dependency-check / dependency-check/DependencyCheck
use CPE `update` and `edition` fields to derive matching version to reduce FP
Open
enhancement
nvd
- Dominant language
- Java
- Stars
- 7.7k
- Forks
- 1.4k
- Avg merge
- 9d 22h
- Merged PRs (30d)
- 13
Description
The NVD has some CVEs such as https://nvd.nist.gov/vuln/detail/CVE-2021-42550, that use these fields to include additional data that is part of the version, sometimes representing pre-release versions.
Creating this issue to group together FPs which cannot be fixed without support for these CPE fields.
Relates to #7139
Contributor guide
Assessment
This issue has not been assessed yet.