logoalt Hacker News

DeepYogurttoday at 2:17 AM1 replyview on HN

To be fair the CVE system can't even encode a version string


Replies

spockztoday at 7:44 AM

Not sure whether this is a limitation of the scanning tooling or of the CVE format itself, it also cannot express sub packages. So if some Jackson-very-specific-module has a CVE the whole of Jackson gets marked as impacted. Same with netty.