Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Multiple false positive for ICU DLL #7337

Open
breizh31 opened this issue Jan 21, 2025 · 8 comments
Open

Multiple false positive for ICU DLL #7337

breizh31 opened this issue Jan 21, 2025 · 8 comments
Labels

Comments

@breizh31
Copy link

breizh31 commented Jan 21, 2025

Hello,

I don't know if it is a bug or a misconfiguration, but i'm scanning a project with an ICU DLL (icudt74.dll) and i'm facing to a lots of false positive because the version seems to be ignored.
See attachment: CVE for 57.1, analyzed version 74.2.

Thanks,

Image

@breizh31
Copy link
Author

Sorry, i forgot: I'm using the cli 12.0.0.

@aikebah
Copy link
Collaborator

aikebah commented Jan 26, 2025

You're not showing what the library itself is recognized as, you're only showing the truncated details of a vulnerability.

@breizh31
Copy link
Author

Hello @aikebah ,

You are right, my description is a little short. The vulnerability is CVE-2016-7415.

What do you need as additional informations ?

Thanks

@aikebah
Copy link
Collaborator

aikebah commented Jan 27, 2025

@breizh31 The more relevant part, besides the CVE is the information on what library is reported to have it (the identifiers section of the HTML report) and the information that dependency check extracted from your library (the evidences section of the HTML report)

@breizh31
Copy link
Author

Image

The evidence is on 74.2.0.0 but the identifier uses version *. Surely why a lots of vulnerabilities on previous versions are reported, isn't it ?

@aikebah
Copy link
Collaborator

aikebah commented Jan 27, 2025

Right, looks like a bug of some kind in the determination of the version of this component. I'll at least flag is as a bug rather than a question, since with the evidences discovered it should not be flagging CVEs that are for a version smaller than 74.x

@aikebah
Copy link
Collaborator

aikebah commented Jan 27, 2025

Can you take a look inside the 'related dependencies' what other libraries from your scan are also bundled up under this same ICU DLL umbrella in the report?

@breizh31
Copy link
Author

Hello @aikebah ,

Sure

Image

Thanks,

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants