False positive on node.js 18.18.2 on Oracle Linux #5672
Replies: 2 comments 6 replies
-
Hello @bianjp There are some difficulties with parsing Oracle Database. <criterion test_ref="oval:com.oracle.elsa:tst:20237205003" comment="nodejs is earlier than 1:20.8.1-1.module+el8.9.0+90082+b6a613a6"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20237205004" comment="nodejs is signed with the Oracle Linux 8 key"/> We can't be sure that only versions of nodejs Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
-
We can't be sure that only versions of nodejs 20.X.X are vulnerable. You missed this OVAL criterion for that advisory:
This criterion is not optional. It means that this ELSA is only applicable if The enabled version of a stream can be found by looking at the metadata file. For checking
and check that it contains |
Beta Was this translation helpful? Give feedback.
-
IDs
CVE-2023-38552, CVE-2023-39331, CVE-2023-39332, CVE-2023-39333, CVE-2023-44487, CVE-2023-45143
Description
Sorry I don't know how to check whether Oracle oval data source is correct.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
Oracle Linux 8
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions