Skip to content

[FP]: Jersey HK2 JARs Misidentified as GlassFish Server #8588

Description

@er-balaji

Package URl

pkg:maven/org.glassfish.jersey.inject/jersey-hk2@2.48

CPE

cpe:2.3:a:eclipse:glassfish::::::::

CVE

CVE-2024-9329, CVE-2026-2586, CVE-2026-2587

ODC Integration

None

ODC Version

Maven / OWASP Dependency-Check CLI

Description

False positive: The scanner matches HK2 dependency injection JARs (namespace org.glassfish.hk2 / org.glassfish.jersey) against GlassFish Application Server CPE.

HK2 is a standalone dependency injection framework used by Jersey REST framework. GlassFish Application Server is NOT deployed. The CVEs are for GlassFish server-specific vulnerabilities (admin console, deployment) that have no relevance to the standalone HK2 DI library.

Metadata

Metadata

Assignees

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions