site Scr…
-
Currently in Hyades, we've skipped the mapping of affected package versions for scan analysers (Snyk, OssIndex) because of scenario like :
If Snyk reports affected versions and later it doesn't, the…
-
### Package URl
pkg:maven/io.netty/netty-handler@4.1.109.Final
### CPE
cpe:2.3:a:netty:netty:4.1.109:*:*:*:*:*:*:*
### CVE
CVE-2023-4586 and sonatype-2020-0026
### ODC Integration
…
-
Happen to stumble upon the [announcement of this project](https://www.finos.org/blog/introducing-finos-security-scanning?hss_channel=lcp-18473937) and wonder if the maintainers of this project are fam…
-
Hello.
In the DependencyCheck I'm getting alerts for CVE-2007-1651 and CVE-2007-1652 vulnerabilities referred to **Microsoft.IdentityModel.Protocols.OpenIdConnect** package (performing dll scanning…
-
### Current Behavior
![image (1)](https://github.com/DependencyTrack/dependency-track/assets/92030419/d48f0977-a07e-4f2c-a861-1fab7ca220aa)
### Steps to Reproduce
1.generate sbom based on one a…
-
### Package URl
https://ossindex.sonatype.org/component/pkg:npm/lodash@0px
### CPE
pkg:javascript/lodash@0px
### CVE
CVE-2019-10744 CVE-2021-23337 CVE-2018-3721 CVE-2019-1010266 CVE-2018-16487 …
-
**Vulnerability URL**
```
https://ossindex.sonatype.org/component/pkg:deb/debian/openssl@1.1.0l%3Farch=amd64
```
**Description**
Only 1 vulnerability is found instead of 3 according to [the o…
-
JIRA Issue: [KIEKER-1927] Kieker 1.15.1 Contains Security Vulnerability
Original Reporter: David Georg Reichelt
***
Kieker 1.15.1 contains guava 31.0.1-jre, which contains a security problem: https:…
-
Please consider migrating from `joda.time` to `java.time`. The `joda.time` library is no longer being maintained as `java.time` (JSR-310) is now part of core Java. See https://www.joda.org/joda-time/.…