DefectDojo / django-DefectDojo

DevSecOps, ASPM, Vulnerability Management. All on one platform.
https://defectdojo.com
BSD 3-Clause "New" or "Revised" License
3.68k stars 1.55k forks source link

BlackDuck API report import issue. #11029

Open barucijah opened 2 weeks ago

barucijah commented 2 weeks ago

Slack us first! I was writing in the Slack channel but no response. https://owasp.slack.com/archives/C2P5BA8MN/p1727869238459629

Be informative Please enter as much information as possible, otherwise we can't provide support. If possible upgrade to the latest release or dev version and try again. I am using latest version of the DefectDojo

Bug description Recently, we faced an issue with importing a report from Blackduck via the BlackDuckAPI config. I am unable to import this report, and I get the error' An exception error occurred during the report import: 'vulnerabilityWithRemediation'. I have noticed that after upgrading the BlackDuck instance to the version v2024.7.0 we started getting this error. Before everything was working. Also, I am using latest version of the defectdojo

Steps to reproduce Steps to reproduce the behavior:

  1. re-upload report for the test with BlackDuckAPI

Expected behavior I expect that the import will finish successfully.

Deployment method (select with an X)

Environment information

Screenshots Screenshot 2024-10-09 at 15 47 44

Additional context (optional) Add any other context about the problem here.

mtesauro commented 2 weeks ago

@barucijah Unfortunately with the API integrations, there's not much the project can do to assist with this as we don't have a license or install of Blackduck which we can test this error.

Have you tried the 3 different Blackduck file parsers we have - see https://documentation.defectdojo.com/integrations/parsers/file/

Perhaps one of those will work for you.

Without access to the API, I'm not sure how we reproduce this issue to be able to figure out a fix. :frowning_face: