diff --git a/vuln_scans/mqtt-producer_vuln_scan.sarif b/vuln_scans/mqtt-producer_vuln_scan.sarif index 9852bf3..c45df85 100644 --- a/vuln_scans/mqtt-producer_vuln_scan.sarif +++ b/vuln_scans/mqtt-producer_vuln_scan.sarif @@ -1,12 +1,21 @@ -jpradoar/mqtt-producer:1.1.2 (alpine 3.19.0) -============================================ +For OSS Maintainers: VEX Notice +-------------------------------- +If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement. +VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users. +Learn more and start using VEX: https://aquasecurity.github.io/trivy/v0.56/docs/supply-chain/vex/repo#publishing-vex-documents + +To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable. + + +jpradoar/mqtt-producer:1.1.3-o6ds4isz-Update-feat (alpine 3.19.0) +================================================================= Total: 0 (HIGH: 0, CRITICAL: 0) Python (python-pkg) =================== -Total: 1 (HIGH: 1, CRITICAL: 0) +Total: 2 (HIGH: 2, CRITICAL: 0) ┌───────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────────┐ │ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │ @@ -14,4 +23,8 @@ Total: 1 (HIGH: 1, CRITICAL: 0) │ setuptools (METADATA) │ CVE-2022-40897 │ HIGH │ fixed │ 65.5.0 │ 65.5.1 │ pypa-setuptools: Regular Expression Denial of Service │ │ │ │ │ │ │ │ (ReDoS) in package_index.py │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-40897 │ +│ ├────────────────┤ │ │ ├───────────────┼───────────────────────────────────────────────────────┤ +│ │ CVE-2024-6345 │ │ │ │ 70.0.0 │ pypa/setuptools: Remote code execution via download │ +│ │ │ │ │ │ │ functions in the package_index module in... │ +│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2024-6345 │ └───────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────────┘