Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Vulnerability finding are different when scanning from Windows machine vs Linux machine #3403

@amahakalkar

Description

@amahakalkar

Grype version: 0.111.1
Image used for scan: eclipse-temurin:11

I installed grype on windows machine and scanned this image. The vulnerabilities reported contains critical vulnerability CVE-2024-5535 for openssl library on version 3.0.13 version. Whereas if I install grype on ubuntu machine and scan this image, this vulnerability does not appear. I added this specific case but there are differences in for many findings. Is this an expected behavior?
@kzantow

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions