CVE-2023-2976 (Guava vulnerability) #4839
Closed
brfrn169
started this conversation in
False Detection
Replies: 3 comments 4 replies
-
Hello @brfrn169
Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
2 replies
-
|
Beta Was this translation helpful? Give feedback.
0 replies
-
Hello, |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Question
In our Java project, we use the Guava library (
com.google.guava:guava:32.0.0-jre
). When we ran the Trivy vulnerability scanner, we got the following result:However, upon reviewing the
CVE-2023-2976
vulnerability, it appears that it is not the32.0.1
version that resolves the CVE, but rather32.0.0
, according to the document:Therefore, I believe that the Trivy vulnerability scanner should not report this vulnerability. What are your thoughts?
Target
Container Image
Scanner
Vulnerability
Output Format
Table
Mode
Standalone
Operating System
No response
Version
No response
Beta Was this translation helpful? Give feedback.
All reactions