[ 
https://issues.apache.org/jira/browse/ZOOKEEPER-3933?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Patrick D. Hunt resolved ZOOKEEPER-3933.
----------------------------------------
    Resolution: Invalid

I had seen this with 6.0.0 of dependency-check - after looking into the issue 
it looks like a false positive and is not being flagged with 5.3.0. Closing.

> owasp failing with json-simple-1.1.1.jar: CVE-2020-10663, CVE-2020-7712
> -----------------------------------------------------------------------
>
>                 Key: ZOOKEEPER-3933
>                 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-3933
>             Project: ZooKeeper
>          Issue Type: Bug
>          Components: security
>    Affects Versions: 3.7.0, 3.5.8, 3.6.2
>            Reporter: Patrick D. Hunt
>            Priority: Blocker
>             Fix For: 3.7.0, 3.5.9, 3.6.3
>
>
> dependency-check is failing with:
> json-simple-1.1.1.jar: CVE-2020-10663, CVE-2020-7712



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to