aboutcode-org / aboutcode-org/vulnerablecode

Investigate data issue with withdrawn advisories and CVSS scores

Open
#1,181 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

This https://public.vulnerablecode.io/vulnerabilities/VCID-yqzv-rncc-aaak?search=CVE-2022-40151
has these origins:
- https://github.com/advisories/GHSA-3mq5-fq9h-gj7j which is marked as withdrawn and has a CVSS V31 QR score
- https://github.com/advisories/GHSA-f8cc-g7j8-xxpm which replaces the above and has a CVSS V31 QR score
- https://github.com/x-stream/xstream/security/advisories/GHSA-f8cc-g7j8-xxpm which is upstream from above and seems to match here and has a CVSS V31 QR score
- https://nvd.nist.gov/vuln/detail/CVE-2022-40151 which is the NVD record and has two CVSS v3 scores. It does not have the github references
- the ultimate upstream is https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47367 and https://github.com/x-stream/xstream/issues/304

We have these issues as of filing:
- we are missing CVSS scores from the NVD
- we are reporting this https://github.com/FasterXML/woodstox/issues/160 and https://nvd.nist.gov/vuln/detail/CVE-2022-40152 packages are related to CVE-2022-40151 ... not sure this is correct as these are closely related and the NVD marks CPEs from both as related here https://nvd.nist.gov/vuln/detail/CVE-2022-40152
- we are reporting GMS-2022-9109 as an alias but without a link to its upstream which is https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/blob/master/maven/com.thoughtworks.xstream/xstream/GMS-2022-9109.yml Also this is related to https://github.com/advisories/GHSA-3f7h-mf4q-vrm4

This needs careful review on the data side.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.