aboutcode-org / aboutcode-org/vulnerablecode

Behaviour of 'arch' param in debian package request

未关闭
#582 5 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
data-quality feature Priority: medium
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

Hello,

This is more a question than a bug.
The api/docs of VulnerableCode gives the following quest example:
`pkg:deb/debian/curl@7.50.3-1?arch=i386&distro=jessie`

I try to play with the `arch` param.
If I query `pkg:deb/debian/apt@2.2.4?distro=bullseye` to VulnerableCode I receive:
```

{
"url": "http://localhost:9999/api/packages/613937",
"unresolved_vulnerabilities": [
{
"url": "http://localhost:9999/api/vulnerabilities/7783",
"vulnerability_id": "CVE-2011-3374",
"references": [
{
"reference_id": "CVE-2011-3374",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-3374",
"scores": [
[...]
```

And if I look on https://security-tracker.debian.org/tracker/CVE-2011-3374 I see that `all versions` are vulnerable.

Then when I query
`pkg:deb/debian/apt@2.2.4?distro=bullseye&arch=amd64`
why do I get no vulnerabilities ?

```
[
{
"type": "deb",
"namespace": "debian",
"name": "apt",
"version": "2.2.4",
"qualifiers": {
"arch": "amd64",
"distro": "bullseye"
},
"subpath": null,
"unresolved_vulnerabilities": [],
"resolved_vulnerabilities": [],
"purl": "pkg:deb/debian/apt@2.2.4?distro=bullseye&arch=amd64"
}
]
```

Shouldn't the same vulnerability be returned since it affects all versions ?

Version of VulnerableCode used: https://github.com/nexB/vulnerablecode/commit/4677f70c654a15da529a80d19d7de1ca013ef8eb

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。