CVE id present in three repository advisories, missing from two of the global ones
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
Hướng nghiên cứu
Bắt đầu với GET /advisories?cve_id=CVE-2025-9467 và so sánh ba repository advisory với các global record đã được promote tương ứng, tập trung vào cve_id và aliases. Truy vết hành vi promotion nếu entry point của nó khả dụng, sau đó xác định liệu các CVE dùng chung có nên tiếp tục tồn tại trên mọi global advisory hay không; hoàn tất nghĩa là có một quyết định được ghi lại và các identifier đã được sửa hoặc được chủ ý giữ nguyên.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Three repository advisories were published for CVE-2025-9467, one per affected repository. That split is ours, and each of the three repository advisories carries the CVE id. Two of the global advisories promoted from them do not.
| Repository advisory | cve_id there |
Global advisory | cve_id there |
Package |
|---|---|---|---|---|
| vaadin/framework | CVE-2025-9467 | GHSA-9gfh-4fwj-w3rj | CVE-2025-9467 | com.vaadin:vaadin-server |
| vaadin/platform | CVE-2025-9467 | GHSA-c7v7-rqfm-f44j | none | com.vaadin:vaadin |
| vaadin/flow-components | CVE-2025-9467 | GHSA-94g8-xv23-7656 | none | com.vaadin:vaadin-upload-flow |
All three were published on 2025-09-04 and reviewed the same day. aliases is empty on the last two, and the CVE survives only as a reference link, where no tool can use it.
The effect: GET /advisories?cve_id=CVE-2025-9467 returns one advisory, covering Vaadin 7 and 8. The Vaadin 14, 23 and 24 lines, which are the supported ones, are invisible to anyone asking by CVE. Every coordinate scanner joins on aliases, so they report those two under a GHSA id that leads back to no CVE.
Nothing disagrees on the data. The three together state exactly what the CVE record states, boundary for boundary.
The question. Is dropping the CVE on promotion intended when several advisories share one CVE? I can see the reasoning: across 5853 Maven advisories carrying a cve_id, no CVE maps to more than one, so keeping it on all three would be a first.
If it is intended, then the fix is on our side and I would rather know it: we would consolidate into a single repository advisory covering all three packages, and ask for the other two to be withdrawn as duplicates, the way GHSA-6qm2-mcq7-53qp is handled. Tell me that is the answer and I will do it.
If it is not intended, the two global records are losing an identifier their source advisories carry.
Not unique to this one: 147 Maven advisories have no cve_id, and 77 of those reference a CVE in their links.
(I opened #9515 earlier proposing to merge the ranges into one advisory and closed it myself after an automated review pointed out the siblings already carry them. They do, but where a CVE query cannot reach.)
- Ngôn ngữ chính
- Không có dữ liệu ngôn ngữ
- Star
- 2.5k
- Fork
- 772
- Merge trung bình
- 3 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 46
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github/advisory-database
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
github/advisory-database#9255 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
github/advisory-database#9164 · 1 reaction ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
github/advisory-database#8994 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
github/advisory-database#8898 · 4 bình luận · 1 reaction ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
github/advisory-database#8841 ·
Tất cả issue của github/advisory-database
Issue tương tự
-
[Documentation Request] vLLM kv_load_failure_policy doesn't apply to load failures in L2 adapters Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
-
DATABASE_URL=pglite:memory: creates a directory named 'memory:' instead of an in-memory database Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
BuilderIO/agent-native#5730 · 1 bình luận ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
duckdb/duckdb-wasm#2258 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
supabase/agent-skills#602 ·