Uploaded image for project: 'Red Hat Insights Engineering'
  1. Red Hat Insights Engineering
  2. RHINENG-13590

[RFE] CVE vulnerability scan should look for currently active kernel

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • Vulnerability

      ** Note that this is a public ticket, please refrain from adding any sensitive data. **

      Description of Problem

       

      The external scanner identified CVE-2023-45871 reporting an outdated kernel version (4.18.0-513.9.1.el8_9) as vulnerable. Despite the insight portal indicating "no affected systems," further investigation revealed that the server was running this older kernel. The current booted kernel should be prioritized over the installed kernel versions in the Insights portal's assessment, as it led to a discrepancy in vulnerability reporting.

              Unassigned Unassigned
              rhn-support-jbhatia Jayant Bhatia
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated: