Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

CVE id present in three repository advisories, missing from two of the global ones

Đang mở
#9,582 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
35/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
java
Lĩnh vực
databases, security

Hướng nghiên cứu

Bắt đầu với GET /advisories?cve_id=CVE-2025-9467 và so sánh ba repository advisory với các global record đã được promote tương ứng, tập trung vào cve_id và aliases. Truy vết hành vi promotion nếu entry point của nó khả dụng, sau đó xác định liệu các CVE dùng chung có nên tiếp tục tồn tại trên mọi global advisory hay không; hoàn tất nghĩa là có một quyết định được ghi lại và các identifier đã được sửa hoặc được chủ ý giữ nguyên.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Three repository advisories were published for CVE-2025-9467, one per affected repository. That split is ours, and each of the three repository advisories carries the CVE id. Two of the global advisories promoted from them do not.

Repository advisory cve_id there Global advisory cve_id there Package
vaadin/framework CVE-2025-9467 GHSA-9gfh-4fwj-w3rj CVE-2025-9467 com.vaadin:vaadin-server
vaadin/platform CVE-2025-9467 GHSA-c7v7-rqfm-f44j none com.vaadin:vaadin
vaadin/flow-components CVE-2025-9467 GHSA-94g8-xv23-7656 none com.vaadin:vaadin-upload-flow

All three were published on 2025-09-04 and reviewed the same day. aliases is empty on the last two, and the CVE survives only as a reference link, where no tool can use it.

The effect: GET /advisories?cve_id=CVE-2025-9467 returns one advisory, covering Vaadin 7 and 8. The Vaadin 14, 23 and 24 lines, which are the supported ones, are invisible to anyone asking by CVE. Every coordinate scanner joins on aliases, so they report those two under a GHSA id that leads back to no CVE.

Nothing disagrees on the data. The three together state exactly what the CVE record states, boundary for boundary.

The question. Is dropping the CVE on promotion intended when several advisories share one CVE? I can see the reasoning: across 5853 Maven advisories carrying a cve_id, no CVE maps to more than one, so keeping it on all three would be a first.

If it is intended, then the fix is on our side and I would rather know it: we would consolidate into a single repository advisory covering all three packages, and ask for the other two to be withdrawn as duplicates, the way GHSA-6qm2-mcq7-53qp is handled. Tell me that is the answer and I will do it.

If it is not intended, the two global records are losing an identifier their source advisories carry.

Not unique to this one: 147 Maven advisories have no cve_id, and 77 of those reference a CVE in their links.

(I opened #9515 earlier proposing to merge the ranges into one advisory and closed it myself after an automated review pointed out the siblings already carry them. They do, but where a CVE query cannot reach.)

Ngôn ngữ chính
Không có dữ liệu ngôn ngữ
Star
2.5k
Fork
772
Merge trung bình
3 ngày 15 giờ
Pull request đã merge (30 ngày)
46

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của github/advisory-database

Tất cả issue của github/advisory-database

Issue tương tự

Thêm issue về Databases

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.