CVE-2022-3715 reported as LOW when it's actually HIGH #4835
Closed
huornlmj
started this conversation in
False Detection
Replies: 1 comment 3 replies
-
Hello @huornlmj Looks like it is just mistake in For those rare cases, Trivy supports modules. You can create new module to update severity for this CVE. Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2022-3715
Description
Reported as HIGH (CVSS 3.1 7.8) at https://ubuntu.com/security/CVE-2022-3715 and also HIGH with in the JSON output (details below)
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
Ubuntu:22.04
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions