Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Potential Data Discrepancy in CVE Listings

Offen
#4,860 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
35/100
Issue-Typ
Bug
Klarheit
Muss geklärt werden
Aktivitätsstatus
Veraltet
Bereich
security

Rechercherichtung

Beginne mit der verknüpften README, die Artefakte, CVE-Namen und NVD-Links auflistet, und vergleiche diese Einträge anschließend mit den entsprechenden JSON-Dateien des Repositorys. Überprüfe, ob für jedes gemeldete Artefakt ein zugehöriges CVE in der NVD vorhanden ist, und bestimme, welche Datenbankkorrektur gegebenenfalls erforderlich ist.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

While conducting a deeper analysis of your repository to compare it with the NVD (National Vulnerability Database) in terms of usability and available information, with the goal of making life easier for security researchers, I discovered 2,249 artifacts that lacked CVE names. Upon focusing on these, I found that 99 of them were indeed listed in the NVD, which made it odd that the CVE identifiers were not explicitly present in the JSON files. I then examined the references and noticed that these artifacts contained links to the NVD, where their respective CVEs were listed.

I wanted to bring this potential discrepancy to your attention, as these artifacts do have associated CVEs, which are documented in the attached file along with their corresponding NVD links. This might indicate a possible issue in the database that could benefit from further review.

Here are the names of the files along with the names of the CVE's mentioned in them and their links to the nvd which is where I got the CVE's from:
https://github.com/leoambrus/artefactswithoutCVEonGitHubAdvisoryDatabase/blob/main/README.md

Vorherrschende Sprache
Keine Sprachdaten
Sterne
2.5k
Forks
803
Ø Merge
6 T. 21 Std.
Gemergte PRs (30 T.)
61

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus github/advisory-database

Alle Issues in github/advisory-database

Ähnliche Issues

Weitere Issues zu Security

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.