aboutcode-org / aboutcode-org/vulnerablecode

Clarify apache_httpd importer references and severities

Đang mở
#1,006 0 bình luận 0 reaction 1 người được giao Được @johnmhoran nhận Xem trên GitHub
import-improver-migration versioning
Ngôn ngữ chính
Python
Star
702
Fork
328
Merge trung bình
3 ngày 8 giờ
Pull request đã merge (30 ngày)
3

Mô tả

The Apache HTTP Server advisories are published as a series of JSON files, one advisory per file. The most recent, for example, is https://httpd.apache.org/security/json/CVE-2022-31813.json. This excerpt shows the potential reference and severity data:

```
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"generator": {
"engine": "Vulnogram 0.0.9"
},
"CVE_data_meta": {
"ID": "CVE-2022-31813",
"ASSIGNER": "security@apache.org",
"DATE_PUBLIC": "",
"TITLE": "mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism",
"AKA": "",
"STATE": "REVIEW"
},

. . .

"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"url": "",
"name": ""
}
]
},
"configuration": [],
"impact": [
{
"other": "low"
}
],

. . .

}
```

My understanding is that without a reference URL we cannot report the `low` severity value.

- One potential solution is to use the JSON file URL as the reference URL, which the current `apache_httpd.py` already effectively does by reconstructing that URL with the `["CVE_data_meta"]["ID"]` value.

- However, even if that's the right approach, this does not look like a valid reference:

```
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"url": "",
"name": ""
}
]
},
```

- In that case (or when the entry is simply `"references": {},`), what does our JSON reference entry look like, and does this affect our reporting the `low` severity value? Is this the desired result?

```
"references": [
{
"reference_id": "CVE-2022-31813",
"url": "https://httpd.apache.org/security/json/CVE-2022-31813.json",
"severities": [
{
"system": "apache_httpd",
"value": "low"
}
]
}
],
```

And one question re version/versionrange:

The current code uses `SemverVersion` and `VersionRange`; for `postgresql.py` we're using `GenericVersion` and `GenericVersionRange`; and perhaps we might even want to create a `univers` version scheme for `apache_httpd`. What factors do we consider in making this choice? The relevant JSON data from [the advisory we've been discussing](https://httpd.apache.org/security/json/CVE-2022-31813.json), for example, is

```
"version": {
"version_data": [
{
"version_name": "Apache HTTP Server 2.4",
"version_affected": "<=",
"version_value": "2.4.53",
"platform": ""
}
]
}
```

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.