aboutcode-org / aboutcode-org/vulnerablecode
Investigate data issue with withdrawn advisories and CVSS scores
- 主要语言
- Python
- 星标
- 702
- 派生
- 328
- 平均合并
- 3 天 8 小时
- 30 天内合并 PR
- 3
描述
This https://public.vulnerablecode.io/vulnerabilities/VCID-yqzv-rncc-aaak?search=CVE-2022-40151
has these origins:
- https://github.com/advisories/GHSA-3mq5-fq9h-gj7j which is marked as withdrawn and has a CVSS V31 QR score
- https://github.com/advisories/GHSA-f8cc-g7j8-xxpm which replaces the above and has a CVSS V31 QR score
- https://github.com/x-stream/xstream/security/advisories/GHSA-f8cc-g7j8-xxpm which is upstream from above and seems to match here and has a CVSS V31 QR score
- https://nvd.nist.gov/vuln/detail/CVE-2022-40151 which is the NVD record and has two CVSS v3 scores. It does not have the github references
- the ultimate upstream is https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47367 and https://github.com/x-stream/xstream/issues/304
We have these issues as of filing:
- we are missing CVSS scores from the NVD
- we are reporting this https://github.com/FasterXML/woodstox/issues/160 and https://nvd.nist.gov/vuln/detail/CVE-2022-40152 packages are related to CVE-2022-40151 ... not sure this is correct as these are closely related and the NVD marks CPEs from both as related here https://nvd.nist.gov/vuln/detail/CVE-2022-40152
- we are reporting GMS-2022-9109 as an alias but without a link to its upstream which is https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/blob/master/maven/com.thoughtworks.xstream/xstream/GMS-2022-9109.yml Also this is related to https://github.com/advisories/GHSA-3f7h-mf4q-vrm4
This needs careful review on the data side.
贡献指南
这个仓库没有索引到贡献指南
评估
这个 Issue 还没有评估数据。