-
QuestionHi, I'd like to know how the severity of trivy works, I thought it just use the CVE severity? But the ruby rexml gem CVE, https://www.cve.org/CVERecord?id=CVE-2024-49761, I got HIGH by trivy output, but I saw Medium in cve.org. somewhere wrong? Thanks TargetContainer Image ScannerVulnerability Output FormatTable ModeStandalone Operating SystemRocky Linux 9.0 Version# trivy --version
Version: 0.58.0
Vulnerability DB:
Version: 2
UpdatedAt: 2024-12-17 06:16:04.798697378 +0000 UTC
NextUpdate: 2024-12-18 06:16:04.798697017 +0000 UTC
DownloadedAt: 2024-12-17 07:25:33.40114213 +0000 UTC
Java DB:
Version: 1
UpdatedAt: 2024-12-17 02:46:02.884793825 +0000 UTC
NextUpdate: 2024-12-20 02:46:02.884793715 +0000 UTC
DownloadedAt: 2024-12-17 07:38:13.416442913 +0000 UTC |
Beta Was this translation helpful? Give feedback.
Answered by
knqyf263
Dec 17, 2024
Replies: 1 comment 2 replies
-
trivy output when I scan container images:
|
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
It's described here: https://trivy.dev/latest/docs/scanner/vulnerability/#severity-selection