Replies: 1 comment
-
Hello @mcarbonne Trivy detects version for binaries with
That is why Trivy can't detect version of Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
When running
docker run aquasec/trivy image traefik:v3.1.2
(with the latest available trivy image), critical CVE-2024-45410 isn't detected.I don't know if the issue lies in SBOM generation or in the matching of vulnerabilities.
There is a discussion regarding SBOM generation and traefik (#7169) but I don't know if it is related.
Desired Behavior
CVE-2024-45410 detected (as traefik 3.1.2 is vulnerable)
Actual Behavior
critical vulnerability not detected
Reproduction Steps
1. Run `docker run aquasec/trivy image traefik:v3.1.2`
Target
Container Image
Scanner
Vulnerability
Output Format
None
Mode
None
Debug Output
Operating System
Linux
Version
Checklist
trivy clean --all
Beta Was this translation helpful? Give feedback.
All reactions