False positive for CVE-2023-1108 undertow-core #5221
Closed
bvahdat
started this conversation in
False Detection
Replies: 1 comment 1 reply
-
Hello @bvahdat Looks like GitHub advisory database contains mistake: Can you create an improvement for this advisory? (https://github.com/advisories/GHSA-m4mm-pg93-fv78/improve) Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2023-1108
Description
Scanning a custom Docker image finds a vulnerability by the maven artifact
io.undertow:undertow-core:2.2.24.Final
However starting from undertow
2.2.24.Final
CVE-2023-1108 is already fixed and has been tracked through:https://issues.redhat.com/browse/UNDERTOW-2239
This can be verified through this GitHub blame link on the
2.2.24.Final
tagged codebase.More details available by the following links:
Reproduction Steps
Target
Filesystem
Scanner
License
Target OS
No response
Debug Output
.
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions