deepfence / ThreatMapper

Open Source Cloud Native Application Protection Platform (CNAPP)
https://deepfence.io
Apache License 2.0
4.82k stars 583 forks source link

high amount of false positives detetcted #2273

Open intelliIT opened 3 months ago

intelliIT commented 3 months ago

Describe the bug

i am currently in the evaluation of the product for our prod environment, so i did a quick deployment via docker and scanned 2 machines in my test-env. out of 63 critical vulnerabilities a good portition seem to be false positives, almost all coming from linux-modules. help me here if im not seeing or thinking correctly.

To Reproduce

-deploy docker compose -add agents (docker/linux-baremetal) -scan

Screenshots image image

CVE fixed in.. <-> kernel-version

Components/Services affected

Additional context

shyam-dev commented 3 months ago

Thank you for bringing this to our notice. We will take a look at this one....

intelliIT commented 2 months ago

@shyam-dev any news on this?