You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This seems to be the same issue as #1668, where the CPE is so general that it matches the Java library as well, despite the fact that it is purely an impl of the XZ compression. It does not implement or use (x)zgrep and therefore is not vulnerable to the filename validation problem mentioned in the CVE.
The text was updated successfully, but these errors were encountered:
Package URl
pkg:maven/org.tukaani/[email protected]
CPE
cpe:2.3:a:tukaani:xz::::::::
CVE
CVE-2022-1271
ODC Integration
{"label"=>"Ant Task"}
ODC Version
10.0.1
Description
This seems to be the same issue as #1668, where the CPE is so general that it matches the Java library as well, despite the fact that it is purely an impl of the XZ compression. It does not implement or use (x)zgrep and therefore is not vulnerable to the filename validation problem mentioned in the CVE.
The text was updated successfully, but these errors were encountered: