Skip to content

Trivy does not detect CVE-2023-20873 #6901

Closed Answered by DmitriyLewen
namandf asked this question in Q&A
Discussion options

You must be logged in to vote

Hellol @namandf
Thanks for your report!

We use GitHub advisory database for java package (https://aquasecurity.github.io/trivy/v0.52/docs/scanner/vulnerability/#data-sources_1).

GitHub database use the following ranges:

If you sure that versions prior to 2.5.0 are vulnerable - please suggest changes on GitHub - https://github.com/advisories/GHSA-g5h3-w546-pj7f/improve

Regards, Dmitriy

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@namandf
Comment options

@DmitriyLewen
Comment options

@namandf
Comment options

Answer selected by DmitriyLewen
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question. scan/vulnerability Issues relating to vulnerability scanning
2 participants