You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CVE-2019-2124 affects Google Android but the PURL pkg:maven/org.bouncycastle/[email protected] is marked as vulnerable. This is an invalid mapping. There are currently quite a number of these issues in Postgres.
The text was updated successfully, but these errors were encountered:
I think that the PURL inference strategies are the problem here, also in #118
Try running the vulnerability-producer with the -i none flag to turn those off.
I think that the PURL inference strategies are the problem here, also in #118 Try running the vulnerability-producer with the -i none flag to turn those off.
Yes, this is related to the devised heuristics for PURL inference.
By turning off the flag -i, I think the tool won't infer PURLs.
I am currently investigating what we can possibly do to mitigate these false positives.
CVE-2019-2124 affects Google Android but the PURL
pkg:maven/org.bouncycastle/[email protected]
is marked as vulnerable. This is an invalid mapping. There are currently quite a number of these issues in Postgres.The text was updated successfully, but these errors were encountered: