Skip to content

[FP]: org.eclipse.jetty.toolchain/jetty-jakarta-websocket-api@2.0.0 is misidentified as a jetty 2.0.0 component #6798

@lread

Description

@lread

Package URl

pkg:maven/org.eclipse.jetty.toolchain/jetty-jakarta-websocket-api@2.0.0

CPE

cpe:2.3:a:jetty:jetty:2.0.0:*:*:*:*:*:*:*

CVE

No response

ODC Integration

None

ODC Version

10.0.1

Description

Hello! Thanks for all the hard work on DependencyCheck!

This seems similar to #6666.

The package pkg:maven/org.eclipse.jetty.toolchain/jetty-jakarta-websocket-api@2.0.0 is being classified as a Jetty 2.0.0 package (cpe:2.3:a:eclipse:jetty:2.0.0:*:*:*:*:*:*:* andcpe:2.3:a:jetty:jetty:2.0.0:*:*:*:*:*:*:*), although it ships with Jetty 11. The package version is independent of the Jetty release version and describes the WebSocket API version.

This triggers a bunch of false positive CVEs related to older versions of Jetty:

Here's a link to the artifact on Sonatype, if that helps:
https://central.sonatype.com/artifact/org.eclipse.jetty.toolchain/jetty-jakarta-websocket-api/2.0.0/versions

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions