Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cvefor returns vulnerabilities for incorrect version #449

Closed
jukkahell opened this issue Jul 30, 2020 · 4 comments
Closed

cvefor returns vulnerabilities for incorrect version #449

jukkahell opened this issue Jul 30, 2020 · 4 comments

Comments

@jukkahell
Copy link

jukkahell commented Jul 30, 2020

cve-search version 2.9
Call endpoint like this: /api/cvefor/cpe:2.3:a:xmlsoft:libxml2:2.9.1
It will give vulnerability cve-2019-20388 which is only valid for version 2.9.10

Could it be that I need to format the version somehow?

@P-T-I
Copy link
Member

P-T-I commented Aug 5, 2020

@jukkahell I'll see if I can reproduce your issue

@P-T-I
Copy link
Member

P-T-I commented Aug 5, 2020

@jukkahell I'm able to reproduce; investigating further

@P-T-I
Copy link
Member

P-T-I commented Aug 24, 2020

@jukkahell sorry haven't found the time yet to take a closer look at your issue; hopefully this week!

@P-T-I
Copy link
Member

P-T-I commented Aug 24, 2020

@jukkahell Submitted a PR #454 with a fix

@adulau adulau closed this as completed in 3a2dd74 Aug 24, 2020
adulau added a commit that referenced this issue Aug 24, 2020
fix #449; Added stricter regex for matching CVE on CPE
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants