jfrog / jfrog/artifactory-client-java
False positive reported on python3-lxml CVE-2022-2309
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 331
- Forks
- 163
- Avg merge
- 20h 9m
- Merged PRs (30d)
- 1
Description
CVE-2022-2309 vulnerability only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected.
As per https://www.suse.com/security/cve/CVE-2022-2309.html, this vulnerability is fixed in python3-lxml >= 4.9.1-150500.1.2, this version is already part of the product, however XRAY is identifying this package as affected with this vulnerability. Please fix this false positive.
XRAY version used for scan - 3.124.16 Revision: 679c9d5dde Enterprise License.
SUSE version - SUSE Linux Enterprise Module for Basesystem 15 SP6
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by determining whether this repository contains the Xray vulnerability data or scanning entry point involved in issue #431; the payload names no source files or tests. Compare the reported python3-lxml and libxml2 versions with the linked SUSE advisory, and consider the work complete only when the reported false positive is corrected or its handling is clearly identified.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100