Albert Wang

Results 3 comments of Albert Wang

Hi @kwwall is there a further update about the FP? Do we know the reason that xerceslmpl-2.12.2.jar is matched with the CVE-2017-10355? Thank you.

@kwwall @aikebah I reported the issue to [OSSIndex]( My current understanding is that OSSIndex published a vulnerability [[sonatype-2017-0348] CWE-833: Deadlock]( of [xerces:xercesImpl]( Somehow, when OWASP Dependency-Check reports the vulnerability, it...

Hi @aikebah , do you think [SNYK-JAVA-XERCES-31497]( and [sonatype-2017-0348]( are the same issue of XercesImpl, or they are different issues?