aboutcode-org / aboutcode-org/vulnerablecode

correlate CVEs to other CVEs based on "ref" element in CVE XML

Đang mở
#657 5 bình luận 1 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Python
Star
702
Fork
328
Merge trung bình
3 ngày 8 giờ
Pull request đã merge (30 ngày)
3

Mô tả

There are many CVEs that are identical or closely related, but which have been reported separately. It might be useful to extract this information. When looking at the CVE XML download: apart from references in the CVE `` there is also possibly useful information in the `` element. Many references, like URLs, are identical, meaning that the bugs are related.

If there are related CVEs it is usually a handful, although there is one extreme outlier with a reference that occurs 1390 times in today's CVE data.

A small proof of concept script of how this data could be extracted (but only processes identical URLs, which not all references have): https://github.com/armijnhemel/compliance-scripts/blob/cve_extract_paths/cve/cve_match_cves.py

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.