No vulnerabilities identified for pkg:maven/org.apache.tomcat.embed/tomcat-embed-core #5816
Closed
biehl1
started this conversation in
False Detection
Replies: 1 comment
-
Hello @biehl1 I can't find info that artifacts for We use Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
No advisories are found for
pkg:maven/org.apache.tomcat.embed/[email protected]
while multiple are reported for such version, namely CVE-2023-46589, CVE-2023-45648, CVE-2023-44487, CVE-2023-42795.Ref: https://tomcat.apache.org/security-10.html
Desired Behavior
Advisories related to tomcat-embed-core should be identified
Actual Behavior
While trivy is able to report vulnerabilities for certain jar components (example below) the tool provides empty results for tomcat-embed-core instance.
Reproduction Steps
Target
SBOM
Scanner
Vulnerability
Output Format
Table
Mode
Standalone
Debug Output
Operating System
macOS / docker
Version
Checklist
trivy image --reset
Beta Was this translation helpful? Give feedback.
All reactions