Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Owasp scan still reflects vulnerability for CVE-2020-26945 when mybatis 3.5.6 is used. #2982

Closed
taroace22 opened this issue Nov 29, 2020 · 1 comment
Milestone

Comments

@taroace22
Copy link

taroace22 commented Nov 29, 2020

Don't know if this is the correct channel post for CVE-2020-26945 that was flag by Owasp scan.

Recently we did a OWASP scan on the libs for my project and a vulnerability was flagged for mybatis-spring-2.0.5.jar on CVE-2020-26945 to use mybatis-3.5.6.

Thus I have up only mybatis to 3.5.6 with mybatis-spring-2.0.5 and did another owasp scan. The vulnerability is still being reported.

Thinking maybe I need to up mybatis-spring to 2.0.6 wth 3.5.6 and did another scan. The vulnerability is still being reported. Is there issue with the dependency?

The fact that synk seems to show its correct here https://snyk.io/vuln/SNYK-JAVA-ORGMYBATIS-1017032

For expert advice. Thanks alot.

Best Regards,
Taroace22

2 0 6 Owasp Result

@jeremylong
Copy link
Owner

Likely a false positive. Please see:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants
@jeremylong @taroace22 and others