cisagov / vulnrichment

A repo to conduct vulnerability enrichment.
Creative Commons Zero v1.0 Universal
462 stars 35 forks source link

Missing CVE: CVE-2024-33602 #9

Closed bardenstein closed 4 months ago

bardenstein commented 4 months ago

🐛 Summary

What's wrong? Please be specific. I didn't see a json file for https://nvd.nist.gov/vuln/detail/CVE-2024-33602.

To reproduce

Steps to reproduce the behavior:

  1. Github for this project > 2024 > 33xxxx

Expected behavior

What did you expect to happen that didn't? No entry called CVE-2024-33602.

Any helpful log output or screenshots

Paste the results here:

Add any screenshots of the problem here.

jwoytek-cisa commented 4 months ago

@bardenstein thank you for your report! This entry had been analyzed but not pushed out on our side yet. It will be in the update that gets posted today.

jwoytek-cisa commented 4 months ago

File is now in the repository!

fwininger commented 4 months ago

@jwoytek-cisa this issue is more generic.

I have lot to CVE that are published since 2 month and not in your data.

Exemple : CVE-2024-2886 : https://www.cve.org/CVERecord?id=CVE-2024-2886 / https://nvd.nist.gov/vuln/detail/CVE-2024-2886

todb-cisa commented 4 months ago

Hi @fwininger -- is the issue that the entire unscored corpus isn't published yet? This should be expected -- it'll be a few weeks before we catch up with the entire set of CVEs from February through today. Or, am I misunderstanding the question?

Oh, I see that 2887 has been vulnriched, but 2886 has not. Is the question, why one and not the other? If that's the case, we can certainly look into it. Thanks, and any clarification would be appreciated!

fwininger commented 4 months ago

Alright. I understand that we have to wait a little longer to have more complete data.

todb-cisa commented 4 months ago

We're vulnriching as fast as we can! :)