aquasecurity / microscanner

Scan your container images for package vulnerabilities with Aqua Security
859 stars 108 forks source link

Cassandra 2.2.14 incorrectly identified as having CVEs #26

Open elsmorian opened 5 years ago

elsmorian commented 5 years ago

When scanning a container that is based on the official Cassandra:2.2.14 image, Microscanner incorrectly identifies two CVEs that do not apply to this version, see https://gist.github.com/elsmorian/79e0148c2508b1be7d1ddb4b83f0385e for Microscanner output.