aboutcode-org / aboutcode-org/vulnerablecode
Behaviour of 'arch' param in debian package request
- Linguagem predominante
- Python
- Estrelas
- 702
- Forks
- 328
- Merge médio
- 3d 8h
- PRs com merge (30d)
- 3
Descrição
Hello,
This is more a question than a bug.
The api/docs of VulnerableCode gives the following quest example:
`pkg:deb/debian/curl@7.50.3-1?arch=i386&distro=jessie`
I try to play with the `arch` param.
If I query `pkg:deb/debian/apt@2.2.4?distro=bullseye` to VulnerableCode I receive:
```
{
"url": "http://localhost:9999/api/packages/613937",
"unresolved_vulnerabilities": [
{
"url": "http://localhost:9999/api/vulnerabilities/7783",
"vulnerability_id": "CVE-2011-3374",
"references": [
{
"reference_id": "CVE-2011-3374",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-3374",
"scores": [
[...]
```
And if I look on https://security-tracker.debian.org/tracker/CVE-2011-3374 I see that `all versions` are vulnerable.
Then when I query
`pkg:deb/debian/apt@2.2.4?distro=bullseye&arch=amd64`
why do I get no vulnerabilities ?
```
[
{
"type": "deb",
"namespace": "debian",
"name": "apt",
"version": "2.2.4",
"qualifiers": {
"arch": "amd64",
"distro": "bullseye"
},
"subpath": null,
"unresolved_vulnerabilities": [],
"resolved_vulnerabilities": [],
"purl": "pkg:deb/debian/apt@2.2.4?distro=bullseye&arch=amd64"
}
]
```
Shouldn't the same vulnerability be returned since it affects all versions ?
Version of VulnerableCode used: https://github.com/nexB/vulnerablecode/commit/4677f70c654a15da529a80d19d7de1ca013ef8eb
Guia de contribuição
Nenhum guia de contribuição indexado para este repositório
Avaliação
Esta issue ainda não foi avaliada.