Possible false positive caused by firefox installed with PPA in Ubuntu 22.04 #6792
kitshinghk-crypto
started this conversation in
False Detection
Replies: 1 comment 1 reply
-
I think I understand the issue better now. But is there anything can be done in Trivy to support the deb package version? |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2022-26486
Description
Trivy returns vulnerabilities findings in latest firefox package installed with PPA in ubuntu 22.04.
In https://ubuntu.com/security/CVE-2022-26486 , the fixed version for ubuntu jammy is 1:1snap1-0ubuntu1, which could be wrong, but the installed version 126.0+build2-0ubuntu0.22.04.1~mt1 is newer than 1:1snap1-0ubuntu1. It should not be detected by Trivy.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
Ubuntu 22.04
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions