-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
For example, frontend image scan report does not show any vulnerabilities, but there are high and medium vulnerabilities in package dependencies.
trivy image scan:
----------------------------------------------
πΎ Image: frontend
Scanning commander::frontend
Done
Uploading trivy CVE report for image frontend of commander module
trivy filesystem scan:
images/frontend/package-lock.json (npm)
Total: 4 (UNKNOWN: 0, LOW: 0, MEDIUM: 3, HIGH: 1, CRITICAL: 0)
ββββββββββββ¬βββββββββββββββββ¬βββββββββββ¬βββββββββ¬ββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Library β Vulnerability β Severity β Status β Installed Version β Fixed Version β Title β
ββββββββββββΌβββββββββββββββββΌβββββββββββΌβββββββββΌββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β vite β CVE-2025-30208 β MEDIUM β fixed β 6.2.0 β 6.2.3, 6.1.2, 6.0.12, 5.4.15, 4.5.10 β vite: Vite bypasses server.fs.deny when using `?raw??` β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-30208 β
β ββββββββββββββββββ€ β β ββββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2025-31125 β β β β 6.2.4, 6.1.3, 6.0.13, 5.4.16, 4.5.11 β vite: Vite has a `server.fs.deny` bypassed for `inline` and β
β β β β β β β `raw` with `?import`... β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-31125 β
β ββββββββββββββββββ€ β β ββββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2025-31486 β β β β 6.2.5, 6.1.4, 6.0.14, 5.4.17, 4.5.12 β vite: Vite allows server.fs.deny to be bypassed with .svg or β
β β β β β β β relative paths... β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-31486 β
ββββββββββββΌβββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β vue-i18n β CVE-2025-27597 β HIGH β β 9.14.2 β 9.14.3, 10.0.6, 11.1.2 β Vue I18n Allows Prototype Pollution in `handleFlatJson` β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-27597 β
ββββββββββββ΄βββββββββββββββββ΄βββββββββββ΄βββββββββ΄ββββββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Metadata
Metadata
Assignees
Labels
No labels