Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False positive in vulnerability scan (CVE-2023-27482) #23335

Open
gitusr-gcar opened this issue May 7, 2024 · 1 comment
Open

False positive in vulnerability scan (CVE-2023-27482) #23335

gitusr-gcar opened this issue May 7, 2024 · 1 comment
Assignees

Comments

@gitusr-gcar
Copy link

Wazuh version
4.7

There appears to be a false positive related to CVE-2023-27482.
In my installation, there is a CentOS 7 server running the "supervisord" process (see http://supervisord.org/) version 4.2.1-1.el7, which is erroneously associated with the CVE-2023-27482 vulnerability which is instead related to a "supervisor" component in the Home Automation application (condition: "Package less than 2023.03.1").

@MiguelazoDS
Copy link
Member

Hi @gitusr-gcar,

Indeed, this is considering a package with the same name but a different vendor.

https://nvd.nist.gov/vuln/detail/CVE-2023-27482

The RH CVEs feed does not report anything about this CVE so this should be considered not vulnerable.

To overcome this kind of problem, we are refactoring the vulnerability scanner. Now the CVE content will be sanitized before the manager uses it.

#14153

We'll have this issue in mind to avoid repeating the same behavior. Thanks for reporting this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants