False negative: clamav 1.2.x is out of support, has vulnerabilities and is in Alpine 3.20 and is not detected #8056
Closed
kolbma
started this conversation in
False Detection
Replies: 1 comment 6 replies
-
In general, it's listed here. For your specific case, https://secdb.alpinelinux.org/v3.20/. You can see those vulnerabilities are not listed. |
Beta Was this translation helpful? Give feedback.
6 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2024-20506,CVE-2024-20505
Description
Which vulnerability sources are used for scanning Alpine images?
The CVEs say all 1.2.x versions are vulnerable.
Alpine has some human resource problem to manage security in its packages.
Although now only Alpine 3.21 is supported, the clamav 1.2.2 package has been undetected for months while Alpine 3.20 has been stable and supported.
Reproduction Steps
1. Create Alpine 3.20 docker image and apk add clamav 2. docker push to harbor instance using trivy scanner 3. Doesn't detect vulnerability
Target
Container Image
Scanner
Vulnerability
Target OS
Alpine 3.20
Debug Output
Don't know how to do this with harbor trivy adapter.
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions