anchore / anchore/syft

Set correct TargetSW for Node.js Redis CPE

Open
#412 4 comments 0 reactions 0 assignees View on GitHub
ecosystem:javascript
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
1d 5h
Merged PRs (30d)
42

Description

CPE should be: `cpe:2.3:a:redis.js:redis:*:*:*:*:*:node.js:*:*`

Vulnerability example for this CPE: https://nvd.nist.gov/vuln/detail/CVE-2021-29469

For more context (internal link): https://anchore.slack.com/archives/C1DMGFP3J/p1620774479360500

Contributor guide

Open the contributing guide

Research direction

Use the requested CPE and CVE-2021-29469 as the acceptance criteria. Trace where the Node.js Redis TargetSW value is produced, update it to `node.js`, and verify that the generated CPE matches `cpe:2.3:a:redis.js:redis:*:*:*:*:*:node.js:*:*`.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js, redis
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.