FP CVE-2024-20932 on jdk8 #1913
Labels
bug
Something isn't working
changelog-ignore
Don't include this issue in the release changelog
false-positive
What happened:
I am scanning an image of alpine 3.20 that contains a dependency of openjdk 8.
I am receiving from Grype 0.74.4\0.78.0 the CVE of CVE-2024-20932.
This CVE according to the DB is related to openjdk17 (alpine remediation) for version < 17.0.10_p7-r0
My version is 8.402.06-r0
I tried to debug, seems like Syft from the one hand tries to guess CPEs and Grype from the other hands does some heuristic which makes the jdk8 become jdk and than matches the mentioned CVE.
The versions seems to be unrelated, which makes me think we have a FP.
What you expected to happen:
Not to find this vulnerability.
How to reproduce it (as minimally and precisely as possible):
I can't attach the full SBOM, so ill attach only a sample:
Anything else we need to know?:
Environment:
grype version
: 0.78.0cat /etc/os-release
or similar): alpine 3.20.0The text was updated successfully, but these errors were encountered: