CVE-2023-2976 is being detected wrongly flagged , even in runtime 3pp version has the latest patch with vulnerability fixed #10810
Closed
evadivu
started this conversation in
False Detection
Replies: 1 comment
-
|
duplicate of #10809 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
IDs
CVE-2023-2976
Description
Trivy is detective positive for CVE-2023-2976 which is for Google guava . Since its a shaded jar the tool is unable to pick the runtime version correctly
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
RHEL
Debug Output
Version
Checklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions