Possible FP - CVE-2020-1747 in amazon image #7349
TimBrown1611
started this conversation in
False Detection
Replies: 1 comment
-
Hello @TimBrown1611
You install package from source code, so this package is vulnerable.
Vendors OS fix vulnerabilities for their packages (to get these fixed packages - you need to install packages from Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2020-1747
Description
I scanned an image and got CVE-2020-1747
At first look it seems alright, since the version of the python package is indeed vulnerable.
But, this image is based on amazon so I've also looked at their website and saw this CVE is not effected.
here is the link -
https://explore.alas.aws.amazon.com/CVE-2020-1747.html
I don't see any information about the "explore" page of this advisory.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
Amazon 2023
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions