-
Notifications
You must be signed in to change notification settings - Fork 2.6k
Closed
Labels
Description
Hi,
we received a security alert originating from GHSA-gw55-jm4h-x339 linking to https://nvd.nist.gov/vuln/detail/CVE-2020-11050
Our OWASP dependency checker wrongly matched the javax.websocket:javax.websocket-api against this vulnerability with a high confidence in several fields of the MANIFEST.
Can you please check the reported Metadata to make sure it does match only the affected client side library and not the javax.websocket-api
Horcrux7, uap-universe and mzimnn