Skip to content

[FP]: Jakarta.json 2.0.1 reports 3 vulnerabilities #7192

@AndreiElvediMetro

Description

@AndreiElvediMetro

Package URl

pkg:maven/org.glassfish/jakarta.json@2.0.1

CPE

'cpe:2.3:a:eclipse:glassfish:2.0.1:::::::*'

CVE

CVE-2023-5072

ODC Integration

{"label"=>"Maven Plugin"}

ODC Version

2.0.1

Description

Hello,
Version 2.0.1 reports 2 extra CVEs aside from CVE-2022-45688 that was reported in a previous ticket.
Those extra ones are: CVE-2023-5072 and CVE-2024-9329.

5072 is also tied to json:java but 9329 is tied to [cpe:2.3:a:eclipse:glassfish:::::::: versions up to (excluding) 7.0.17].

I would like to confirm if these extra 2 are false positives as well.

Thanks,
Andrei

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions