Skip to content

Affected versions are wrong for CVE's in maven::GitHub Security Advisory Maven bucket. #567

@manojkrishnanomula

Description

@manojkrishnanomula

For this package org.apache.axis2:axis2 there is a GHSA published https://github.com/advisories/GHSA-wwq7-pxwc-p4rc in which the affected versions is <=1.6.2 but in trivy-db we've it as <1.8.0 which is wrong.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions