DependencyTrack / DependencyTrack/dependency-track

Incorrectly reported severity

Open
#7,226 1 comment 0 reactions 0 assignees View on GitHub
defect in triage
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

[GHSA-m7v2-7gxm-vc2v](https://github.com/advisories/GHSA-m7v2-7gxm-vc2v) is being reported as a `CRITICAL` vulnerability when the assigned severity is `HIGH`.

### Steps to Reproduce

1. SBOM uploaded with the `symfony/monolog-bridge` dependency.
2. Internal analyser runs and assigns the `GHSA-m7v2-7gxm-vc2v` to the project.
3. Assigns it as a `CRITICAL` instead of `HIGH` severity.

### Expected Behavior

Is assigned `HIGH` severity in Dependency Track as per the GItHub and NVD severity.

### Dependency-Track Version

5.x

### Browser

N/A

### Checklist

- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/main/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the report with an SBOM containing the symfony/monolog-bridge dependency and the GHSA-m7v2-7gxm-vc2v advisory. Trace the internal analyser's severity assignment and verify that the reported severity matches the GitHub and NVD value of HIGH rather than CRITICAL.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.