Skip to content

[FP]: Wrongly reporting CVE-2020-21913 vulnerabilitiy on org.graalvm.shadowed/icu4j 24.2.1 #7706

@AlexanderB-elo

Description

@AlexanderB-elo

Package URl

pkg:maven/org.graalvm.shadowed/icu4j@24.2.1

CPE

cpe:2.3:a:icu-project:international_components_for_unicode:24.2.1:::::::*

CVE

CVE-2020-21913

ODC Integration

{"label" => "Gradle Plugin"}

ODC Version

12.1.1

Description

Wrongly reporting serveral vulnerabilities on shaded icu4j-23.1.2.jar from 'org.graalvm.polyglot:js-community:24.2.1.

see also : oracle/graal#8204

CVE-2016-6293, CVE-2017-17484, CVE-2015-5922, CVE-2014-7923, CVE-2011-4599, CVE-2017-15396, CVE-2017-7868, CVE-2014-7926, CVE-2017-7867, CVE-2014-9911, CVE-2014-8147, CVE-2014-9654, CVE-2014-8146, CVE-2017-14952, CVE-2014-7940, CVE-2020-10531, CVE-2017-15422, CVE-2016-7415, CVE-2020-21913

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions