VEX statement for multiple subcomponents broken in v0.67.2 #9754
Closed
hteichmann-strato
started this conversation in
Bugs
Replies: 1 comment
-
|
Hello @hteichmann-strato Created #9757 Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Description
Since (approximately) Trivy version
0.66.0, OpenVEX statements that target multiplesubcomponentswithin a singleproductare no longer correctly suppressing all intended vulnerabilities.Desired Behavior
The vulnerability
CVE-2019-1010022should be suppressed for both thelibc-binandlibc6components, resulting in a Total: 2 suppressed vulnerabilities, matching the behavior seen in versions<= 0.66.0.Actual Behavior
Actual Output (Total: 1 suppressed): Shows suppression only for
libc-bin.Reproduction Steps
$ docker run -v /tmp/vex:/tmp/vex:z aquasec/trivy:0.66.0 image --vex=/tmp/vex/Debian13-openVEX-CVE-2019-1010022.json debian:trixie-slim --show-suppressedShows suppression for both
libc-binandlibc6$ docker run -v /tmp/vex:/tmp/vex:z aquasec/trivy:0.67.2 image --vex=/tmp/vex/Debian13-openVEX-CVE-2019-1010022.json debian:trixie-slim --show-suppressedShows suppression only for
libc-bin.Operating System
Fedora 42
Version
Checklist
trivy clean --allBeta Was this translation helpful? Give feedback.
All reactions