🛡️ openSUSE-SU-2025:0056-1 — trivy (CVE-2024-45337 +7 more)
Description
Security update for trivy
This update for trivy fixes the following issues:
Update to version 0.58.2 (
boo#1234512, CVE-2024-45337,
boo#1235265, CVE-2024-45338):
- fix(misconf): allow null values only for tf variables [backport: release/v0.58] (#8238)
- fix(suse): SUSE - update OSType constants and references for compatility [backport: release/v0.58] (#8237)
- fix: CVE-2025-21613 and CVE-2025-21614 : go-git: argument injection via the URL field [backport: release/v0.58] (#8215)
- fix(sbom): attach nested packages to Application [backport: release/v0.58] (#8168)
- fix(python): skip dev group's deps for poetry [backport: release/v0.58] (#8158)
- fix(sbom): use root package for
unknowndependencies (if exists) [backport: release/v0.58] (#8156) - chore(deps): bump
golang.org/x/netfromv0.32.0tov0.33.0[backport: release/v0.58] (#8142) - chore(deps): bump
github.com/CycloneDX/cyclonedx-gofromv0.9.1tov0.9.2[backport: release/v0.58] (#8136) - fix(redhat): correct rewriting of recommendations for the same vulnerability [backport: release/v0.58] (#8135)
- fix(oracle): add architectures support for advisories [backport: release/v0.58] (#8125)
- fix(sbom): fix wrong overwriting of applications obtained from different sbom files but having same app type [backport: release/v0.58] (#8124)
- chore(deps): bump golang.org/x/crypto from 0.30.0 to 0.31.0 [backport: release/v0.58] (#8122)
- fix: handle
BLOW_UNKNOWNerror to download DBs [backport: release/v0.58] (#8121) - fix(java): correctly overwrite version from depManagement if dependency uses
project.*props [backport: release/v0.58] (#8119) - release: v0.58.0 [main] (#7874)
- fix(misconf): wrap AWS EnvVar to iac types (#7407)
- chore(deps): Upgrade trivy-checks (#8018)
- refactor(misconf): Remove unused options (#7896)
- docs: add terminology page to explain Trivy concepts (#7996)
- feat: add
workspaceRelationship(#7889) - refactor(sbom): simplify relationship generation (#7985)
- docs: improve databases documentation (#7732)
- refactor: remove support for custom Terraform checks (#7901)
- docs: drop AWS account scanning (#7997)
- fix(aws): change CPU and Memory type of ContainerDefinition to a string (#7995)
- fix(cli): Handle empty ignore files more gracefully (#7962)
- fix(misconf): load full Terraform module (#7925)
- fix(misconf): properly resolve local Terraform cache (#7983)
- refactor(k8s): add v prefix for Go packages (#7839)
- test: replace Go checks with Rego (#7867)
- feat(misconf): log causes of HCL file parsing errors (#7634)
- chore(deps): bump the aws group across 1 directory with 7 updates (#7991)
- chore(deps): bump github.com/moby/buildkit from 0.17.0 to 0.17.2 in the docker group across 1 directory (#7990)
- chore(deps): update csaf module dependency from csaf-poc to gocsaf (#7992)
- chore: downgrade the failed block expand message to debug (#7964)
- fix(misconf): do not erase variable type for child modules (#7941)
- feat(go): construct dependencies of
go.modmain module in the parser (#7977) - feat(go): construct dependencies in the parser (#7973)
- feat: add cvss v4 score and vector in scan response (#7968)
- docs: add
overviewpage forothers(#7972) - fix(sbom): Fixes for Programming Language Vulnerabilities and SBOM Package Maintainer Details (#7871)
- feat(suse): Align SUSE/OpenSUSE OS Identifiers (#7965)
- chore(deps): bump the common group with 4 updates (#7949)
- feat(oracle): add
flavorssupport (#7858) - fix(misconf): Update trivy-checks default repo to
mirror.gcr.io(#7953) - chore(deps): Bump up trivy-checks to v1.3.0 (#7959)
- fix(k8s): check all results for vulnerabilities (#7946)
- ci(helm): bump Trivy version to 0.57.1 for Trivy Helm Chart 0.9.0 (#7945)
- feat(secret): Add built-in secrets rules for Private Packagist (#7826)
- docs: Fix broken links (#7900)
- docs: fix mistakes/typos (#7942)
- feat: Update registry fallbacks (#7679)
- fix(alpine): add
UIDfor removed packages (#7887) - chore(deps): bump the aws group with 6 updates (#7902)
- chore(deps): bump the common group with 6 updates (#7904)
- fix(debian): infinite loop (#7928)
- fix(redhat): don't return error if
root/buildinfo/content_manifests/contains files that are notcontentSetsfiles (#7912) - docs: add note about temporary podman socket (#7921)
- docs: combine trivy.dev into trivy docs (#7884)
- test: change branch in spdx schema link to check in integration tests (#7935)
- docs: add Headlamp to the Trivy Ecosystem page (#7916)
- fix(report): handle
[email protected]schema for misconfigs insarifreport (#7898) - chore(k8s): enhance k8s scan log (#6997)
- fix(terraform): set null value as fallback for missing variables (#7669)
- fix(misconf): handle null properties in CloudFormation templates (#7813)
- fix(fs): add missing defered Cleanup() call to post analyzer fs (#7882)
Affected software
openSUSE-SU-2025:0056-1 is recorded against 1 package.
- trivy (fixed in 0.58.2-bp156.2.6.1)
Timeline and source
Published on 7 February 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
lists.opensuse.org (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| trivy | — | 0.58.2-bp156.2.6.1 |
Similar Threats
- Unknown CGA-2j38-cxfp-c8p6
- Unknown CGA-2mv5-7p9w-vp27
- Unknown CGA-33qc-7m28-fvwr
- Unknown CGA-37xx-2fqv-rjhr
- Unknown CGA-382c-27vm-3c8m
Free Vulnerability Check
Is your site affected by openSUSE-SU-2025:0056-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2025:0056-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.