aboutcode-org / aboutcode-org/vulnerablecode

Apache HTTPD does NOT use Maven versioning

Ouverte
#579 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub
bug Data collection data-quality versioning
Langage dominant
Python
Étoiles
702
Forks
328
Merge moyen
3 j 8 h
PR mergées (30 j)
3

Description

The current code use the univers MavenVersion for httpd advisories. This is incorrect.
The semantics and range notation from httpd are NOT the Maven ones.
See https://httpd.apache.org/security/json/CVE-2000-1204.json for instance:
```JSON
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Apache Software Foundation",
"product": {
"product_data": [
{
"product_name": "Apache HTTP Server",
"version": {
"version_data": [
{
"version_name": "1.3",
"version_affected": "=",
"version_value": "1.3.12"
},
{
"version_name": "1.3",
"version_affected": "=",
"version_value": "1.3.11"
},
{
"version_name": "1.3",
"version_affected": "=",
"version_value": "1.3.9"
}
]
}
}
]
}
}
]
}

```

And per https://archive.apache.org/dist/httpd/ the version seem to be mostly semver with some pre-release extra but these is NOT maven.

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.