aboutcode-org / aboutcode-org/vulnerablecode

RHSA is polluting the data quality

未關閉
#1,084 0 則留言 0 個 reaction 已指派 1 人 已被 @keshav-space 認領 在 GitHub 檢視
9-next data-quality
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

[VCID-67rm-w5m7-aaar](https://public.vulnerablecode.io/vulnerabilities/VCID-67rm-w5m7-aaar) contains unrelated redhat packages in `affected packages`

```
pkg:rpm/redhat/python27-babel@0.9.6-10?arch=el7
pkg:rpm/redhat/python27-python@2.7.18-3?arch=el7
pkg:rpm/redhat/python27-python-jinja2@2.6-16?arch=el7
pkg:rpm/redhat/python27-python-pygments@1.5-5?arch=el7
pkg:rpm/redhat/rh-python38-babel@2.7.0-12?arch=el7
pkg:rpm/redhat/rh-python38-python@3.8.11-2?arch=el7
pkg:rpm/redhat/rh-python38-python-cryptography@2.8-5?arch=el7
pkg:rpm/redhat/rh-python38-python-lxml@4.4.1-7?arch=el7
pkg:rpm/redhat/rh-python38-python-pip@19.3.1-2?arch=el7
pkg:rpm/redhat/rh-python38-python-urllib3@1.25.7-7?arch=el7
```
[VCID-67rm-w5m7-aaar](https://public.vulnerablecode.io/vulnerabilities/VCID-67rm-w5m7-aaar) alias [CVE-2020-28493](https://nvd.nist.gov/vuln/detail/CVE-2020-28493) is essentially a security advisory for jinja2 and has nothing to do with cryptography or pip.

Upon further investigation it turn out that redhat advisory is clubbing bunch of unrelated CVEs in their [RHSA-2021:3252](https://access.redhat.com/errata/RHSA-2021:3252) advisory resulting in this mess. And it's the same story for all RHSA advisories.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。