You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Issue:
I have two versions of my project, and the reported vulnerabilities for this component vary significantly:
Version 1: Reports 1,772 vulnerabilities associated with the CPE.
Version 2: Reports 0 vulnerabilities for the same CPE.
Steps Taken:
Check that the reported analyzer is NVD
I performed a "reanalyze" action, but the vulnerability count remained unchanged in both versions.
I downloaded the BOM with vulnerabilities for each version and found that the vulnerabilities listed in both versions align with the data in the report.
Screenshots:
Version 1 (1772 vulnerabilities):
Version 2 (0 vulnerabilities):
Questions:
Could this be an issue with how the CPE is being matched?
Is there a known bug or an inconsistency in how NVD is handling this package?
Are there any debugging steps I can take to further investigate this discrepancy?
Steps to Reproduce
I'm not sure if this scenario can be reproduced easily
Expected Behavior
The vulnerability analysis should be consistent across project versions for the same CPE ad PURL
Current Behavior
I am experiencing a discrepancy in the number of vulnerabilities reported for the same component across two different versions of my project.
Component Details:
Issue:
I have two versions of my project, and the reported vulnerabilities for this component vary significantly:
Steps Taken:
Screenshots:
Version 1 (1772 vulnerabilities):
Version 2 (0 vulnerabilities):
Questions:
Steps to Reproduce
Expected Behavior
The vulnerability analysis should be consistent across project versions for the same CPE ad PURL
Dependency-Track Version
4.12.1
Dependency-Track Distribution
Container Image
Database Server
PostgreSQL
Database Server Version
No response
Browser
N/A
Checklist
The text was updated successfully, but these errors were encountered: