Skip to content

[FP]: Nuget packages with Redis in name is marked as vulnerable #4321

@McMlok

Description

@McMlok

Package URl

pkg:generic/[email protected]
pkg:generic/[email protected]

CPE

cpe:2.3:a:redis:redis:5.0.2:::::::*
cpe:2.3:a:microsoft:.net_core:6.0.1:::::::*
cpe:2.3:a:microsoft:exchange:6.0.1:::::::*
cpe:2.3:a:redis:redis:6.0.1:::::::*

CVE

CVE-2021-32626
CVE-2021-32627
CVE-2021-32628
CVE-2021-32675
CVE-2021-32687
CVE-2021-32762
CVE-2021-41099

ODC Integration

{"label"=>"CLI"}

ODC Version

  • 6.5.3
  • 7.0.4

Description

It looks like that all Nuget packages with "Redis" in name and with the version similar to a version number used in Redis server are marked with vulnerabilities found in Redis Server.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions