Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive: CVE-2023-42282 not affected in SUSE ecosystem. #1813

Open
sekveaja opened this issue Apr 18, 2024 · 0 comments
Open

False Positive: CVE-2023-42282 not affected in SUSE ecosystem. #1813

sekveaja opened this issue Apr 18, 2024 · 0 comments
Labels
bug Something isn't working

Comments

@sekveaja
Copy link

sekveaja commented Apr 18, 2024

What happened:
Scan on custom image and get this vulnerability reported:

ip 2.0.0 2.0.1 npm GHSA-78xj-cgh5-2h22 Medium

Issue: "GHSA-78xj-cgh5-2h22" ------> "CVE-2023-42282"
:
"locations": [
{
"path": "/usr/lib64/node_modules/npm18/node_modules/ip/package.json",
"layerID": "sha256:8cbcaaf005a84d63ae8755f21c3504fd224b9fcc1fa6ea021b30938e6065f3a9"
}

What you expected to happen:

As per SUSE Advisory, there is no CVE-2023-42282 found.
Therefore, the CVE is not apply for SUSE ecosystem.
Grype should not report this vulnerability.

It seems that vulnerability is solely based on NVD CPE regardless argument "--distro sles:15.5" is provided to Grype.

How to reproduce it (as minimally and precisely as possible):

Build a test SUSE image and install with this package npm18-18.18.2-150400.9.15.1.x86_64

Anything else we need to know?:

Environment:

  • Output of grype version: grype 0.74.7
  • OS (e.g: cat /etc/os-release or similar):
    NAME="SLES"
    VERSION="15-SP5"
    VERSION_ID="15.5"
    PRETTY_NAME="SUSE Linux Enterprise Server 15 SP5"
@sekveaja sekveaja added the bug Something isn't working label Apr 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
Status: No status
Development

No branches or pull requests

1 participant