Add Spring Security Advisories as data source for GHSA database
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Accessibilité débutants
- 25/100
Piste de recherche
L’issue n’identifie aucun fichier, test ni point d’entrée d’implémentation. Commencez par examiner comment la base de données GHSA ingère actuellement les données de NVD, puis comparez les informations de Spring Security Advisories concernant CVE-2024-38809 ; la tâche serait considérée comme terminée lorsqu’une approche d’importation convenue et une couverture fiable des avis seront disponibles sans attendre la publication par NVD.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Hi there!
We have noticed that some CVEs affecting Spring libraries are not reported by Dependabot. This is caused by the fact that some CVEs are taking a long time to be included in the National Vulnerabilities Database(NVD) with a full description and CVSS score. As far as I know, the NVD is currently the only data source used by the GHSA database which will contain Java- and Spring-related vulnerabilities.
One example which was not reported by Dependabot: CVE-2024-38809. This CVE affects org.springframework:spring-web in most versions prior to 6.1.12.
This CVE is reported as reserved in the MITRE CVE database, but its details have not been published yet. It is not published in the NVD too, which leads to Dependabot failing to recognize it when scanning our Spring repositories.
Thanks to the wonderful Github Enterprise support, this CVE has now received an entry in the GHSA database, while it is still not included in the NVD: Link to GHSA
To avoid such situations in the future, I'd suggest to use Spring Security Advisories as an additional data source for the GHSA database. The CVE mentioned above has been published there for over a month before it was added to the GHSA database: Spring Security Advisory for CVE-2024-38809
Me and my colleagues think this would be a valuable addition to the GHSA database. Spring is widely used and many organizations use Dependabot to scan their Spring projects. What do the maintainers of the GHSA database think about our suggestion?
- Langage dominant
- Aucune donnée de langage
- Étoiles
- 2.5k
- Forks
- 772
- Merge moyen
- 4 j 17 h
- PR mergées (30 j)
- 75
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de github/advisory-database
-
Difficulté 2/5 1-3 heures Accessibilité débutants 68/100
github/advisory-database#9255 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
github/advisory-database#9164 · 1 réaction ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
github/advisory-database#8994 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 68/100
github/advisory-database#8898 · 4 commentaires · 1 réaction ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
github/advisory-database#8841 ·
Toutes les issues de github/advisory-database
Issues similaires
-
bug
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
hanami/hanami-cli#449 ·
-
external-issue to-triage
Difficulté 2/5 1-3 heures Accessibilité débutants 88/100
-
SqliteSaver.list(filter=...) silently misses nested metadata values containing non-ASCII text Ouverteexternal
Difficulté 2/5 1-3 heures Accessibilité débutants 65/100
langchain-ai/langgraph#9074 · 1 commentaire ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 92/100
litestar-org/sqlspec#816 ·
-
JIT-compiled number -> Decimal conversion silently overflows instead of raising DECIMAL_OVERFLOW Ouvertefuzz
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
ClickHouse/ClickHouse#122114 ·