diff --git a/dependency-check-core/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java b/dependency-check-core/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java index e14a8a39f..c8734f483 100644 --- a/dependency-check-core/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java +++ b/dependency-check-core/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java @@ -768,7 +768,16 @@ public class JarAnalyzer extends AbstractAnalyzer implements Analyzer { } else { versionEvidence.addEvidence(source, key, value, Confidence.MEDIUM); } - + } else if (key.equals("build-id")) { + int pos = value.indexOf('('); + if (pos >= 0) { + value = value.substring(0, pos - 1); + } + pos = value.indexOf('['); + if (pos >= 0) { + value = value.substring(0, pos - 1); + } + versionEvidence.addEvidence(source, key, value, Confidence.MEDIUM); } else if (key.contains("title")) { productEvidence.addEvidence(source, key, value, Confidence.MEDIUM); addMatchingValues(classInformation, value, productEvidence);