aiohttp v3.8.5 false positive #4897
Closed
rubur-webbeds
started this conversation in
False Detection
Replies: 2 comments
-
Hello, second this, it is blocking our delivery pipeline :( |
Beta Was this translation helpful? Give feedback.
0 replies
-
Hi @rubur-webbeds . Thank you for your report! |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2023-37276
Description
Hello,
trivy detects CVE-2023-37276 in aiohttp v3.8.5.
After checking Python Packaging Advisory Database PYSEC-2023-120, it seems like the vulnerability affects up to v3.8.4.
Reproduction Steps
docker build -t aiohttp-vuln .
trivy image aiohttp-vuln
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions