aboutcode-org / aboutcode-org/vulnerablecode

RHSA is polluting the data quality

オープン
#1,084 コメント 0 件 リアクション 0 件 担当者 1 名 @keshav-space が担当を希望しています GitHub で見る
9-next data-quality
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

[VCID-67rm-w5m7-aaar](https://public.vulnerablecode.io/vulnerabilities/VCID-67rm-w5m7-aaar) contains unrelated redhat packages in `affected packages`

```
pkg:rpm/redhat/python27-babel@0.9.6-10?arch=el7
pkg:rpm/redhat/python27-python@2.7.18-3?arch=el7
pkg:rpm/redhat/python27-python-jinja2@2.6-16?arch=el7
pkg:rpm/redhat/python27-python-pygments@1.5-5?arch=el7
pkg:rpm/redhat/rh-python38-babel@2.7.0-12?arch=el7
pkg:rpm/redhat/rh-python38-python@3.8.11-2?arch=el7
pkg:rpm/redhat/rh-python38-python-cryptography@2.8-5?arch=el7
pkg:rpm/redhat/rh-python38-python-lxml@4.4.1-7?arch=el7
pkg:rpm/redhat/rh-python38-python-pip@19.3.1-2?arch=el7
pkg:rpm/redhat/rh-python38-python-urllib3@1.25.7-7?arch=el7
```
[VCID-67rm-w5m7-aaar](https://public.vulnerablecode.io/vulnerabilities/VCID-67rm-w5m7-aaar) alias [CVE-2020-28493](https://nvd.nist.gov/vuln/detail/CVE-2020-28493) is essentially a security advisory for jinja2 and has nothing to do with cryptography or pip.

Upon further investigation it turn out that redhat advisory is clubbing bunch of unrelated CVEs in their [RHSA-2021:3252](https://access.redhat.com/errata/RHSA-2021:3252) advisory resulting in this mess. And it's the same story for all RHSA advisories.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。