Skip to content

False positive: CVE-2024-1233, CVE-2023-6263, CVE-2024-5971, CVE-2024-7885 on jar file #8540

Answered by DmitriyLewen
sekveaja asked this question in Q&A
Discussion options

You must be logged in to vote

Hello @sekveaja
Thanks for your report!

If package contains jar file and installed from rpm - Trivy skips this jar file - https://trivy.dev/latest/docs/scanner/vulnerability/#handling-software-installed-via-os-packages

But if jar file doesn't relate with rpm package - Trivy checks this file as regular jar file.

Q1: Can you please confirm, if Trivy support backport verification when libraries are in a jar file, zip file?

Trivy doesn't support that.

Q2: What is the suggestion to eliminate these false positive?

You can use one (or multiple) filtering options - https://trivy.dev/latest/docs/configuration/filtering/
I think that VEX will be good for you.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@sekveaja
Comment options

@DmitriyLewen
Comment options

Answer selected by sekveaja
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question. scan/vulnerability Issues relating to vulnerability scanning
2 participants