-
Story
-
Resolution: Done
-
Major
-
None
-
False
-
False
-
Undefined
-
With the introduction of Clair V4's new Enrichment feature (substituting for Clair V2's NVD data), we need to ensure this additional data is carried forward with Quay's security scan API as well.
See output from:
Specifically the sections like:
{
"Name": "CVE-2020-8177",
"NamespaceName": "debian:9",
"Link": "https://security-tracker.debian.org/tracker/CVE-2020-8177",
"FixedBy": "7.52.1-5+deb9u11",
"Description": "curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.",
"Metadata": {
"NVD": {
"CVSSv3":
,
"CVSSv2":
}
},
- is related to
-
PROJQUAY-2744 Vulnerabilities for Debian and Alpine based images are marked as unknown, Ubuntu vulnerabilities not detected
- Closed