aboutcode-org / aboutcode-org/vulnerablecode

Clarify apache_httpd importer references and severities

未关闭
#1,006 0 条评论 0 个 reaction 已指派 1 人 已被 @johnmhoran 认领 在 GitHub 查看
import-improver-migration versioning
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

The Apache HTTP Server advisories are published as a series of JSON files, one advisory per file. The most recent, for example, is https://httpd.apache.org/security/json/CVE-2022-31813.json. This excerpt shows the potential reference and severity data:

```
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"generator": {
"engine": "Vulnogram 0.0.9"
},
"CVE_data_meta": {
"ID": "CVE-2022-31813",
"ASSIGNER": "security@apache.org",
"DATE_PUBLIC": "",
"TITLE": "mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism",
"AKA": "",
"STATE": "REVIEW"
},

. . .

"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"url": "",
"name": ""
}
]
},
"configuration": [],
"impact": [
{
"other": "low"
}
],

. . .

}
```

My understanding is that without a reference URL we cannot report the `low` severity value.

- One potential solution is to use the JSON file URL as the reference URL, which the current `apache_httpd.py` already effectively does by reconstructing that URL with the `["CVE_data_meta"]["ID"]` value.

- However, even if that's the right approach, this does not look like a valid reference:

```
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"url": "",
"name": ""
}
]
},
```

- In that case (or when the entry is simply `"references": {},`), what does our JSON reference entry look like, and does this affect our reporting the `low` severity value? Is this the desired result?

```
"references": [
{
"reference_id": "CVE-2022-31813",
"url": "https://httpd.apache.org/security/json/CVE-2022-31813.json",
"severities": [
{
"system": "apache_httpd",
"value": "low"
}
]
}
],
```

And one question re version/versionrange:

The current code uses `SemverVersion` and `VersionRange`; for `postgresql.py` we're using `GenericVersion` and `GenericVersionRange`; and perhaps we might even want to create a `univers` version scheme for `apache_httpd`. What factors do we consider in making this choice? The relevant JSON data from [the advisory we've been discussing](https://httpd.apache.org/security/json/CVE-2022-31813.json), for example, is

```
"version": {
"version_data": [
{
"version_name": "Apache HTTP Server 2.4",
"version_affected": "<=",
"version_value": "2.4.53",
"platform": ""
}
]
}
```

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。