Skip to content

[FP]: False Positive on grpc-netty / grpc-netty-shaded : 1.50.2.jar #5206

@keerthanavenky

Description

@keerthanavenky

Package URl

pkg:maven/io.grpc/[email protected]

CPE

cpe:2.3:a:netty:netty:1.50.2:*:*:*:*:*:*:*

CVE

CVE-2019-20444

ODC Integration

None

ODC Version

7.4.1

Description

False positive on library grpc-netty-shaded-1.50.2.jar

Find below the vulnerabilities reported by the dependency check tool:

CVE-2019-20444
CVE-2019-20445
CVE-2015-2156
CVE-2019-16869
CVE-2021-37136
CVE-2021-37137
CVE-2022-41881
CVE-2021-43797
CVE-2022-41915
CVE-2021-21295
CVE-2021-21409
CVE-2021-21290
CVE-2022-24823
CVE-2014-3488

I have gone through all these CVEs and could not find anything related to grpc-netty-shaded
The issues shown are related to other netty libraries.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions