Skip to content

[FP]:Wrongly reporting vulnerability CVE-2021-41033 on org.eclipse.equinox.launcher.cocoa.macosx.x86_64 #7675

@abhishek171287

Description

@abhishek171287

Package URl

pkg:maven/org.eclipse.equinox/org.eclipse.equinox.launcher.cocoa.macosx.x86_64@1.1.100

CPE

cpe:2.3:a:eclipse:equinox:1.1.100:370::::::

CVE

CVE-2021-41033

ODC Integration

{"label" => "Maven Plugin"}

ODC Version

10.0.3

Description

The above CVE doesn't affect equinox OSGI framework at all according to eclipse-equinox/equinox#532 (reply in thread) and similar FP was raised previously too #5881

Seems like this affects only P2 eclipse equinox artifacts according to this report https://bugs.eclipse.org/bugs/show_bug.cgi?id=575688 rather than OSGI eclipse-equinox

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions