Scout false positive on Spring Core 7.x.x for CVE-2011-2730, CVE-2010-1622
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
Research direction
Start by reproducing the Docker Scout finding for spring-core@7.0.6 and compare its matching logic with the affected ranges stated for CVE-2011-2730 and CVE-2010-1622. Trace the dependency and advisory matching entry points; done means these CVEs are no longer reported against Spring Core 7.0.6 while genuinely affected versions remain detectable.
Written by the indexing model from the issue text.
Description
It seems this morning that Docker Scout has been flagging CVE-2011-2730 & CVE-2010-1622 against Spring Core 7, specifically 7.0.6
This would appear to be a false positive.
CVE-2011-2730
Spring EL/JSP tag vulnerability in very old Spring 2.5/3.0 lines. Scout attached it to spring-core@7.0.6, but the advisory's affected range is <= 2.5.7.SR022, and the issue is about Spring JSP taglibs, not modern spring-core.
CVE-2010-1622
Spring data-binding RCE in Spring 2.5.x / 3.0.x before fixed releases. Scout again attached it to spring-core@7.0.6 even though the reported affected range is <= 2.5.6.SEC01 / 3.0.3.RELEASE.
- Dominant language
- Shell
- Stars
- 454
- Forks
- 134
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from docker/scout-cli
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
-
allstar
Difficulty 2/5 1-3 hours Newbie friendliness 45/100
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
-
panic: nil deref in createVCS() scanning multi-arch image by tag when no attestation sidecar exists Open
Difficulty 4/5 3-5 days Newbie friendliness 64/100
All issues in docker/scout-cli
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
danielmiessler/LifeOS#2218 ·
-
docs(agents): strengthen the no-backslash-escaped-backticks rule with an issue-creation example Open
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
technical-debt
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
ll7/robot_sf_ll7#9560 ·
-
package-update
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
oSoWoSo/vOid_Community_repOsitory#148 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100