aboutcode-org / aboutcode-org/vulnerablecode

Suse scores importer should support version 4

オープン
#1,592 コメント 8 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

Given a sample Suse score https://ftp.suse.com/pub/projects/security/yaml/suse-cvss-scores.yaml:

```
CVE-2024-35255:
cvss:
- version: 3.1
score: 5.5
vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- version: 4
score: 6.8
vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
```

The version 4 cvss is not imported because the importer does not support version 4:
https://github.com/aboutcode-org/vulnerablecode/blob/ed17dbd5a7537b95faf9ef8d30a95333ffdcb3ca/vulnerabilities/importers/suse_scores.py#L34-L38

Additional questions:

Our VulnerableCode instance contains some weird values for this source:

![image](https://github.com/user-attachments/assets/d6a109ba-5c2c-49d9-a847-0b9c35a5169c)

1. Can the cvssv2 and cvssv3 be old values from previous imports ?
2. Why the cvsv3.1 has a score of 0 ?
3. We noticed the public instance does not list suse.com as a source. Should we disable this importer ?
https://public.vulnerablecode.io/vulnerabilities/VCID-p3vk-v2au-aaaa?search=CVE-2024-35255

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。