aboutcode-org / aboutcode-org/vulnerablecode
Some issues with data degradation between upstream, CVE and NVD, then Gihub, OSV and Gitlab
- Ngôn ngữ chính
- Python
- Star
- 702
- Fork
- 328
- Merge trung bình
- 3 ngày 8 giờ
- Pull request đã merge (30 ngày)
- 3
Mô tả
Some ASF projects are seeing their CVE records appearing mangled in GitHub Advisories, but this is only a symptom of a deeper problem and not specific to the ASF. Thanks for @ppkarwasz for the details
An example is `CVE-2026-50628` (disclosed on June 12th), which has a CVSS score of 9.8, and is only present in that PURL `pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2` and not in the whole CXF codebase.
Here are some background:
- at MITRE: https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/50xxx/CVE-2026-50628.json or https://www.cve.org/CVERecord?id=CVE-2026-50628 have Maven coordinates properly provided at least in the name
- at NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50628 or https://github.com/olbat/nvdcve/blob/master/nvdcve/CVE-2026-50628.json if the NVD is down. See rough history at https://github.com/fkie-cad/nvd-json-data-feeds/commits/main/CVE-2026/CVE-2026-506xx/CVE-2026-50628.json
- initial record mostly empty when pulled from MITRE https://github.com/fkie-cad/nvd-json-data-feeds/blob/bde8d216748790cf40fc461aa9e9351dd7c06e96/CVE-2026/CVE-2026-506xx/CVE-2026-50628.json
- on June 15th, update to add an incorrect CPE, too wide cpe:2.3:a:apache:cxf, a product with dozens of different artifacts, and not the actual package that is affected https://github.com/fkie-cad/nvd-json-data-feeds/blob/c8e589f587fe50f16712ebc10079e4fde00a1210/CVE-2026/CVE-2026-506xx/CVE-2026-50628.json#L49
- on June 17th, update to get more data from the CVE record with better data https://github.com/fkie-cad/nvd-json-data-feeds/blob/644f9fc5bd0a10688470dc004d55d76098d99f56/CVE-2026/CVE-2026-506xx/CVE-2026-50628.json but the CPE is still wrong.
- On top of that, RedHat later adds CPE-keyed, VEX-like statements of whether their larger products are affected or not https://github.com/fkie-cad/nvd-json-data-feeds/blob/2dd45b48e0efa0fde64742f95da829dc45ea506c/CVE-2026/CVE-2026-506xx/CVE-2026-50628.json
- at Github: https://github.com/advisories/ghsa-g5v7-jchf-7jrr is initially published with mostly nothing known, no title, no artifact, no affected ranges, and 2 months later still is the same https://github.com/github/advisory-database/blob/dbc1435941d42e394de655b8e344b1aab124a9a4/advisories/unreviewed/2026/06/GHSA-g5v7-jchf-7jrr/GHSA-g5v7-jchf-7jrr.json
Then OSV and GitLab
- Since this is "unreviewed" at Github, Gitlab ignores that advisory https://gitlab.com/search?search=CVE-2026-50628&nav_source=navbar&project_id=12006272&group_id=2452873&search_code=true&repository_ref=master
- The OSV pulls from GitHub and separately from Mitre that was backfilled with the same infor as NVD keeping the incorrect historical CPE published by the NVD https://osv.dev/vulnerability/CVE-2026-50628 and diluting the data further
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Đánh giá
Issue này chưa được đánh giá.