Trivy is unable to detect CVE-2023-31419 for elasticsearch-7.10.2.jar #5573
Closed
navzen2000
started this conversation in
Bugs
Replies: 2 comments 12 replies
-
https://aquasecurity.github.io/trivy/v0.47/docs/coverage/language/ |
Beta Was this translation helpful? Give feedback.
12 replies
-
Not happy with response provided above, very illogical |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
Trivy is unable to detect CVE-2023-31419 for elasticsearch-7.10.2.jar
Desired Behavior
Grype is able to report, Trivy should also report
grype elasticsearch-7.10.2.jar
✔ Vulnerability DB [no update available]
✔ Indexed file system
✔ Cataloged packages [1 packages]
✔ Scanned for vulnerabilities [6 vulnerabilities]
├── 0 critical, 3 high, 3 medium, 0 low, 0 negligible
└── 0 fixed
NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
elasticsearch 7.10.2 java-archive CVE-2023-31419 High
elasticsearch 7.10.2 java-archive CVE-2023-31418 High
elasticsearch 7.10.2 java-archive CVE-2023-31417 High
elasticsearch 7.10.2 java-archive CVE-2021-22145 Medium
elasticsearch 7.10.2 java-archive CVE-2021-22144 Medium
elasticsearch 7.10.2 java-archive CVE-2021-22134 Medium
Actual Behavior
trivy --scanners vuln fs elasticsearch-7.10.2.jar
2023-11-13T23:11:13.157-0800 INFO Vulnerability scanning is enabled
2023-11-13T23:11:13.159-0800 INFO Number of language-specific files: 0
Reproduction Steps
Target
Filesystem, Container
Scanner
Vulnerability
Output Format
None
Mode
None
Debug Output
Operating System
linux
Version
Checklist
trivy image --reset
Beta Was this translation helpful? Give feedback.
All reactions