Ansible 7.6.0 being picked up by Trivy for CVE-2020-25636 which is a 3rd party community component (long been fixed) #4480
Closed
mig5
started this conversation in
False Detection
Replies: 1 comment
-
This advisory could be wrong. Please ask them. Please let me close the discussion. If you still think this is a Trivy's bug, please feel free to reopen it. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2020-25636
Description
I keep getting the following using a poetry.lock with Ansible 7.6.0 which came out only 5 days ago:
The issue is not actually part of the core Ansible package - it's part of the 'community-aws' 3rd party plugin, and was fixed years ago. I don't even use this plugin in my ansible setup.
Reproduction Steps
Here is my poetry.lock which lives under the folder 'ansible':
I am running it like so:
Target
Filesystem
Scanner
Vulnerability
Target OS
No response
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions