CVE-2025-46569: Improper Control of Generation of Code ('Code Injecton')#2177
CVE-2025-46569: Improper Control of Generation of Code ('Code Injecton')#2177jdesouza wants to merge 1 commit intoaquasecurity:masterfrom
Conversation
|
tfsec does not run OPA in server mode. |
Cool, thanks for your replay. |
|
@simar7 - I would move to trivy but last year when we tried to move to trivy to replace tfsec we missed some features:
|
Do you have an example? Trivy is able to scan terraform plan as well. https://trivy.dev/latest/docs/coverage/iac/terraform/
Yes we no longer have support for checks written in Go. All custom checks must be written in Rego. But if this is an issue, I would like to understand what is the friction point. We have written some docs on writing custom checks https://trivy.dev/latest/tutorials/misconfiguration/custom-checks/ but if they are not enough or if you are running into other issues please let us know. |
|
|
As mentioned In the docs Trivy can scan both. |
CVE-2025-46569: Improper Control of Generation of Code ('Code Injecton')
https://avd.aquasec.com/nvd/2025/cve-2025-46569/