aboutcode-org / aboutcode-org/vulnerablecode

Investigate data issue with withdrawn advisories and CVSS scores

未关闭
#1,181 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

This https://public.vulnerablecode.io/vulnerabilities/VCID-yqzv-rncc-aaak?search=CVE-2022-40151
has these origins:
- https://github.com/advisories/GHSA-3mq5-fq9h-gj7j which is marked as withdrawn and has a CVSS V31 QR score
- https://github.com/advisories/GHSA-f8cc-g7j8-xxpm which replaces the above and has a CVSS V31 QR score
- https://github.com/x-stream/xstream/security/advisories/GHSA-f8cc-g7j8-xxpm which is upstream from above and seems to match here and has a CVSS V31 QR score
- https://nvd.nist.gov/vuln/detail/CVE-2022-40151 which is the NVD record and has two CVSS v3 scores. It does not have the github references
- the ultimate upstream is https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47367 and https://github.com/x-stream/xstream/issues/304

We have these issues as of filing:
- we are missing CVSS scores from the NVD
- we are reporting this https://github.com/FasterXML/woodstox/issues/160 and https://nvd.nist.gov/vuln/detail/CVE-2022-40152 packages are related to CVE-2022-40151 ... not sure this is correct as these are closely related and the NVD marks CPEs from both as related here https://nvd.nist.gov/vuln/detail/CVE-2022-40152
- we are reporting GMS-2022-9109 as an alias but without a link to its upstream which is https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/blob/master/maven/com.thoughtworks.xstream/xstream/GMS-2022-9109.yml Also this is related to https://github.com/advisories/GHSA-3f7h-mf4q-vrm4

This needs careful review on the data side.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。