Critical
High
Medium
Low
Secrets
Misconfig
| Severity | CVE ID | Package | Installed | Fixed In | Description |
|---|---|---|---|---|---|
| MEDIUM | CVE-2024-35195 | requests | 2.31.0 | 2.32.0 | requests: subsequent requests to the same host ignore cert verification |
| MEDIUM | CVE-2024-47081 | requests | 2.31.0 | 2.32.4 | requests: Requests vulnerable to .netrc credentials leak via malicious URLs |
| Type | File | Line | Match |
|---|---|---|---|
| ✅ No secrets found | |||
| Severity | ID | Check | File | Message |
|---|---|---|---|---|
| HIGH | DS-0002 | Image user should not be 'root' | Dockerfile | Specify at least 1 USER command in Dockerfile with non-root user as argument |
{
"SchemaVersion": 2,
"Trivy": {
"Version": "0.69.0"
},
"ReportID": "019cfa59-8cf0-720f-808e-b0bf920f71f8",
"CreatedAt": "2026-03-17T05:51:38.736137712Z",
"ArtifactID": "sha256:f3d372f0abe7f1511a3cf6f94b8d37d22816b23cc2e0c4adf2d41a2d849c52ca",
"ArtifactName": "/src",
"ArtifactType": "repository",
"Metadata": {
"RepoURL": "https://github.com/eizen-ai/eizen-sop-service.git",
"Branch": "ldev",
"Commit": "9f707cbcfd81c661529a06c7a7064704c3f484f1",
"CommitMsg": "Update requirements.txt",
"Author": "eizen-neeraj <neeraj.palikala@eizen.ai>",
"Committer": "GitHub <noreply@github.com>"
},
"Results": [
{
"Target": "requirements.txt",
"Class": "lang-pkgs",
"Type": "pip",
"Packages": [
{
"Name": "fastapi",
"Identifier": {
"PURL": "pkg:pypi/fastapi@0.115.0",
"UID": "9ea1cd07f1e11f49"
},
"Version": "0.115.0",
"Locations": [
{
"StartLine": 3,
"EndLine": 3
}
],
"AnalyzedBy": "pip"
},
{
"Name": "pymongo",
"Identifier": {
"PURL": "pkg:pypi/pymongo@4.6.3",
"UID": "5b343bb5a139800f"
},
"Version": "4.6.3",
"Locations": [
{
"StartLine": 1,
"EndLine": 1
}
],
"AnalyzedBy": "pip"
},
{
"Name": "requests",
"Identifier": {
"PURL": "pkg:pypi/requests@2.31.0",
"UID": "40610664e64be9fe"
},
"Version": "2.31.0",
"Locations": [
{
"StartLine": 2,
"EndLine": 2
}
],
"AnalyzedBy": "pip"
},
{
"Name": "uvicorn",
"Identifier": {
"PURL": "pkg:pypi/uvicorn@0.30.6",
"UID": "84b68611f98d0503"
},
"Version": "0.30.6",
"Locations": [
{
"StartLine": 4,
"EndLine": 4
}
],
"AnalyzedBy": "pip"
}
],
"Vulnerabilities": [
{
"VulnerabilityID": "CVE-2024-35195",
"VendorIDs": [
"GHSA-9wx4-h78v-vm56"
],
"PkgName": "requests",
"PkgIdentifier": {
"PURL": "pkg:pypi/requests@2.31.0",
"UID": "40610664e64be9fe"
},
"InstalledVersion": "2.31.0",
"FixedVersion": "2.32.0",
"Status": "fixed",
"SeveritySource": "ghsa",
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-35195",
"DataSource": {
"ID": "ghsa",
"Name": "GitHub Security Advisory pip",
"URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
},
"Fingerprint": "sha256:954bea4b60e69a50125bd0b127804ceb006dc89b5f39a5bb811af84a2937cd48",
"Title": "requests: subsequent requests to the same host ignore cert verification",
"Description": "Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.",
"Severity": "MEDIUM",
"CweIDs": [
"CWE-670"
],
"VendorSeverity": {
"alma": 2,
"amazon": 2,
"azure": 2,
"cbl-mariner": 2,
"ghsa": 2,
"oracle-oval": 2,
"photon": 2,
"redhat": 2,
"rocky": 2,
"ubuntu": 2
},
"CVSS": {
"ghsa": {
"V3Vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N",
"V3Score": 5.6
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N",
"V3Score": 5.6
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2025:7049",
"https://access.redhat.com/security/cve/CVE-2024-35195",
"https://bugzilla.redhat.com/2282114",
"https://bugzilla.redhat.com/show_bug.cgi?id=2282114",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35195",
"https://errata.almalinux.org/9/ALSA-2025-7049.html",
"https://errata.rockylinux.org/RLSA-2025:0012",
"https://github.com/psf/requests",
"https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac",
"https://github.com/psf/requests/pull/6655",
"https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56",
"https://linux.oracle.com/cve/CVE-2024-35195.html",
"https://linux.oracle.com/errata/ELSA-2025-7049.html",
"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q",
"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q/",
"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ",
"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ/",
"https://nvd.nist.gov/vuln/detail/CVE-2024-35195",
"https://www.cve.org/CVERecord?id=CVE-2024-35195"
],
"PublishedDate": "2024-05-20T21:15:09.99Z",
"LastModifiedDate": "2024-11-21T09:19:54.51Z"
},
{
"VulnerabilityID": "CVE-2024-47081",
"VendorIDs": [
"GHSA-9hjg-9r4m-mvj7"
],
"PkgName": "requests",
"PkgIdentifier": {
"PURL": "pkg:pypi/requests@2.31.0",
"UID": "40610664e64be9fe"
},
"InstalledVersion": "2.31.0",
"FixedVersion": "2.32.4",
"Status": "fixed",
"SeveritySource": "ghsa",
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-47081",
"DataSource": {
"ID": "ghsa",
"Name": "GitHub Security Advisory pip",
"URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
},
"Fingerprint": "sha256:8813ba048f0ebc75dc92afd89b948ef591ac214fea22dfc1ff1bf7bee67ab7c4",
"Title": "requests: Requests vulnerable to .netrc credentials leak via malicious URLs",
"Description": "Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.",
"Severity": "MEDIUM",
"CweIDs": [
"CWE-522"
],
"VendorSeverity": {
"alma": 2,
"amazon": 2,
"azure": 2,
"cbl-mariner": 2,
"ghsa": 2,
"oracle-oval": 2,
"photon": 2,
"redhat": 2,
"rocky": 2,
"ubuntu": 2
},
"CVSS": {
"ghsa": {
"V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
"V3Score": 5.3
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
"V3Score": 5.3
}
},
"References": [
"http://seclists.org/fulldisclosure/2025/Jun/2",
"http://www.openwall.com/lists/oss-security/2025/06/03/11",
"http://www.openwall.com/lists/oss-security/2025/06/03/9",
"http://www.openwall.com/lists/oss-security/2025/06/04/1",
"http://www.openwall.com/lists/oss-security/2025/06/04/6",
"https://access.redhat.com/errata/RHSA-2025:12519",
"https://access.redhat.com/security/cve/CVE-2024-47081",
"https://bugzilla.redhat.com/2371272",
"https://bugzilla.redhat.com/show_bug.cgi?id=2371272",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47081",
"https://errata.almalinux.org/9/ALSA-2025-12519.html",
"https://errata.rockylinux.org/RLSA-2025:13234",
"https://github.com/psf/requests",
"https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef",
"https://github.com/psf/requests/pull/6965",
"https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7",
"https://linux.oracle.com/cve/CVE-2024-47081.html",
"https://linux.oracle.com/errata/ELSA-2025-14999.html",
"https://nvd.nist.gov/vuln/detail/CVE-2024-47081",
"https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env",
"https://seclists.org/fulldisclosure/2025/Jun/2",
"https://ubuntu.com/security/notices/USN-7568-1",
"https://ubuntu.com/security/notices/USN-7762-1",
"https://www.cve.org/CVERecord?id=CVE-2024-47081",
"https://www.openwall.com/lists/oss-security/2025/06/03/9"
],
"PublishedDate": "2025-06-09T18:15:24.983Z",
"LastModifiedDate": "2025-06-12T16:06:47.857Z"
}
]
},
{
"Target": "Dockerfile",
"Class": "config",
"Type": "dockerfile",
"MisconfSummary": {
"Successes": 23,
"Failures": 1
},
"Misconfigurations": [
{
"Type": "Dockerfile Security Check",
"ID": "DS-0002",
"Title": "Image user should not be 'root'",
"Description": "Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.",
"Message": "Specify at least 1 USER command in Dockerfile with non-root user as argument",
"Namespace": "builtin.dockerfile.DS002",
"Query": "data.builtin.dockerfile.DS002.deny",
"Resolution": "Add 'USER <non root user name>' line to the Dockerfile",
"Severity": "HIGH",
"PrimaryURL": "https://avd.aquasec.com/misconfig/ds-0002",
"References": [
"https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
"https://avd.aquasec.com/misconfig/ds-0002"
],
"Status": "FAIL",
"CauseMetadata": {
"Provider": "Dockerfile",
"Service": "general"
}
}
]
}
]
}