GHSA CVE-2024-50379 has 7.2 V3Score but trivy has 9.8 V3Score #8463
dev-sca
started this conversation in
False Detection
Replies: 1 comment 5 replies
-
Trivy uses CVSS v3.1, while GH uses CVSS v4, so the scores are different. @DmitriyLewen Correct me if I'm wrong. |
Beta Was this translation helpful? Give feedback.
5 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2024-50379
Description
I execute trivy via
"trivy sbom <my application sbom path> --format json -o output.json"
and I found my application's vulnerability CVE-2024-50379 has HIGH severity with ghsa source
but ghsa has 9.8 score which should be CRITICAL

so I look up ghsa CVE-2024-50379, and I found it's not 9.8 but 7.2
Reproduction Steps
Target
SBOM
Scanner
Vulnerability
Target OS
Windows
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions