Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Data quality issue with GHSA-4wrc-f8pq-fpqp #2197

Open
wrngrn opened this issue May 9, 2024 · 1 comment
Open

Data quality issue with GHSA-4wrc-f8pq-fpqp #2197

wrngrn opened this issue May 9, 2024 · 1 comment
Labels
data quality Issues with data quality

Comments

@wrngrn
Copy link

wrngrn commented May 9, 2024

The CVE ID
CVE-2016-1000027
https://osv.dev/vulnerability/CVE-2016-1000027
https://osv.dev/vulnerability/GHSA-4wrc-f8pq-fpqp

Describe the data quality issue observed

Missing releases
Versions are missing in the affected[].versions field.
All vesions before 6.0.0 are affected but the affected[].versions list ends at 5.3.32 it is missing 5.3.33 and 5.3.34

Suggested changes to record
Update the affected versions to include all the missing releases.

Additional context
Thanks a lot!

@wrngrn wrngrn added the data quality Issues with data quality label May 9, 2024
@andrewpollock andrewpollock changed the title Data quality issue with CVE-2016-1000027 Data quality issue with GHSA-4wrc-f8pq-fpqp May 15, 2024
@andrewpollock
Copy link
Contributor

Hello,

Thank you for taking the time to report this data quality issue.

Please note that in OSV.dev, CVE-2016-1000027 and GHSA-4wrc-f8pq-fpqp are distinct vulnerability records.

Your feedback relates specifically to the latter record, not the former.

GHSA-4wrc-f8pq-fpqp originates from the GitHub Advisory Database, and can be directly corrected via https://github.com/advisories/GHSA-4wrc-f8pq-fpqp/improve

That said, I see that the source record was corrected in github/advisory-database@2f3ad85

Due to #2017 and #2018, subsequent updates to Git-based source records are not picked up by OSV.dev's importer.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
data quality Issues with data quality
Projects
None yet
Development

No branches or pull requests

2 participants