You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
Dependency Check when scanning pkg:maven/org.quartz-scheduler/quartz@1.8.4 fails to successfully generate the CPE required to match against the NVD
Version of dependency-check used
CLI and version used: 5.3.2
To Reproduce
When scanning the above module the evidence collected does not provide the information capable of generating the correct CPE to match against the NVD.
The issue itself was fixed in v2.3.2 as per this thread: quartz-scheduler/quartz#467
Describe the bug
Dependency Check when scanning pkg:maven/org.quartz-scheduler/quartz@1.8.4 fails to successfully generate the CPE required to match against the NVD
Version of dependency-check used
CLI and version used: 5.3.2
Log file
Scan results for this module: https://gist.github.com/Rob-Conan/3f04d98fe9b1140c493434277b95fde3
To Reproduce
When scanning the above module the evidence collected does not provide the information capable of generating the correct CPE to match against the NVD.
The issue itself was fixed in v2.3.2 as per this thread: quartz-scheduler/quartz#467
Expected behavior
Return the correct CPE and CVE finds https://nvd.nist.gov/vuln/search/results?form_type=Advanced&cves=on&cpe_version=cpe%3A%2Fa%3Asoftwareag%3Aquartz%3A1.8.4
The text was updated successfully, but these errors were encountered: