CVE-2021-40528 is reported as High severity when it is Medium severity #3925
Labels
kind/bug
Categorizes issue or PR as related to a bug.
lifecycle/stale
Denotes an issue or PR has remained open with no activity and will be auto-closed.
scan/vulnerability
Issues relating to vulnerability scanning
Description
CVE-2021-40528 is being reported by trivy as High severity, when it is ranked as Medium/Moderate severity. Besides, that CVE is still flagged for https://oraclelinux.pkgs.org/8/ol8-baseos-latest-aarch64/libgcrypt-1.8.5-7.el8_6.aarch64.rpm.html latest version when it was already fixed (2021-06-28)
What did you expect to happen?
CVE-2021-40528 should be reported as Medium.
What happened instead?
CVE-2021-40528 was reported for a fixed version and with higher severity as mentioned above.
Output of run with
-debug
:Output of
trivy -v
:Additional details (base image name, container registry info...):
The text was updated successfully, but these errors were encountered: