cisagov / log4j-affected-db

A community sourced list of log4j-affected software
Creative Commons Zero v1.0 Universal
1.12k stars 281 forks source link

Update cisagov_N.yml #435

Closed kyle-ni closed 2 years ago

kyle-ni commented 2 years ago

๐Ÿ—ฃ Description

๐Ÿ’ญ Motivation and context

๐Ÿงช Testing

โœ… Pre-approval checklist

โœ… Pre-merge checklist

โœ… Post-merge checklist

kyle-ni commented 2 years ago

@Lcerkov - Makes sense. I missed how 'Status' was computed and the fact that it is an 'OR' of the individual CVEs. Was attempting to communicate that we have investigated against all of the CVEs, but only vulnerable to one.

Lcerkov commented 2 years ago

@kyle-ni Ahh, is it only vulnerable to CVE-2021-44228? If so, I will make that change and then merge the PR.

kyle-ni commented 2 years ago

@Lcerkov Yes, that is correct. Technically only CVE-2021-44228 applies for our products.

Lcerkov commented 2 years ago

@kyle-ni Thanks for the clarification- I fixed that and merged the update!