-
Notifications
You must be signed in to change notification settings - Fork 3
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
CVE-2020-35728 - mapping to purls more than NVD described #112
Comments
The trouble with this one is that GHSA lists a non-existing Maven coordinate: The proper coordinate is |
The story is complicated, but it seems that things are working as intended for the most part. Because GHSA names an incorrect Maven coordinate, we fall back to previous known purl mapping of the CPE At that stage however, the version range of GHSA is also not used anymore to identify the vulnerable versions. Instead, the code checks here for all versions of the Maven package: https://repo1.maven.org/maven2/com/fasterxml/jackson/core/jackson-databind/ Checking back at Maven https://repo1.maven.org/maven2/com/fasterxml/jackson/core/jackson-databind/ results in the list of versions listed above by @cg122, so that is working as intended. I wonder why the version range is set differently in both the NVD and the GHSA data. Perhaps it's related to responsible disclosure? There is one bug here, and that is the |
As described in NVD:
The current mapping includes later versions:
The text was updated successfully, but these errors were encountered: