boostsecurityio / poutine

boostsecurityio/poutine
Apache License 2.0
215 stars 21 forks source link

Fix CVE-2020-13283 matching #170

Closed fproulx-boostsecurity closed 2 months ago

fproulx-boostsecurity commented 2 months ago

The rule generated was too lax >=10.8

https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13283.json

I'll file a bug so that we update the CVE DB update to have fixups routines and/or use the Gitlab CVE assignement DB for Gitlab (https://gitlab.com/gitlab-org/cves/-/tree/master)