Wrong xz-libs 5.4.6 version showing as vulnerable #6448
fhielpos
started this conversation in
False Detection
Replies: 2 comments 3 replies
-
Alpine advisories define fixed versions only as below.
This means that older versions rather than fixed version are considered vulnerable. Trivy relies on public advisories. We cannot handle this kind of case. |
Beta Was this translation helpful? Give feedback.
3 replies
-
#6442 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2024-3094
Description
The xz-libs version 5.4.6 should not be vulnerable to the CVE-2024-3094. The vulnerable versions are 5.6.0 and 5.6.1.
Here Trivy shows the following library as vulnerable:
Here is the json for the CVE:
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
alpine 3.19
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions