Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

openSUSE: 2023:20022-2 Moderate: Trivy Security Notice Upgrade

opensuse
Calendar Grey June 21, 2022
Dist Opensuse Esm H88
A recent security patch for Trivy addresses numerous vulnerabilities, improving both security and reliability in openSUSE systems.
An update that fixes two vulnerabilities is now available

Description

This update for trivy fixes the following issues:

trivy was updated to version 0.28.0 (boo#1199760, CVE-2022-28946):

* fix: remove Highlighted from json output (#2131)

* fix: remove trivy-kubernetes replace (#2132)

* docs: Add Operator docs under Kubernetes section (#2111)

* fix(k8s): security-checks panic (#2127)

* ci: added k8s scope (#2130)

* docs: Update misconfig output in examples (#2128)

* fix(misconf): Fix coloured output in Goland terminal (#2126)

* docs(secret): Fix default value of --security-checks in docs (#2107)

* refactor(report): move colorize function from trivy-db (#2122)

* feat: k8s resource scanning (#2118)

* chore: add CODEOWNERS (#2121)

* feat(image): add `--server` option for remote scans (#1871)

* refactor: k8s (#2116)

* refactor: export useful APIs (#2108)

* docs: fix k8s doc (#2114)

* feat(kubernetes): Add report flag for summary (#2112)

* fix: Remove problematic advanced rego policies (#2113)

*...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2022-10022=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 i586 s390x x86_64):

trivy-0.28.0-bp154.2.3.1

References

https://www.suse.com/security/cve/CVE-2022-23648.html

https://www.suse.com/security/cve/CVE-2022-28946.html

https://bugzilla.suse.com/1199760

Announcement ID: openSUSE-SU-2022:10022-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here