Potential Data Discrepancy in CVE Listings
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 35/100
- Issue-Typ
- Bug
- Klarheit
- Muss geklärt werden
- Aktivitätsstatus
- Veraltet
- Bereich
- security
Rechercherichtung
Beginne mit der verknüpften README, die Artefakte, CVE-Namen und NVD-Links auflistet, und vergleiche diese Einträge anschließend mit den entsprechenden JSON-Dateien des Repositorys. Überprüfe, ob für jedes gemeldete Artefakt ein zugehöriges CVE in der NVD vorhanden ist, und bestimme, welche Datenbankkorrektur gegebenenfalls erforderlich ist.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
While conducting a deeper analysis of your repository to compare it with the NVD (National Vulnerability Database) in terms of usability and available information, with the goal of making life easier for security researchers, I discovered 2,249 artifacts that lacked CVE names. Upon focusing on these, I found that 99 of them were indeed listed in the NVD, which made it odd that the CVE identifiers were not explicitly present in the JSON files. I then examined the references and noticed that these artifacts contained links to the NVD, where their respective CVEs were listed.
I wanted to bring this potential discrepancy to your attention, as these artifacts do have associated CVEs, which are documented in the attached file along with their corresponding NVD links. This might indicate a possible issue in the database that could benefit from further review.
Here are the names of the files along with the names of the CVE's mentioned in them and their links to the nvd which is where I got the CVE's from:
https://github.com/leoambrus/artefactswithoutCVEonGitHubAdvisoryDatabase/blob/main/README.md
- Vorherrschende Sprache
- Keine Sprachdaten
- Sterne
- 2.5k
- Forks
- 803
- Ø Merge
- 6 T. 21 Std.
- Gemergte PRs (30 T.)
- 61
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus github/advisory-database
-
Update https://github.com/advisories/GHSA-5pf6-cq2v-23ww to include patched versionEvtl. vergeben @GreyforgeLabs hat das vor 9 Tagen übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
github/advisory-database#9879 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
github/advisory-database#9255 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
github/advisory-database#9164 · 1 Reaktion ·
Maintainer antworten meist innerhalb von 1 Tag
-
CVE-2026-5598 has incorrect fixed versions for bcprov-jdk packagesEvtl. vergeben @ECD5A hat das vor 52 Tagen übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
github/advisory-database#8994 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
github/advisory-database#8898 · 4 Kommentare · 1 Reaktion ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in github/advisory-database
Ähnliche Issues
-
area/frontend area/v2 kind/bug priority/needs-triage
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
kubeflow/notebooks#1498 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 66/100
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 62/100
splunk/security_content#4334 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Streamable HTTP client: a 401 or 403 with a JSON-RPC error body and no WWW-Authenticate loses its HTTP statusEvtl. vergeben Ein verknüpfter Pull Request ist offen oder bereits gemergt. Offenbug P2 ready for work T-security T-transport
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
modelcontextprotocol/rust-sdk#1339 ·
Maintainer antworten meist innerhalb von 3 Tagen
-
bug : find_key() compares kty against "ocy" instead of "oct", breaking kid-less HS256 verificationOffen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 77/100
OpenPrinting/cups#1756 ·
Maintainer antworten meist innerhalb von 1 Tag