DependencyTrack / DependencyTrack/dependency-track
Incorrectly reported severity
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior
[GHSA-m7v2-7gxm-vc2v](https://github.com/advisories/GHSA-m7v2-7gxm-vc2v) is being reported as a `CRITICAL` vulnerability when the assigned severity is `HIGH`.
### Steps to Reproduce
1. SBOM uploaded with the `symfony/monolog-bridge` dependency.
2. Internal analyser runs and assigns the `GHSA-m7v2-7gxm-vc2v` to the project.
3. Assigns it as a `CRITICAL` instead of `HIGH` severity.
### Expected Behavior
Is assigned `HIGH` severity in Dependency Track as per the GItHub and NVD severity.
### Dependency-Track Version
5.x
### Browser
N/A
### Checklist
- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/main/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported
Contributor guide
Research direction
Start by reproducing the report with an SBOM containing the symfony/monolog-bridge dependency and the GHSA-m7v2-7gxm-vc2v advisory. Trace the internal analyser's severity assignment and verify that the reported severity matches the GitHub and NVD value of HIGH rather than CRITICAL.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100