CVE-2023-44487 was not detected in jar file #5504
DuyTran-TomTom
started this conversation in
False Detection
Replies: 1 comment
-
Hello @DuyTran-TomTom Looks like GHSA hasn't information that java package is vulnerable - GHSA-qppj-fm5r-hxr3 Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2023-44487
Description
CVE-2023-44487 is presented in netty-* packages from 4.1.0 to up to and excluding 4.1.100
https://netty.io/news/2023/10/10/4-1-100-Final.html
https://nvd.nist.gov/vuln/detail/CVE-2023-44487
This CVE was not detected by trivy scan.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
Ubuntu 22.04
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions