Critical vulnerability in trivy-operator:0.22.0
image (CVE-2024-41110)
#2218
Labels
kind/bug
Categorizes issue or PR as related to a bug.
What steps did you take and what happened:
1.
docker pull ghcr.io/aquasecurity/trivy-operator:0.22.0
2.
trivy image ghcr.io/aquasecurity/trivy-operator:0.22.0 --severity CRITICAL
Produces:
What did you expect to happen:
No critical vulnerabilities.
Anything else you would like to add:
The same vulnerability is also reported by Trivy Operator running in Kubernetes, not just locally using the Trivy CLI.
Environment:
trivy-operator version
): v0.22.0kubectl version
): v1.28.9The text was updated successfully, but these errors were encountered: