Skip to content

Fals positive detection for CVE-2024-24806 #6180

Closed Answered by DmitriyLewen
dhirschfeld asked this question in Q&A
Discussion options

You must be logged in to vote

Hello @dhirschfeld
Thanks for your report!

Debian didn't release fix of CVE-2024-24806 for Debian 12 - https://security-tracker.debian.org/tracker/CVE-2024-24806

We can't detect info that installed package was derived from another release - This is why Trivy reports this CVE.

You can use VEX to filter this CVE yourself.

Regards, Dmitriy

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by DmitriyLewen
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question. scan/vulnerability Issues relating to vulnerability scanning
2 participants