aboutcode-org / vulnerablecode

A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
https://public.vulnerablecode.io
Apache License 2.0
543 stars 201 forks source link

Weird item with no history and various RedHat data bugs #1662

Open pombredanne opened 3 days ago

pombredanne commented 3 days ago

This entry is weird https://public.vulnerablecode.io/packages/pkg:rpm/redhat/application-ui@container-v2.3%3Farch=6-9?search=pkg:rpm/redhat/application-ui@container-v2.3?arch=6-9

In https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-3918.json I see:

{
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8",
    "release_date" : "2022-03-04T00:00:00Z",
    "advisory" : "RHSA-2022:0595",
    "cpe" : "cpe:/a:redhat:acm:2.3::el8",
    "package" : "rhacm2/application-ui-rhel8:v2.3.6-9",
    "impact" : "moderate"
  }

which is likely the thing did not parse correctly.

pombredanne commented 3 days ago

We should drop using OVAL which is problematic, and embrace their CSAF and OSV formats instead

And https://openssf.org/blog/2024/11/01/red-hats-collaboration-with-the-openssf-and-osv-dev-yields-results-red-hat-security-data-now-available-in-the-osv-format/

There are also SPDX SBOMs https://security.access.redhat.com/data/sbom/