aboutcode-org / aboutcode-org/vulnerablecode

correlate CVEs to other CVEs based on "ref" element in CVE XML

未關閉
#657 5 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

There are many CVEs that are identical or closely related, but which have been reported separately. It might be useful to extract this information. When looking at the CVE XML download: apart from references in the CVE `` there is also possibly useful information in the `` element. Many references, like URLs, are identical, meaning that the bugs are related.

If there are related CVEs it is usually a handful, although there is one extreme outlier with a reference that occurs 1390 times in today's CVE data.

A small proof of concept script of how this data could be extracted (but only processes identical URLs, which not all references have): https://github.com/armijnhemel/compliance-scripts/blob/cve_extract_paths/cve/cve_match_cves.py

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。