-
Notifications
You must be signed in to change notification settings - Fork 193
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Data quality issue with CVE-2021-42384 #2128
Labels
bug
Something isn't working
data quality
Issues with data quality
worker
Worker-related infrastructure
Comments
Confirmed that 1dd2685dcc735496d7adde87ac60b9434ed4a04c is tagged as 1.30.1:
Confirmed that querying for 1dd2685dcc735496d7adde87ac60b9434ed4a04c only returns CVE-2023-39810 and not CVE-2021-42384:
|
Version enumeration does not appear to be identifying 1.30.1 or the 1_30_1 tag, by the looks of it, so it stands to reason it's also not enumerating the related commits (note the lack of this in the `versions` array):
|
My current conclusion is that this is an issue in the version enumeration/repository analysis code and not the CVE conversion itself. |
andrewpollock
added
worker
Worker-related infrastructure
bug
Something isn't working
labels
Jun 20, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
bug
Something isn't working
data quality
Issues with data quality
worker
Worker-related infrastructure
The CVE ID
CVE-2021-42384
Describe the data quality issue observed
When I searched this CVE ID from osv.dev, I got different result with NVD when echo system is GIT.
Result of osv.dev
The affected version shows as below image
Result of NVD
The affected version shows as below image
The "From" (1_18_0) and and "Up to" (1_33_1) version are both the same between osv.dev and NVD.
However, osv.dev does not link this CVE to all tag version .
For example, I use the busybox v1.30.1, the tag ID is 1_30_1 , and the GIT commit hash is as following
1dd2685dcc735496d7adde87ac60b9434ed4a04c
As you can see, CVE-2021-42384 can not be found on osv.dev and osv-scanner tool with this version.
Suggested changes to record
Link CVE to all tag version between from and Up .
Hope my description is clear :)
Thank you very much.
The text was updated successfully, but these errors were encountered: