Skip to content

False positive on spring-batch - reported as cpe:/a:pivotal_software:spring_framework:3.0.8, cpe:/a:pivotal:spring_framework:3.0.8, org.springframework.batch:spring-batch-core:3.0.8.RELEASE #1328

@javathought

Description

@javathought

Spring batch major version is behind spring-framework leading project

False positive on spring-batch - reported as cpe:/a:pivotal_software:spring_framework:3.0.8, cpe:/a:pivotal:spring_framework:3.0.8, org.springframework.batch:spring-batch-core:3.0.8.RELEASE

<dependency>
   <groupId>org.springframework.batch</groupId>
   <artifactId>spring-batch-core</artifactId>
   <version>3.0.8.RELEASE</version>
</dependency>

spring-batch-core-3.0.8.RELEASE.jar (cpe:/a:pivotal_software:spring_framework:3.0.8, cpe:/a:pivotal:spring_framework:3.0.8, org.springframework.batch:spring-batch-core:3.0.8.RELEASE) : CVE-2018-1271, CVE-2018-1270, CVE-2016-9878, CVE-2018-1272

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions