DependencyTrack / dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
https://dependencytrack.org/
Apache License 2.0
2.44k stars 531 forks source link

False positif CVE-2023-29827 linked to ejs@3.1.10 #3913

Open JingLeiTalan opened 3 days ago

JingLeiTalan commented 3 days ago

Current Behavior

image (1)

Steps to Reproduce

1.generate sbom based on one angular project

Expected Behavior

This CVE should not be liked to current dependency

Dependency-Track Version

4.7.x

Dependency-Track Distribution

Container Image

Database Server

PostgreSQL

Database Server Version

No response

Browser

Google Chrome

Checklist

VinodAnandan commented 3 days ago

@JingLeiTalan Looks like this was reported by OSS Index. You can request the record to be corrected here: https://ossindex.sonatype.org/doc/report-vulnerability