owasp-modsecurity / owasp-modsecurity/ModSecurity
No CPE for 3.0.11 and 3.0.12
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 9.8k
- Forks
- 1.8k
- Avg merge
- 2h 46m
- Merged PRs (30d)
- 1
Description
I am the package maintainer of ModSecurity in Buildroot. Buildroot has automated tracking of CVEs which it does by checking the CPE for the corresponding release. It seems that for both 3.0.11 and 3.0.12 no CPE was registered. The newest CPE I can find in the NIST database is cpe:2.3🅰️trustwave:modsecurity:3.0.10:::::::*
This has effectively broken the CVE reporting infrastructure for ModSecurity in Buildroot, causing us to miss CVE-2024-1019.
Will the creation of CPEs resume in the future for future versions or will this be deprecated?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No repository file, test, or entry point is identified. Start by verifying the NIST CPE records for ModSecurity 3.0.11 and 3.0.12 and checking how those releases are represented in the project’s release metadata. Done means the missing CPEs are registered or the project’s future CPE policy is documented clearly enough for Buildroot CVE tracking.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- release, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100