False detection of CVE-2020-8559 in k8s.io/apimachinery #6560
Closed
ajchiarello
started this conversation in
False Detection
Replies: 1 comment 1 reply
-
Updating the database today seems to have resolved this for me:
|
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2020-8559
Description
It looks like it is conflating the versions of Kubernetes that are vulnerable (v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6) with the version of the apimachinery library (which follows a different versioning scheme with the most recent version being v0.30.0 from last week.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
alpine 3.19, among others.
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions