aboutcode-org / aboutcode-org/vulnerablecode
Investigate data issue with withdrawn advisories and CVSS scores
- Ngôn ngữ chính
- Python
- Star
- 702
- Fork
- 328
- Merge trung bình
- 3 ngày 8 giờ
- Pull request đã merge (30 ngày)
- 3
Mô tả
This https://public.vulnerablecode.io/vulnerabilities/VCID-yqzv-rncc-aaak?search=CVE-2022-40151
has these origins:
- https://github.com/advisories/GHSA-3mq5-fq9h-gj7j which is marked as withdrawn and has a CVSS V31 QR score
- https://github.com/advisories/GHSA-f8cc-g7j8-xxpm which replaces the above and has a CVSS V31 QR score
- https://github.com/x-stream/xstream/security/advisories/GHSA-f8cc-g7j8-xxpm which is upstream from above and seems to match here and has a CVSS V31 QR score
- https://nvd.nist.gov/vuln/detail/CVE-2022-40151 which is the NVD record and has two CVSS v3 scores. It does not have the github references
- the ultimate upstream is https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47367 and https://github.com/x-stream/xstream/issues/304
We have these issues as of filing:
- we are missing CVSS scores from the NVD
- we are reporting this https://github.com/FasterXML/woodstox/issues/160 and https://nvd.nist.gov/vuln/detail/CVE-2022-40152 packages are related to CVE-2022-40151 ... not sure this is correct as these are closely related and the NVD marks CPEs from both as related here https://nvd.nist.gov/vuln/detail/CVE-2022-40152
- we are reporting GMS-2022-9109 as an alias but without a link to its upstream which is https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/blob/master/maven/com.thoughtworks.xstream/xstream/GMS-2022-9109.yml Also this is related to https://github.com/advisories/GHSA-3f7h-mf4q-vrm4
This needs careful review on the data side.
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Đánh giá
Issue này chưa được đánh giá.