Plugin pulls in org.glassfish:jakarta.json:2.0.1 which is flagged by vulnerability scanners
envgap__dependency-check__DependencyCheck-8127
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
cd30afc3f26ea973f873fdb3d667132cbdf0c07c- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
dependency-check/DependencyCheck #8127 · read the original issue
**Precondition** - [x] I checked the issues list for existing open or closed reports of the same problem. This was reported before but has been closed without a fix: https://github.com/dependency-check/DependencyCheck/issues/7192. Please see the explanation on why it needs fixing below. **Describe the bug** Vulnerability scanners flag the transitive dependency `org.glassfish:jakarta.json:2.0.1` as vulnerable. - [CVE-2023-4043](https://nvd.nist.gov/vuln/detail/cve-2023-4043) - [CVE-2023-7272](https://nvd.nist.gov/vuln/detail/cve-2023-7272) These CVEs are being reported because `org.glassfish:jakarta.json` is the older, unmaintained implementation that was replaced by Eclipse Parsson. The vulnerabilities exist in the underlying JSON parsing code that both share. **Version of dependency-check used** Gradle plugin: `org.owasp:dependency-check-gradle:12.1.8` **Log file** N/A **To Reproduce** N/A **Expected behavior** `org.glassfish:jakarta.json` → migrated to → `org.eclipse.parsson:parsson` The `org.glassfish` artifact is the original implementation and is no longer maintained. Security scanners flag it because it contains the same vulnerable code patterns that were later fixed in Eclipse Parsson. The latest Eclipse Parsson versions (1.0.5+ or 1.1.4+) have both vulnerabilities fixed. **Additional context** N/A
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]