DependencyTrack / DependencyTrack/dependency-track

Dependency that has 1 vulnerability detected in one project and no vulnerability in another.

Open
#2,863 5 comments 0 reactions 0 assignees View on GitHub
defect in triage pending more information
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

Hello, we are using Dependency Track 4.5.0, and we are facing an odd behavior.
In one project, we find that the dependency lucenequeryparser 4.7.2 contains 1 vulnerability.
and in another project, the same dependency ( with same version) / having the same purl .. doesn't show any vulnerability.
We tried to reupload new boms, rescan the Boms.. but nothing has changed.
Can you please tell what is happening on our side and how we can fix it ?

Thank you in advance.

Best Regards,

### Steps to Reproduce

1.using lucenequeryparser 4.7.2 as a dependency

### Expected Behavior

having the same number of vulnerabilities for the same exact component.

### Dependency-Track Version

4.7.x

### Dependency-Track Distribution

Executable WAR

### Database Server

PostgreSQL

### Database Server Version

_No response_

### Browser

Google Chrome

### Checklist

- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.