Nexus marks version with vulnerability patch as vulnerable - Sonatype Lifecycle & Repository Firewall - Sonatype Community

Nexus marks version with vulnerability patch as vulnerable

post by valourie on Jan 12, 2023

Valourie Valgardsson
According to the package owner, System.Data.SqlClient 4.8.5 is the fix version for the vulnerability issue CVE-2022-41064 but Nexus still reports it. If the package is indeed safe then shouldn’t Nexus update this issue?

Source: GitHub Advisory Database · GitHub

post by mfrost on Jan 12, 2023

Maura Frost
Hi @valourie - thanks for reaching out. I reached out to our team about this. There was a patch released on version 4.8.5. However, upon further investigation, our security research team determined that there were some scenarios where users with "fixed" versions were still vulnerable, which is why Nexus still reports this. There is more information in Nexus Lifecycle that explains this further in an Advisory Deviation Notice associated with this issue.

New & Unread Topics

Topic Replies Views Activity
Bom scan does not generate a report 3 122 Mar 11
how to use remote tcp socket instead of local unix socket for nexus iq container image scan for pulling neuvector image from private registry 1 65 Apr 21
Batch Deletion of expired waivers 1 26 26d
Migration Issue during Nexus 2 to Nexus 3 upgrade (LDAP Configuration Error) 0 81 Dec 2025
How could I find out the role name 1 65 Aug 2025