aboutcode-org / aboutcode-org/vulnerablecode

Apache HTTPD does NOT use Maven versioning

Open
#579 1 comment 0 reactions 0 assignees View on GitHub
bug Data collection data-quality versioning
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

The current code use the univers MavenVersion for httpd advisories. This is incorrect.
The semantics and range notation from httpd are NOT the Maven ones.
See https://httpd.apache.org/security/json/CVE-2000-1204.json for instance:
```JSON
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Apache Software Foundation",
"product": {
"product_data": [
{
"product_name": "Apache HTTP Server",
"version": {
"version_data": [
{
"version_name": "1.3",
"version_affected": "=",
"version_value": "1.3.12"
},
{
"version_name": "1.3",
"version_affected": "=",
"version_value": "1.3.11"
},
{
"version_name": "1.3",
"version_affected": "=",
"version_value": "1.3.9"
}
]
}
}
]
}
}
]
}

```

And per https://archive.apache.org/dist/httpd/ the version seem to be mostly semver with some pre-release extra but these is NOT maven.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.