False positive for CVE-2024-43485 with dotnet 9 or 9.x.x packages
Current Behavior
CVE-2024-43485 is being flagged as vulnerability but dotnet 9 or packages with >=8.0.10 are not affected according to dt.
Steps to Reproduce
- Create a csproj for dotnet 9
- Reference System.Text.Json 9.0.1
- Create sbom
- Import sbom in dt
- false positive for CVE-2024-43485
Expected Behavior
- Create a csproj for dotnet 9
- Reference System.Text.Json 9.0.1
- Create sbom
- Import sbom in dt
- No false positive
Dependency-Track Version
4.12.2
Dependency-Track Distribution
Container Image
Database Server
H2
Database Server Version
No response
Browser
Google Chrome
Checklist
- [x] I have read and understand the contributing guidelines
- [x] I have checked the existing issues for whether this defect was already reported
I keep having to suppress this over and over again, it goes away for projects for a while, and then pops back up again at some random interval.
Having the same problem. Will this be fixed soon?
When will this be addressed?
Hi @pregress, do you have OSS Index analyzer enabled? I see that problem seems to be due to OSS Index: https://ossindex.sonatype.org/component/pkg:nuget/System.Text.Json I contacted them to request correction.
@antoinbo
When you contacted OSS Index and requested a correction; did you make the request through a GitHub issue or similar? If your correction request is publicly available, it would be nice if you could provide a link so that we can monitor the status of the case.
Hi @pregress, do you have OSS Index analyzer enabled? I see that problem seems to be due to OSS Index: https://ossindex.sonatype.org/component/pkg:nuget/System.Text.Json I contacted them to request correction.
Don't know, we stopped using dependency track.
@josundt I contacted via the 💬 Report advisory or correction link, asking to:
Missing or Incorrect Advisory
To report an advisory missing from OSS Index, or a correction to an existing report, please email us at ✉️ [email protected].
So I will keep you informed here.
Same here! Any news?
Hi @Willimaendu, I was in contact with them, they asked for recommended corrections. No update since. I sent them a reminder today.
Any news here?
No, so my next step will be to check what it detects, as it appears to only report false positives.