Update NIST CPE Dictionary
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Domain
- security
Research direction
Start with the issue's NIST CPE Dictionary links and the proposed CPE identifiers for LoopBack and related packages. Determine which entries should be revoked, replaced, or added, then confirm the final naming with NIST; done means the agreed CPE records are registered and the repository's security guidance reflects them.
Written by the indexing model from the issue text.
Description
CPE (Common Platform Enumeration) is a standard syntax for describing software (e.g. vendor, software type, software name, version).
The NIST CPE Dictionary is a central database of registered CPEs. Vendors can register their CPEs with NIST to be added to the database.
Currently, LoopBack only has 1 CPE entry, cpe:2.3:a:ibm:loopback:8.0.0:*:*:*:*:*:*:*.
Here is a 3-part proposal:
- IBM is no longer the vendor for LoopBack
To solve this, we can revoke the current CPE and replace it with the following:
cpe:2.3:a:loopback:\@loopback\/rest:8.0.0:*:*:*:*:*:*:*
Note that the CPE above is not registered and may change once we contact NIST. The backslash is used to "quote" printable, non-alphanmuric characters in accordance with the CPE 2.3 specification. - Other vulnerable LoopBack packages with a published CVE do not have an associated CPE.
LB2/3 is quite different from LB4. Hence one proposal is to utilise the DefinitelyTyped syntax by:
a. Replacing the above CPE with double underscore
b. Use hyphen as per-normal for LB2/3 packages (e.g.loopback-boot)
This allows us to exploit the existing distinctive property separating LB2/3 and LB4, that LB2/3 packages are unscoped while LB4 packages are scoped. - For "non-LoopBack" packages such as
strong-soap, keep theloopbackvendor and use the package name as per-normal, similar to 2.a.
- Dominant language
- TypeScript
- Stars
- 4
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from loopbackio/security
-
Difficulty 4/5 3-5 days Newbie friendliness 45/100
loopbackio/security#42 ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
loopbackio/security#41 ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
loopbackio/security#40 ·
-
openjsf
Difficulty 5/5 Over a week Newbie friendliness 25/100
loopbackio/security#39 ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
loopbackio/security#38 ·
All issues in loopbackio/security
Similar issues
-
clawsweeper:linked-pr-open clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:message-loss issue-rating: 🦞 diamond lobster maturity:stable P2
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Eynzof/Hermes-CN-Desktop#616 ·
-
ZCode 3.14.3 に対応する Open
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
supermomonga/zcode-acp#24 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
growthbook/growthbook#7100 ·
-
triage
Difficulty 1/5 1-3 hours Newbie friendliness 88/100