Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.833596
Category:SuSE Local Security Checks
Title:openSUSE: Security Advisory for trivy (openSUSE-SU-2022:10081-1)
Summary:The remote host is missing an update for the 'trivy'; package(s) announced via the openSUSE-SU-2022:10081-1 advisory.
Description:Summary:
The remote host is missing an update for the 'trivy'
package(s) announced via the openSUSE-SU-2022:10081-1 advisory.

Vulnerability Insight:
This update for trivy fixes the following issues:
trivy was updated to version 0.30.4:

* fix: remove the first arg when running as a plugin (#2595)

* fix: k8s controlplaner scanning (#2593)

* fix(vuln): GitLab report template (#2578)
Update to version 0.30.3:

* fix(server): use a new db worker for hot updates (#2581)

* docs: add trivy with download-db-only flag to Air-Gapped Environment
(#2583)

* docs: split commands to download db for different versions of oras
(#2582)

* feat(report): export exitcode for license checks (#2564)

* fix: cli can use lowercase for severities (#2565)

* fix: allow subcommands with TRIVY_RUN_AS_PLUGIN (#2577)

* fix: add missing types in TypeOSes and TypeLanguages in analyzer (#2569)

* fix: enable some features of the wasm runtime (#2575)

* fix(k8s): no error logged if trivy can't get docker image in kubernetes
mode (#2521)

* docs(sbom): improve sbom attestation documentation (#2566)
Update to version 0.30.2:

* fix(report): show the summary without results (#2548)

* fix(cli): replace '-' to '_' for env vars (#2561)
Update to version 0.30.1:

* chore: remove a test repository (#2551)

* fix(license): lazy loading of classifiers (#2547)

* fix: CVE-2022-1996 in Trivy (#2499)

* docs(sbom): add sbom attestation (#2527)

* feat(rocky): set Rocky Linux 9 EOL (#2543)

* docs: add attributes to the video tag to autoplay demo videos (#2538)

* fix: yaml files with non-string chart name (#2534)

* fix: skip dirs (#2530)

* feat(repo): add support for branch, commit, & tag (#2494)

* fix: remove auto configure environment variables via viper (#2526)
Update to version 0.30.0:

* fix: separating multiple licenses from one line in dpkg copyright files
(#2508)

* fix: change a capital letter for `plugin uninstall` subcommand (#2519)

* fix: k8s hide empty report when scanning resource (#2517)

* refactor: fix comments (#2516)

* fix: scan vendor dir (#2515)

* feat: Add support for license scanning (#2418)

* chore: add owners for secret scanning (#2485)

* fix: remove dependency-tree flag for image subcommand (#2492)

* fix(k8s): add shorthand for k8s namespace flag (#2495)

* docs: add information about using multiple servers to troubleshooting
(#2498)

* ci: add pushing canary build images to registries (#2428)

* feat(dotnet): add support for .Net core .deps.json files (#2487)

* feat(amazon): add support for 2022 version (#2429)

* Type correction bitna ...

Description truncated. Please see the references for more information.

Affected Software/OS:
'trivy' package(s) on openSUSE Backports SLE-15-SP4.

Solution:
Please install the updated package(s).

CVSS Score:
6.4

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-1996
https://huntr.dev/bounties/be837427-415c-4d8c-808b-62ce20aa84f1
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OBDD3Q23RCGAGHIXUCWBU6N3S4RNAKXB/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/575BLJ3Y2EQBRNTFR2OSQQ6L2W6UCST3/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZGQKWD6SE75PFBPFVSZYAKAVXKBZXKWS/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W56PP46JVZEKCANBKXFKRVSBBRRMCY6V/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SO5QC2JFW2PXBWAE27OYYYL5SPFUBHTY/
https://github.com/emicklei/go-restful/commit/fd3c327a379ce08c68ef18765bdc925f5d9bad10
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.