[RHACS] Issue while scanning nested jars
Issue
- Scanning
uber (fat) jars that containnested dependenciesdoesnotshowcomponent. - No
vulnerabilitiesare being detected upon scanning thefat/nested jars, for example, that contain Log4J libraries within fat/nested jars. - An example is the
New Relic Java agentwhich nestsLog4Jdependencies within fat jars. Scanner isnot detectingthe log4j vulnerability for the New Relic Java agent nor it's component. - log4j component is not found by the scanner. Other vulnerabilities are being detected
- log4j component is in newrelic.jar which is not detected. Scanner is
skippingthatJARfile.
Environment
- Red Hat Advanced Cluster Security:
3.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.