← All tasks
javadependency-check/DependencyCheck #8127Not a task: already works

Plugin pulls in org.glassfish:jakarta.json:2.0.1 which is flagged by vulnerability scanners

envgap__dependency-check__DependencyCheck-8127

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
cd30afc3f26ea973f873fdb3d667132cbdf0c07c
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

dependency-check/DependencyCheck #8127 · read the original issue
**Precondition**
- [x] I checked the issues list for existing open or closed reports of the same problem.

This was reported before but has been closed without a fix: https://github.com/dependency-check/DependencyCheck/issues/7192. Please see the explanation on why it needs fixing below.

**Describe the bug**

Vulnerability scanners flag the transitive dependency `org.glassfish:jakarta.json:2.0.1` as vulnerable.

- [CVE-2023-4043](https://nvd.nist.gov/vuln/detail/cve-2023-4043)
- [CVE-2023-7272](https://nvd.nist.gov/vuln/detail/cve-2023-7272)

These CVEs are being reported because `org.glassfish:jakarta.json` is the older, unmaintained implementation that was replaced by Eclipse Parsson. The vulnerabilities exist in the underlying JSON parsing code that both share.

**Version of dependency-check used**

Gradle plugin: `org.owasp:dependency-check-gradle:12.1.8`

**Log file**

N/A

**To Reproduce**

N/A

**Expected behavior**

 `org.glassfish:jakarta.json` → migrated to → `org.eclipse.parsson:parsson`

The `org.glassfish` artifact is the original implementation and is no longer maintained. Security scanners flag it because it contains the same vulnerable code patterns that were later fixed in Eclipse Parsson. The latest Eclipse Parsson versions (1.0.5+ or 1.1.4+) have both vulnerabilities fixed.

**Additional context**

N/A
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]