UNCLASSIFIED - NO CUI

Need more details in security scan feedback

Hi,

As it stands today in the feedback offered by DSOP, we'd need to know the actual components affected by a vulnerability.

For example, CVE-2019-20445: io.netty_netty - 3.6.6.Final could apply to various underlying jar files that make up products. Without that information, providing a justification can be at best generic.

Thank you.