You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何OWASP Dependency-Check会报Mule Runtime 4.4.0不存在的漏洞?

关于Mule HTTP Connector依赖漏洞误报的确认与分析

问题背景

基于Mule Runtime 4.4.0构建应用,pom.xml中引入mule-http-connector@1.7.3依赖,配置如下:

<dependency>
    <groupId>org.mule.connectors</groupId>
    <artifactId>mule-http-connector</artifactId>
    <version>1.7.3</version>
    <classifier>mule-plugin</classifier>
</dependency>

漏洞检测情况

使用OWASP Dependency-Check Maven插件(版本8.2.1)执行命令 mvn org.owasp:dependency-check-maven:8.2.1:check 后,报告显示mule-http-connector@1.7.3的传递依赖mule-module-cors-kernel-1.1.2.jar关联以下CPE漏洞:

  • cpe:2.3🅰️mulesoft:api_gateway:1.1.2:::::::*
  • cpe:2.3🅰️mulesoft:mule_runtime:1.1.2:::::::*

涉及的漏洞为CVE-2019-15630和CVE-2019-13116,这两个漏洞仅存在于旧版Mule Runtime,并非4.4.0版本范畴。

结论:属于误报

误报原因

  1. CPE匹配逻辑混淆:OWASP Dependency-Check通过版本号匹配CPE时,错误将mule-module-cors-kernel-1.1.2的版本关联到Mule Runtime/API Gateway的1.1.2版本,但该组件是Mule 4.x生态下的独立模块,版本号与主框架版本无对应关系。
  2. 漏洞范围不匹配:CVE-2019-15630和CVE-2019-13116针对的是Mule Runtime 3.x及更早版本,Mule 4.4.0的CORS模块已完全重构,不存在这些历史漏洞。
  3. 组件版本独立性:mule-module-cors-kernel-1.1.2是Mule 4.x体系的合法组件版本,并非旧版主框架的分支,插件误将组件版本等同于主框架版本进行漏洞关联。

处理方案

  1. 兼容性确认:mule-http-connector@1.7.3与Mule Runtime 4.4.0完全兼容,其依赖的mule-module-cors-kernel-1.1.2无上述漏洞,可正常使用。
  2. 添加误报排除规则:在OWASP Dependency-Check插件配置中加入抑制规则,忽略错误匹配的漏洞:
    <plugin>
        <groupId>org.owasp</groupId>
        <artifactId>dependency-check-maven</artifactId>
        <version>8.2.1</version>
        <configuration>
            <suppressions>
                <suppress>
                    <cpe>cpe:2.3:a:mulesoft:api_gateway:1.1.2:*:*:*:*:*:*:*</cpe>
                    <cve>CVE-2019-15630</cve>
                </suppress>
                <suppress>
                    <cpe>cpe:2.3:a:mulesoft:mule_runtime:1.1.2:*:*:*:*:*:*:*</cpe>
                    <cve>CVE-2019-13116</cve>
                </suppress>
            </suppressions>
        </configuration>
        <executions>
            <execution>
                <goals>
                    <goal>check</goal>
                </goals>
            </execution>
        </executions>
    </plugin>
    
  3. 升级连接器版本:建议将mule-http-connector升级至与Mule 4.4.0兼容的最新稳定版(如1.15.x系列),新版本依赖的组件更规范,可降低此类误报概率。

内容的提问来源于stack exchange,提问作者Jaci_2019

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 19:43:10