Skip to content

CVE-2023-38646 not being detected #6350

Closed Answered by exiett
exiett asked this question in Q&A
Mar 19, 2024 · 2 comments · 13 replies
Discussion options

You must be logged in to vote

@DmitriyLewen, I've read the blogpost made by the team that found out this vulnerability in Metabase (see here).

I've concluded that this CVE is more linked to faulty application logic, which is written in Clojure, rather than a vulnerable package by itself.

Does this classify this vulnerability as undetectable by Trivy?

Replies: 2 comments 13 replies

Comment options

You must be logged in to vote
6 replies
@DmitriyLewen
Comment options

@exiett
Comment options

@DmitriyLewen
Comment options

@exiett
Comment options

@lvanbuiten
Comment options

Comment options

You must be logged in to vote
7 replies
@DmitriyLewen
Comment options

@exiett
Comment options

Answer selected by DmitriyLewen
@DmitriyLewen
Comment options

@exiett
Comment options

@DmitriyLewen
Comment options

@lucasaboud0
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
scan/vulnerability Issues relating to vulnerability scanning
4 participants