javamelody / jira-confluence-javamelody

JavaMelody plugin for JIRA, Confluence or Bamboo
Apache License 2.0
14 stars 6 forks source link

Vulnerability reported in Confluence for Java Melody plugin #26

Closed Rajat-Github100 closed 1 year ago

Rajat-Github100 commented 1 year ago

Hi Team

We received a report from our security team that there is malware detected under the javamelody folder. Could you please check and let us know more about this. (attached snapshot). Let me know if you require any further information.

vulnerability
evernat commented 1 year ago

rrd files are "round robin database" made by javamelody with the jrobin library to store metrics values. They are used to display graphs in the monitoring page. I am absolutely sure that rrd files are not malware. This is a false positive.

In case that your anti-malware detects a malware perhaps just because the file name is httpSessions, then it is a poor detection.