aboutcode-org / aboutcode-org/vulnerablecode

Investigate data issue with withdrawn advisories and CVSS scores

Offen
#1,181 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Python
Sterne
702
Forks
328
Ø Merge
3 T. 8 Std.
Gemergte PRs (30 T.)
3

Beschreibung

This https://public.vulnerablecode.io/vulnerabilities/VCID-yqzv-rncc-aaak?search=CVE-2022-40151
has these origins:
- https://github.com/advisories/GHSA-3mq5-fq9h-gj7j which is marked as withdrawn and has a CVSS V31 QR score
- https://github.com/advisories/GHSA-f8cc-g7j8-xxpm which replaces the above and has a CVSS V31 QR score
- https://github.com/x-stream/xstream/security/advisories/GHSA-f8cc-g7j8-xxpm which is upstream from above and seems to match here and has a CVSS V31 QR score
- https://nvd.nist.gov/vuln/detail/CVE-2022-40151 which is the NVD record and has two CVSS v3 scores. It does not have the github references
- the ultimate upstream is https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47367 and https://github.com/x-stream/xstream/issues/304

We have these issues as of filing:
- we are missing CVSS scores from the NVD
- we are reporting this https://github.com/FasterXML/woodstox/issues/160 and https://nvd.nist.gov/vuln/detail/CVE-2022-40152 packages are related to CVE-2022-40151 ... not sure this is correct as these are closely related and the NVD marks CPEs from both as related here https://nvd.nist.gov/vuln/detail/CVE-2022-40152
- we are reporting GMS-2022-9109 as an alias but without a link to its upstream which is https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/blob/master/maven/com.thoughtworks.xstream/xstream/GMS-2022-9109.yml Also this is related to https://github.com/advisories/GHSA-3f7h-mf4q-vrm4

This needs careful review on the data side.

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.