DependencyTrack / DependencyTrack/dependency-track

CVE-2023-35116 not visible on component with jackson-databind 2.13.4.2

Open
#3,764 0 comments 0 reactions 0 assignees View on GitHub
FP/FN report
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

We have uploaded an SBOM with jackson-databind 2.13.4.2 with the following identity information:

![image](https://github.com/DependencyTrack/dependency-track/assets/165893083/ab842af9-c6d5-4ed0-a284-219d28aa04b0)

We noticed that [CVE-2023-35116](https://nvd.nist.gov/vuln/detail/CVE-2023-35116#vulnConfigurationsArea) is not visible in the vulnerabilities tab of Dependency Track:

![image](https://github.com/DependencyTrack/dependency-track/assets/165893083/7231b42a-184d-47ca-a7dc-4e285ab86c1a)

According to the CPE information the CVE is applicable to Up to (excluding) 2.16.0.

The project is active, it does detect other vulnerabilities on other components in the same project but not CVE-2023-35116. We do have another SBOM uploaded which contains jackson-databind 2.15.2 where the CVE issue is detected.

### Steps to Reproduce

1. Upload SBOM with [sbom_test.json](https://github.com/DependencyTrack/dependency-track/files/15469542/sbom_test.json)
2. No vulnerabilities are matched to this component, meanwhile we would expect CVE-2023-35116

### Expected Behavior

1 reported vulnerability to the jackson-databind component (i.e. CVE-2023-35116)

### Dependency-Track Version

4.11.0

### Dependency-Track Distribution

Container Image

### Database Server

PostgreSQL

### Database Server Version

_No response_

### Browser

N/A

### Checklist

- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.