Potential Data Discrepancy in CVE Listings
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Accessibilité débutants
- 35/100
- Type d'issue
- Bug
- Clarté
- À clarifier
- Activité
- À l'abandon
- Domaine
- security
Piste de recherche
Commencez par le README lié, qui répertorie les artefacts, les noms de CVE et les liens NVD, puis comparez ces entrées avec les fichiers JSON correspondants du dépôt. Vérifiez si chaque artefact signalé possède un CVE associé dans la NVD et déterminez quelle correction de la base de données, le cas échéant, est nécessaire.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
While conducting a deeper analysis of your repository to compare it with the NVD (National Vulnerability Database) in terms of usability and available information, with the goal of making life easier for security researchers, I discovered 2,249 artifacts that lacked CVE names. Upon focusing on these, I found that 99 of them were indeed listed in the NVD, which made it odd that the CVE identifiers were not explicitly present in the JSON files. I then examined the references and noticed that these artifacts contained links to the NVD, where their respective CVEs were listed.
I wanted to bring this potential discrepancy to your attention, as these artifacts do have associated CVEs, which are documented in the attached file along with their corresponding NVD links. This might indicate a possible issue in the database that could benefit from further review.
Here are the names of the files along with the names of the CVE's mentioned in them and their links to the nvd which is where I got the CVE's from:
https://github.com/leoambrus/artefactswithoutCVEonGitHubAdvisoryDatabase/blob/main/README.md
- Langage dominant
- Aucune donnée de langage
- Étoiles
- 2.5k
- Forks
- 772
- Merge moyen
- 4 j 17 h
- PR mergées (30 j)
- 75
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de github/advisory-database
-
Difficulté 2/5 1-3 heures Accessibilité débutants 68/100
github/advisory-database#9255 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
github/advisory-database#9164 · 1 réaction ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
github/advisory-database#8994 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 68/100
github/advisory-database#8898 · 4 commentaires · 1 réaction ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
github/advisory-database#8841 ·
Toutes les issues de github/advisory-database
Issues similaires
-
priority:P0 ready-for-human
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
AgoraIO-Extensions/agent-infra#847 · 1 commentaire ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
-
Difficulté 2/5 1-3 heures Accessibilité débutants 88/100
LuckyPennySoftware/AutoMapper#4660 ·
-
[Bug]: Console does not validate "Confirm new password" when a user changes their own password Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
-
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100