-
-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[FP]: CVE-2024-34447 for bcprov-jdk15on-1.60.jar #6659
Comments
Maven Coordinates <dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcpkix-jdk15on</artifactId>
<version>1.60</version>
</dependency> Suppression rule: <suppress base="true">
<notes><![CDATA[
FP per issue #6659
]]></notes>
<packageUrl regex="true">^pkg:maven/org\.bouncycastle/bcpkix-jdk15on@.*$</packageUrl>
<cpe>cpe:/a:bouncycastle:bouncy_castle_for_java</cpe>
</suppress> Link to test results: https://github.com/jeremylong/DependencyCheck/actions/runs/9015590632 |
Maven Coordinates <dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcpkix-jdk15on</artifactId>
<version>1.60</version>
</dependency> Suppression rule: <suppress base="true">
<notes><![CDATA[
FP per issue #6659
]]></notes>
<packageUrl regex="true">^pkg:maven/org\.bouncycastle/bcpkix-jdk15on@.*$</packageUrl>
<cpe>cpe:/a:bouncycastle:bouncy_castle_for_java</cpe>
</suppress> Link to test results: https://github.com/jeremylong/DependencyCheck/actions/runs/9015605859 |
Maven Coordinates <dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcprov-jdk15on</artifactId>
<version>1.60</version>
</dependency> Suppression rule: <suppress base="true">
<notes><![CDATA[
FP per issue #6659
]]></notes>
<packageUrl regex="true">^pkg:maven/org\.bouncycastle/bcprov-jdk15on@.*$</packageUrl>
<cpe>cpe:/a:org.bouncycastle:bcprov-jdk15on</cpe>
</suppress> Link to test results: https://github.com/jeremylong/DependencyCheck/actions/runs/9015617431 |
Probably the CPE is wrong in NVD? |
All the data says the issue is in |
Package URl
pkg:maven/org.bouncycastle/bcprov-jdk15on@1.60
CPE
cpe:2.3:a:org.bouncycastle:bcprov-jdk15on:1.60:::::::*
CVE
CVE-2024-34447
ODC Integration
None
ODC Version
9.1.0
Description
org.bouncycastle.jsse
packages are shipped inorg.bouncycastle:bctls-jdk15on
See https://github.com/bcgit/bc-java/blob/r1v60/tls/build.gradle
Probably this can be generalized to newer versions
The text was updated successfully, but these errors were encountered: