CVE-2023-45853 already fixed in 1:1.3.dfsg+really1.3.1-1, but still tagged as critical in trivy result #7621
Closed
XinwenXiang
started this conversation in
False Detection
Replies: 1 comment
-
Duplicate of #6059 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2023-45853
Description
Hi experts
I'm using the python:3.9-slim as my base image, so i do trivy scan for this image.
I got this in my report:
after learning this CVE Vulnerability, I think this has been fixed in latest version: https://security-tracker.debian.org/tracker/CVE-2023-45853
So I upgrade it in my docker file, but i still get this for 1:1.3.dfsg+really1.3.1-1.
So I think this may should not report this Vulnerability after upgrade it.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
No response
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions