🛡️ openSUSE-SU-2025:0056-1 — trivy (CVE-2024-45337 +7 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for trivy

This update for trivy fixes the following issues:

Update to version 0.58.2 (

boo#1234512, CVE-2024-45337,

boo#1235265, CVE-2024-45338):

  • fix(misconf): allow null values only for tf variables [backport: release/v0.58] (#8238)
  • fix(suse): SUSE - update OSType constants and references for compatility [backport: release/v0.58] (#8237)
  • fix: CVE-2025-21613 and CVE-2025-21614 : go-git: argument injection via the URL field [backport: release/v0.58] (#8215)
  • fix(sbom): attach nested packages to Application [backport: release/v0.58] (#8168)
  • fix(python): skip dev group's deps for poetry [backport: release/v0.58] (#8158)
  • fix(sbom): use root package for unknown dependencies (if exists) [backport: release/v0.58] (#8156)
  • chore(deps): bump golang.org/x/net from v0.32.0 to v0.33.0 [backport: release/v0.58] (#8142)
  • chore(deps): bump github.com/CycloneDX/cyclonedx-go from v0.9.1 to v0.9.2 [backport: release/v0.58] (#8136)
  • fix(redhat): correct rewriting of recommendations for the same vulnerability [backport: release/v0.58] (#8135)
  • fix(oracle): add architectures support for advisories [backport: release/v0.58] (#8125)
  • fix(sbom): fix wrong overwriting of applications obtained from different sbom files but having same app type [backport: release/v0.58] (#8124)
  • chore(deps): bump golang.org/x/crypto from 0.30.0 to 0.31.0 [backport: release/v0.58] (#8122)
  • fix: handle BLOW_UNKNOWN error to download DBs [backport: release/v0.58] (#8121)
  • fix(java): correctly overwrite version from depManagement if dependency uses project.* props [backport: release/v0.58] (#8119)
  • release: v0.58.0 [main] (#7874)
  • fix(misconf): wrap AWS EnvVar to iac types (#7407)
  • chore(deps): Upgrade trivy-checks (#8018)
  • refactor(misconf): Remove unused options (#7896)
  • docs: add terminology page to explain Trivy concepts (#7996)
  • feat: add workspaceRelationship (#7889)
  • refactor(sbom): simplify relationship generation (#7985)
  • docs: improve databases documentation (#7732)
  • refactor: remove support for custom Terraform checks (#7901)
  • docs: drop AWS account scanning (#7997)
  • fix(aws): change CPU and Memory type of ContainerDefinition to a string (#7995)
  • fix(cli): Handle empty ignore files more gracefully (#7962)
  • fix(misconf): load full Terraform module (#7925)
  • fix(misconf): properly resolve local Terraform cache (#7983)
  • refactor(k8s): add v prefix for Go packages (#7839)
  • test: replace Go checks with Rego (#7867)
  • feat(misconf): log causes of HCL file parsing errors (#7634)
  • chore(deps): bump the aws group across 1 directory with 7 updates (#7991)
  • chore(deps): bump github.com/moby/buildkit from 0.17.0 to 0.17.2 in the docker group across 1 directory (#7990)
  • chore(deps): update csaf module dependency from csaf-poc to gocsaf (#7992)
  • chore: downgrade the failed block expand message to debug (#7964)
  • fix(misconf): do not erase variable type for child modules (#7941)
  • feat(go): construct dependencies of go.mod main module in the parser (#7977)
  • feat(go): construct dependencies in the parser (#7973)
  • feat: add cvss v4 score and vector in scan response (#7968)
  • docs: add overview page for others (#7972)
  • fix(sbom): Fixes for Programming Language Vulnerabilities and SBOM Package Maintainer Details (#7871)
  • feat(suse): Align SUSE/OpenSUSE OS Identifiers (#7965)
  • chore(deps): bump the common group with 4 updates (#7949)
  • feat(oracle): add flavors support (#7858)
  • fix(misconf): Update trivy-checks default repo to mirror.gcr.io (#7953)
  • chore(deps): Bump up trivy-checks to v1.3.0 (#7959)
  • fix(k8s): check all results for vulnerabilities (#7946)
  • ci(helm): bump Trivy version to 0.57.1 for Trivy Helm Chart 0.9.0 (#7945)
  • feat(secret): Add built-in secrets rules for Private Packagist (#7826)
  • docs: Fix broken links (#7900)
  • docs: fix mistakes/typos (#7942)
  • feat: Update registry fallbacks (#7679)
  • fix(alpine): add UID for removed packages (#7887)
  • chore(deps): bump the aws group with 6 updates (#7902)
  • chore(deps): bump the common group with 6 updates (#7904)
  • fix(debian): infinite loop (#7928)
  • fix(redhat): don't return error if root/buildinfo/content_manifests/ contains files that are not contentSets files (#7912)
  • docs: add note about temporary podman socket (#7921)
  • docs: combine trivy.dev into trivy docs (#7884)
  • test: change branch in spdx schema link to check in integration tests (#7935)
  • docs: add Headlamp to the Trivy Ecosystem page (#7916)
  • fix(report): handle [email protected] schema for misconfigs in sarif report (#7898)
  • chore(k8s): enhance k8s scan log (#6997)
  • fix(terraform): set null value as fallback for missing variables (#7669)
  • fix(misconf): handle null properties in CloudFormation templates (#7813)
  • fix(fs): add missing defered Cleanup() call to post analyzer fs (#7882)

Affected software

openSUSE-SU-2025:0056-1 is recorded against 1 package.

  • trivy (fixed in 0.58.2-bp156.2.6.1)

Timeline and source

Published on 7 February 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

lists.opensuse.org (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-02-07
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
trivy 0.58.2-bp156.2.6.1

Similar Threats

Free Vulnerability Check

Is your site affected by openSUSE-SU-2025:0056-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2025:0056-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025