为何OWASP Dependency-Check会报Mule Runtime 4.4.0不存在的漏洞?
关于Mule HTTP Connector依赖漏洞误报的确认与分析
问题背景
基于Mule Runtime 4.4.0构建应用,pom.xml中引入mule-http-connector@1.7.3依赖,配置如下:
<dependency> <groupId>org.mule.connectors</groupId> <artifactId>mule-http-connector</artifactId> <version>1.7.3</version> <classifier>mule-plugin</classifier> </dependency>
漏洞检测情况
使用OWASP Dependency-Check Maven插件(版本8.2.1)执行命令 mvn org.owasp:dependency-check-maven:8.2.1:check 后,报告显示mule-http-connector@1.7.3的传递依赖mule-module-cors-kernel-1.1.2.jar关联以下CPE漏洞:
- cpe:2.3🅰️mulesoft:api_gateway:1.1.2:::::::*
- cpe:2.3🅰️mulesoft:mule_runtime:1.1.2:::::::*
涉及的漏洞为CVE-2019-15630和CVE-2019-13116,这两个漏洞仅存在于旧版Mule Runtime,并非4.4.0版本范畴。
结论:属于误报
误报原因
- CPE匹配逻辑混淆:OWASP Dependency-Check通过版本号匹配CPE时,错误将
mule-module-cors-kernel-1.1.2的版本关联到Mule Runtime/API Gateway的1.1.2版本,但该组件是Mule 4.x生态下的独立模块,版本号与主框架版本无对应关系。 - 漏洞范围不匹配:CVE-2019-15630和CVE-2019-13116针对的是Mule Runtime 3.x及更早版本,Mule 4.4.0的CORS模块已完全重构,不存在这些历史漏洞。
- 组件版本独立性:
mule-module-cors-kernel-1.1.2是Mule 4.x体系的合法组件版本,并非旧版主框架的分支,插件误将组件版本等同于主框架版本进行漏洞关联。
处理方案
- 兼容性确认:
mule-http-connector@1.7.3与Mule Runtime 4.4.0完全兼容,其依赖的mule-module-cors-kernel-1.1.2无上述漏洞,可正常使用。 - 添加误报排除规则:在OWASP Dependency-Check插件配置中加入抑制规则,忽略错误匹配的漏洞:
<plugin> <groupId>org.owasp</groupId> <artifactId>dependency-check-maven</artifactId> <version>8.2.1</version> <configuration> <suppressions> <suppress> <cpe>cpe:2.3:a:mulesoft:api_gateway:1.1.2:*:*:*:*:*:*:*</cpe> <cve>CVE-2019-15630</cve> </suppress> <suppress> <cpe>cpe:2.3:a:mulesoft:mule_runtime:1.1.2:*:*:*:*:*:*:*</cpe> <cve>CVE-2019-13116</cve> </suppress> </suppressions> </configuration> <executions> <execution> <goals> <goal>check</goal> </goals> </execution> </executions> </plugin> - 升级连接器版本:建议将
mule-http-connector升级至与Mule 4.4.0兼容的最新稳定版(如1.15.x系列),新版本依赖的组件更规范,可降低此类误报概率。
内容的提问来源于stack exchange,提问作者Jaci_2019
相关产品推荐
相关产品推荐

