diff --git a/dependency-check-core/src/main/java/org/owasp/dependencycheck/analyzer/FalsePositiveAnalyzer.java b/dependency-check-core/src/main/java/org/owasp/dependencycheck/analyzer/FalsePositiveAnalyzer.java index 9c7cc64cd..d6bc6a461 100644 --- a/dependency-check-core/src/main/java/org/owasp/dependencycheck/analyzer/FalsePositiveAnalyzer.java +++ b/dependency-check-core/src/main/java/org/owasp/dependencycheck/analyzer/FalsePositiveAnalyzer.java @@ -285,6 +285,9 @@ public class FalsePositiveAnalyzer extends AbstractAnalyzer { } else if (i.getValue().startsWith("cpe:/a:m-core:m-core") && !dependency.getEvidenceUsed().containsUsedString("m-core")) { itr.remove(); + } else if (i.getValue().startsWith("cpe:/a:jboss:jboss") + && !dependency.getFileName().toLowerCase().matches("jboss-[\\d\\.]+(GA)?\\.jar")) { + itr.remove(); } } }