Incorrect mapping of Applicable versions for CVE-2023-28858 & CVE-2023-28859 #4465
Closed
sreecharanguduri
started this conversation in
Bugs
Replies: 1 comment
-
Please open a discussion as false detection. We'd ask for some checks beforehand. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
Hi Team ,
we have reported anomaly with CVEs in discussion title to be applicable for higher versions i.e with 4.x & not impacted with versions running with 2.x which is updated under https://avd.aquasec.com/nvd/2023/cve-2023-28859/ , https://avd.aquasec.com/nvd/2023/cve-2023-28858 respectively on May17th 2023 both in NVD and also AVD. Can we know when would these changes reflect in Trivy DB so that we no more see these as findings from trivy report for older versions of redis Metadata async library running with 2.10.6 , 2.25.1 (2.x) .Thanks in advance
Best
Sreecharan Guduri
Desired Behavior
Applicability is limited to higher versions 4.x and above .
Actual Behavior
Applicability is made generic even for lower versions ( in our case its 2.25.1 , 2.10.6) reported as findings.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Output Format
Table
Mode
Standalone
Debug Output
Operating System
ubuntu
Version
Checklist
trivy --reset
Beta Was this translation helpful? Give feedback.
All reactions