Replies: 1 comment
-
hi @echalegre Trivy CLI output overrides with any vendor advisory, in this case GitHub marks this as a HIGH GHSA-c28r-hw5m-5gv3 AVD on the other hand shows the NVD score https://nvd.nist.gov/vuln/detail/cve-2022-31159 which is a MEDIUM. We also show other vendors' rating in the AVD page but at the moment GitHub isn't listed, so that's why maybe you got confused. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
When I execute a trivy image to scanner a image, trivy list all vulnerabilities from image.
But some vulnerabilities are marked with one severity and when I enter the site the severity is another.
Desired Behavior
Vulnerability on CLI and Site (https://avd.aquasec.com/nvd/) is equal
Actual Behavior
Vulnerabilities is no equal
Reproduction Steps
Target
None
Scanner
None
Output Format
None
Mode
None
Debug Output
Operating System
macOS Sequoia
Version
Checklist
trivy clean --all
Beta Was this translation helpful? Give feedback.
All reactions