aboutcode-org / aboutcode-org/vulnerablecode

Clarify apache_httpd importer references and severities

Abierto
#1,006 0 comentarios 0 reacciones 1 asignado Reclamado por @johnmhoran Ver en GitHub
import-improver-migration versioning
Lenguaje dominante
Python
Estrellas
702
Forks
328
Merge medio
3 d 8 h
PR fusionados (30 d)
3

Descripción

The Apache HTTP Server advisories are published as a series of JSON files, one advisory per file. The most recent, for example, is https://httpd.apache.org/security/json/CVE-2022-31813.json. This excerpt shows the potential reference and severity data:

```
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"generator": {
"engine": "Vulnogram 0.0.9"
},
"CVE_data_meta": {
"ID": "CVE-2022-31813",
"ASSIGNER": "security@apache.org",
"DATE_PUBLIC": "",
"TITLE": "mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism",
"AKA": "",
"STATE": "REVIEW"
},

. . .

"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"url": "",
"name": ""
}
]
},
"configuration": [],
"impact": [
{
"other": "low"
}
],

. . .

}
```

My understanding is that without a reference URL we cannot report the `low` severity value.

- One potential solution is to use the JSON file URL as the reference URL, which the current `apache_httpd.py` already effectively does by reconstructing that URL with the `["CVE_data_meta"]["ID"]` value.

- However, even if that's the right approach, this does not look like a valid reference:

```
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"url": "",
"name": ""
}
]
},
```

- In that case (or when the entry is simply `"references": {},`), what does our JSON reference entry look like, and does this affect our reporting the `low` severity value? Is this the desired result?

```
"references": [
{
"reference_id": "CVE-2022-31813",
"url": "https://httpd.apache.org/security/json/CVE-2022-31813.json",
"severities": [
{
"system": "apache_httpd",
"value": "low"
}
]
}
],
```

And one question re version/versionrange:

The current code uses `SemverVersion` and `VersionRange`; for `postgresql.py` we're using `GenericVersion` and `GenericVersionRange`; and perhaps we might even want to create a `univers` version scheme for `apache_httpd`. What factors do we consider in making this choice? The relevant JSON data from [the advisory we've been discussing](https://httpd.apache.org/security/json/CVE-2022-31813.json), for example, is

```
"version": {
"version_data": [
{
"version_name": "Apache HTTP Server 2.4",
"version_affected": "<=",
"version_value": "2.4.53",
"platform": ""
}
]
}
```

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.