OSSIndex / vulns

Report missing advisories and corrections on OSS Index
17 stars 12 forks source link

False positive CVEs reported for Ruby on Rails version 7.0.3.1 component activerecord #325

Open arudinskis opened 1 year ago

arudinskis commented 1 year ago

Vulnerability URL

- https://ossindex.sonatype.org/vulnerability/CVE-2017-17916
- https://ossindex.sonatype.org/vulnerability/CVE-2017-17917

Component URL

- https://ossindex.sonatype.org/component/pkg:gem/activerecord

Description

In Dependency Track this component CPE cpe:2.3:a:activerecord:activerecord:7.0.3.1:*:*:*:*:*:*:* clearly defines component name and version. Both vulnerabilities are related with Rails < 5.1.4 and do not apply to this component.

image