You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Run /path/to/dependencycheck/bin/dependency-check.sh -s .
But fail to reproduce. Based on the URL towards OSSIndex that you quote you suffer from a mangled lodash package that gets identified as lodash version 0px.
My run properly shows lodash as lodash v4.17.21 and surfaces no FPs
Package URl
https://ossindex.sonatype.org/component/pkg:npm/lodash@0px
CPE
pkg:javascript/lodash@0px
CVE
CVE-2019-10744 CVE-2021-23337 CVE-2018-3721 CVE-2019-1010266 CVE-2018-16487 CVE-2020-28500
ODC Integration
{"label"=>"CLI"}
ODC Version
9.0.9
Description
Versions of lodash lower than 4.17.12 have the following cve's:
CVE-2019-10744
CVE-2021-23337
CVE-2018-3721
CVE-2019-1010266
CVE-2018-16487
CVE-2020-28500
But they are also flagged for lodash: 4.17.21
The text was updated successfully, but these errors were encountered: