Trivy rootfs scan is reporting false positives for ntp and dhcp RPM libraries with "centos" branding in version #4244
dmarcuccio-solace
started this conversation in
False Detection
Replies: 1 comment
-
This issue is stale because it has been labeled with inactivity. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
CVE-2021-25217, CVE-2020-13817, and CVE-2020-11868 are being detected by a rootfs Trivy scan on a centos 7.9.2009 host, even though the packages have these vulnerabilities fixed according to centos.pkgs.org. It appears that Trivy could be running into issues with the "centos" branding in the package versioning, but this is just a theory.
JSON Output of run with
-debug
:Output of
trivy -v
:Additional details (base image name, container registry info...):
Library versions installed on host:
Changelogs on centos.pkgs.org state they have been fixed in these versions:
for dhclient, dhcp-libs, dhcp-common:
https://centos.pkgs.org/7/centos-updates-x86_64/dhclient-4.2.5-83.el7.centos.1.x86_64.rpm.html
https://centos.pkgs.org/7/centos-updates-x86_64/dhcp-libs-4.2.5-83.el7.centos.1.x86_64.rpm.html
https://centos.pkgs.org/7/centos-updates-x86_64/dhcp-common-4.2.5-83.el7.centos.1.x86_64.rpm.html
for ntp, ntpdate:
https://centos.pkgs.org/7/centos-x86_64/ntp-4.2.6p5-29.el7.centos.2.x86_64.rpm.html
https://centos.pkgs.org/7/centos-x86_64/ntpdate-4.2.6p5-29.el7.centos.2.x86_64.rpm.html
Beta Was this translation helpful? Give feedback.
All reactions