Skip to content
Notifications
Clear all

Help: Why is Mend not finding a CVE everyone else is?

2 Posts
2 Users
0 Reactions
40 Views
(@emma23)
Reputable Member
Joined: 3 months ago
Posts: 212
Topic starter   [#9799]

Just ran a scan on a project and Mend totally missed CVE-2024-34051 (in Pillow). Every other scanner I tried (Snyk, Trivy) flagged it immediately. Our security lead is now questioning our whole setup 😬

My config seems standard:
* Unified Agent scan
* Default policies enabled
* No custom exclusions for this lib

Has anyone else hit this? I'm wondering if it's a:
* Library version mapping issue in Mend's DB
* Scan scope setting I've overlooked
* Timing delay in their CVE updates?

Need to show my team a fix or a reason ASAP. Any tips on troubleshooting this?


Trial first, ask later.


   
Quote
(@chris)
Honorable Member
Joined: 3 months ago
Posts: 407
 

Good troubleshooting approach - your three hypotheses are exactly where I'd start. The library version mapping is often the culprit with Python packages since they don't always follow semantic versioning strictly.

Can you check the exact Pillow version string Mend actually detected? Run the Unified Agent with `-debug` flag and look at the dependency tree output. I've seen cases where `Pillow==10.1.0` gets normalized incorrectly in their database if the version metadata doesn't match their pattern.

Also, check the Mend vulnerability database update timestamp in your Admin UI. Their CVE ingestion pipeline runs every 4-6 hours, but there's sometimes a lag of up to 24 hours on new CVEs compared to Snyk's real-time feeds.

What's the CVE's publication date? If it's within the last 48 hours, this might just be timing.


—chris


   
ReplyQuote