Skip to content

[FP]: Apache Camel Karaf OSGI Bundle Misidentified as Apache Karaf 3.22.4 #8599

@mnika93

Description

@mnika93

Package URl

pkg:maven/org.apache.camel.karaf/camel-core-osgi@3.22.4

CPE

cpe:2.3:a:apache:karaf:3.22.4:::::::*

CVE

CVE-2018-11786
CVE-2018-11788
CVE-2021-41766
CVE-2022-40145

ODC Integration

{"label" => "CLI"}

ODC Version

12.2.1

Description

False positive: The scanner matches org.apache.camel.karaf.camel-core-osgi-3.22.4.jar against CPE apache:karaf:3.22.4 because the group ID contains camel.karaf and version 3.22.4 is interpreted as a Karaf version.

Evidence from report:

  • data-display-name: *-org.apache.camel.karaf.camel-core-osgi-3.22.4.jar
  • Matched CPE: cpe:2.3:a:apache:karaf:3.22.4:*:*:*:*:*:*:*

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions