Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Data quality issue with GHSA-4943-9vgg-gr5r #2463

Closed
italvi opened this issue Aug 8, 2024 · 2 comments
Closed

Data quality issue with GHSA-4943-9vgg-gr5r #2463

italvi opened this issue Aug 8, 2024 · 2 comments
Labels
data quality Issues with data quality

Comments

@italvi
Copy link

italvi commented Aug 8, 2024

The CVE ID
https://osv.dev/vulnerability/GHSA-4943-9vgg-gr5r

Describe the data quality issue observed
According to the CVE description the CVE is disputed, which is also shown by the tag "disputed" at MITRTE and therefore should have the "withdrawn"-field. At least you commented that the tag "disputed" at MITRE means "withdrawn" in osv.

Suggested changes to record
Add "withdrawn" to the entry.

@italvi italvi added the data quality Issues with data quality label Aug 8, 2024
Copy link

github-actions bot commented Aug 8, 2024

✨ Thank you for your interest in OSV.dev's data quality! ✨

Please review our FAQ entry on how to most efficiently have this addressed.

@andrewpollock
Copy link
Contributor

Please note that in OSV.dev, GHSA-4943-9vgg-gr5r and CVE-2021-3163 are different vulnerability records. In this particular instance, the former exists (and specifies the latter as an alias, and the latter does not exist).

GHSA-4943-9vgg-gr5r originates from the GitHub Advisory Database, and I am unsure of their treatment of records for disputed CVEs, but given I believe they human-review all advisories imported from the NVD, I would assume this is working as intended. GHSA-4943-9vgg-gr5r is the appropriate place to take this feedback.

@andrewpollock andrewpollock changed the title Data quality issue with CVE-2021-3163 Data quality issue with GHSA-4943-9vgg-gr5r Aug 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
data quality Issues with data quality
Projects
None yet
Development

No branches or pull requests

2 participants