False Positive: CVE-2017-12621 commons-jelly 1.0.1 #4775
Closed
sekveaja
started this conversation in
False Detection
Replies: 1 comment 1 reply
-
Hello @sekveaja ! Thanks for your report! I created #233. Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2017-12621
Description
Installed common-jelly is version 1.0.1.
Every accessible reference show issue is related to common-jelly < 1.0.1
https://avd.aquasec.com/nvd/cve-2017-12621
GHSA-6g33-82gc-3pw5
https://nvd.nist.gov/vuln/detail/CVE-2017-12621
See Trivy stripped logfile.
The installed version: common-jelly-1.0.1 is not affected according to NVD.
However Trivy is reported as critical, and we believe it is a false positive.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
SUSE Linux enterprise server 15.4
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions