owasp-modsecurity / owasp-modsecurity/ModSecurity

No CPE for 3.0.11 and 3.0.12

Open
#3,083 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

2.x 3.x
Dominant language
C++
Stars
9.8k
Forks
1.8k
Avg merge
2h 46m
Merged PRs (30d)
1

Description

I am the package maintainer of ModSecurity in Buildroot. Buildroot has automated tracking of CVEs which it does by checking the CPE for the corresponding release. It seems that for both 3.0.11 and 3.0.12 no CPE was registered. The newest CPE I can find in the NIST database is cpe:2.3🅰️trustwave:modsecurity:3.0.10:::::::*
This has effectively broken the CVE reporting infrastructure for ModSecurity in Buildroot, causing us to miss CVE-2024-1019.

Will the creation of CPEs resume in the future for future versions or will this be deprecated?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No repository file, test, or entry point is identified. Start by verifying the NIST CPE records for ModSecurity 3.0.11 and 3.0.12 and checking how those releases are represented in the project’s release metadata. Done means the missing CPEs are registered or the project’s future CPE policy is documented clearly enough for Buildroot CVE tracking.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
release, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.