You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
What happened:
Grype 0.91.0, is detecting CVE-2013-6647 and multiple other old CVEs in a recent version of google chromium when this was fixed a long time ago.
I think the following are being detected due to no CPE
Looking at the JSON output of a scan, it looks like it's due to no version information in the CPE,
Looking at the detection for CVE-2013-6647 for example,
What you expected to happen:
no detection of CVE-2013-6647 and similar old CVEs.
How to reproduce it (as minimally and precisely as possible):
The grafana/grafna-image-renderer:3.12.4 image is triggering this bug.
Scanned with a default configuration.
~> grype db list
Status: active
Schema: v6.0.2
Built: 2025-04-07T04:07:01Z
Listing: https://grype.anchore.io/databases/v6/latest.json
DB URL: https://grype.anchore.io/databases/v6/vulnerability-db_v6.0.2_2025-04-07T01:29:59Z_1743998821.tar.zst
Checksum: sha256:8932ea5b149ea0e3b5a487c45879c3716e1153bd865428fd401c49c4ad54c7db
What happened:
Grype 0.91.0, is detecting CVE-2013-6647 and multiple other old CVEs in a recent version of google chromium when this was fixed a long time ago.
I think the following are being detected due to no CPE
Looking at the JSON output of a scan, it looks like it's due to no version information in the CPE,
Looking at the detection for CVE-2013-6647 for example,
What you expected to happen:
no detection of CVE-2013-6647 and similar old CVEs.
How to reproduce it (as minimally and precisely as possible):
The
grafana/grafna-image-renderer:3.12.4
image is triggering this bug.Scanned with a default configuration.
Anything else we need to know?:
Environment:
grype version
:grype db list
:cat /etc/os-release
or similar):The text was updated successfully, but these errors were encountered: