Skip to content

Commit 2d73bf4

Browse files
committed
add tests for OSV DataSource
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
1 parent 022c267 commit 2d73bf4

6 files changed

Lines changed: 328 additions & 1 deletion

File tree

vulntotal/datasources/__init__.py

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,6 @@
2424

2525
from vulntotal.datasources import osv
2626

27-
2827
DATASOURCE_REGISTRY = [
2928
osv.OSVDataSource,
3029
]
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"vulns":[{"id":"PYSEC-2014-8","details":"The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.","aliases":["CVE-2014-1402"],"modified":"2021-07-05T00:01:22.043149Z","published":"2014-05-19T14:55:00Z","references":[{"type":"WEB","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734747"},{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2014-0028.html"},{"type":"WEB","url":"http://jinja.pocoo.org/docs/changelog/"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/01/10/3"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1051421"},{"type":"ADVISORY","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2014:096"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/01/10/2"},{"type":"ADVISORY","url":"http://secunia.com/advisories/59017"},{"type":"ADVISORY","url":"http://secunia.com/advisories/58918"},{"type":"ADVISORY","url":"http://secunia.com/advisories/60770"},{"type":"ADVISORY","url":"http://secunia.com/advisories/60738"},{"type":"ADVISORY","url":"http://secunia.com/advisories/56287"},{"type":"WEB","url":"http://www.gentoo.org/security/en/glsa/glsa-201408-13.xml"},{"type":"WEB","url":"https://oss.oracle.com/pipermail/el-errata/2014-June/004192.html"},{"type":"ADVISORY","url":"http://secunia.com/advisories/58783"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-0748.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-0747.html"}],"affected":[{"package":{"name":"jinja2","ecosystem":"PyPI","purl":"pkg:pypi/jinja2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.2"}]}],"versions":["2.0","2.0rc1","2.1","2.1.1","2.2","2.2.1","2.3","2.3.1","2.4","2.4.1","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6","2.7","2.7.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jinja2/PYSEC-2014-8.yaml"}}],"schema_version":"1.2.0"},{"id":"PYSEC-2014-82","details":"FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.","aliases":["CVE-2014-0012"],"modified":"2021-08-27T03:22:05.027573Z","published":"2014-05-19T14:55:00Z","references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1051421"},{"type":"WEB","url":"https://github.com/mitsuhiko/jinja2/pull/292"},{"type":"FIX","url":"https://github.com/mitsuhiko/jinja2/commit/acb672b6a179567632e032f547582f30fa2f4aa7"},{"type":"WEB","url":"http://seclists.org/oss-sec/2014/q1/73"},{"type":"WEB","url":"https://github.com/mitsuhiko/jinja2/pull/296"},{"type":"ADVISORY","url":"http://secunia.com/advisories/60738"},{"type":"WEB","url":"http://www.gentoo.org/security/en/glsa/glsa-201408-13.xml"},{"type":"ADVISORY","url":"http://secunia.com/advisories/56328"}],"affected":[{"package":{"name":"jinja2","ecosystem":"PyPI","purl":"pkg:pypi/jinja2"},"ranges":[{"type":"GIT","repo":"https://github.com/mitsuhiko/jinja2","events":[{"introduced":"0"},{"fixed":"acb672b6a179567632e032f547582f30fa2f4aa7"}]},{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.3"}]}],"versions":["2.0","2.0rc1","2.1","2.1.1","2.2","2.2.1","2.3","2.3.1","2.4","2.4.1","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6","2.7","2.7.1","2.7.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jinja2/PYSEC-2014-82.yaml"}}],"schema_version":"1.2.0"},{"id":"PYSEC-2019-217","details":"In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.","aliases":["CVE-2019-10906","GHSA-462w-v97r-4m45"],"modified":"2021-11-22T04:57:52.862665Z","published":"2019-04-07T00:29:00Z","references":[{"type":"ARTICLE","url":"https://palletsprojects.com/blog/jinja-2-10-1-released"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b2380d147b508bbcb90d2cad443c159e63e12555966ab4f320ee22da@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/46c055e173b52d599c648a98199972dbd6a89d2b4c4647b0500f2284@%3Cdevnull.infra.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/f0c4a03418bcfe70c539c5dbaf99c04c98da13bfa1d3266f08564316@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/7f39f01392d320dfb48e4901db68daeece62fd60ef20955966739993@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/57673a78c4d5c870d3f21465c7e2946b9f8285c7c57e54c2ae552f02@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/320441dccbd9a545320f5f07306d711d4bbd31ba43dc9eebcfc602df@%3Cdevnull.infra.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/2b52b9c8b9d6366a4f1b407a8bde6af28d9fc73fdb3b37695fd0d9ac@%3Cdevnull.infra.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/09fc842ff444cd43d9d4c510756fec625ef8eb1175f14fd21de2605f@%3Cdevnull.infra.apache.org%3E"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QCDYIS254EJMBNWOG4S5QY6AOTOR4TZU/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DSW3QZMFVVR7YE3UT4YRQA272TYAL5AF/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TS7IVZAJBWOHNRDMFJDIZVFCMRP6YIUQ/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1152"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1237"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1329"},{"type":"WEB","url":"https://usn.ubuntu.com/4011-1/"},{"type":"WEB","url":"https://usn.ubuntu.com/4011-2/"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-462w-v97r-4m45"}],"affected":[{"package":{"name":"jinja2","ecosystem":"PyPI","purl":"pkg:pypi/jinja2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.10.1"}]}],"versions":["2.0","2.0rc1","2.1","2.1.1","2.10","2.2","2.2.1","2.3","2.3.1","2.4","2.4.1","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6","2.7","2.7.1","2.7.2","2.7.3","2.8","2.8.1","2.9","2.9.1","2.9.2","2.9.3","2.9.4","2.9.5","2.9.6"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jinja2/PYSEC-2019-217.yaml"}}],"schema_version":"1.2.0"},{"id":"PYSEC-2019-220","details":"In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.","aliases":["CVE-2016-10745","GHSA-hj2j-77xm-mc5v"],"modified":"2021-11-22T04:57:52.929678Z","published":"2019-04-08T13:29:00Z","references":[{"type":"ARTICLE","url":"https://palletsprojects.com/blog/jinja-281-released/"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/9b53045c34e61013dc8f09b7e52a555fa16bed16"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1022"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1237"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1260"},{"type":"WEB","url":"https://usn.ubuntu.com/4011-1/"},{"type":"WEB","url":"https://usn.ubuntu.com/4011-2/"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3964"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4062"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hj2j-77xm-mc5v"}],"affected":[{"package":{"name":"jinja2","ecosystem":"PyPI","purl":"pkg:pypi/jinja2"},"ranges":[{"type":"GIT","repo":"https://github.com/pallets/jinja","events":[{"introduced":"0"},{"fixed":"9b53045c34e61013dc8f09b7e52a555fa16bed16"}]},{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.1"}]}],"versions":["2.0","2.0rc1","2.1","2.1.1","2.2","2.2.1","2.3","2.3.1","2.4","2.4.1","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6","2.7","2.7.1","2.7.2","2.7.3","2.8"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jinja2/PYSEC-2019-220.yaml"}}],"schema_version":"1.2.0"},{"id":"PYSEC-2021-66","details":"This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.","aliases":["CVE-2020-28493","SNYK-PYTHON-JINJA2-1012994","GHSA-g3rq-g295-4j3m"],"modified":"2021-03-22T16:34:00Z","published":"2021-02-01T20:15:00Z","references":[{"type":"WEB","url":"https://github.com/pallets/jinja/blob/ab81fd9c277900c85da0c322a2ff9d68a235b2e6/src/jinja2/utils.py%23L20"},{"type":"WEB","url":"https://github.com/pallets/jinja/pull/1343"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-PYTHON-JINJA2-1012994"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PVAKCOO7VBVUBM3Q6CBBTPBFNP5NDXF4/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g3rq-g295-4j3m"}],"affected":[{"package":{"name":"jinja2","ecosystem":"PyPI","purl":"pkg:pypi/jinja2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.3"}]}],"versions":["2.0rc1","2.0","2.1","2.1.1","2.2","2.2.1","2.3","2.3.1","2.4","2.4.1","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6","2.7","2.7.1","2.7.2","2.7.3","2.8","2.8.1","2.9","2.9.1","2.9.2","2.9.3","2.9.4","2.9.5","2.9.6","2.10","2.10.1","2.10.2","2.10.3","2.11.0","2.11.1","2.11.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jinja2/PYSEC-2021-66.yaml"}}],"schema_version":"1.2.0"}]}
Lines changed: 195 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,195 @@
1+
[
2+
{
3+
"affected_versions": [
4+
"0",
5+
"2.0",
6+
"2.0rc1",
7+
"2.1",
8+
"2.1.1",
9+
"2.2",
10+
"2.2.1",
11+
"2.3",
12+
"2.3.1",
13+
"2.4",
14+
"2.4.1",
15+
"2.5",
16+
"2.5.1",
17+
"2.5.2",
18+
"2.5.3",
19+
"2.5.4",
20+
"2.5.5",
21+
"2.6",
22+
"2.7",
23+
"2.7.1"
24+
],
25+
"fixed_versions": [
26+
"2.7.2"
27+
],
28+
"aliases": [
29+
"CVE-2014-1402",
30+
"PYSEC-2014-8"
31+
]
32+
},
33+
{
34+
"affected_versions": [
35+
"0",
36+
"2.0",
37+
"2.0rc1",
38+
"2.1",
39+
"2.1.1",
40+
"2.2",
41+
"2.2.1",
42+
"2.3",
43+
"2.3.1",
44+
"2.4",
45+
"2.4.1",
46+
"2.5",
47+
"2.5.1",
48+
"2.5.2",
49+
"2.5.3",
50+
"2.5.4",
51+
"2.5.5",
52+
"2.6",
53+
"2.7",
54+
"2.7.1",
55+
"2.7.2"
56+
],
57+
"fixed_versions": [
58+
"acb672b6a179567632e032f547582f30fa2f4aa7"
59+
],
60+
"aliases": [
61+
"CVE-2014-0012",
62+
"PYSEC-2014-82"
63+
]
64+
},
65+
{
66+
"affected_versions": [
67+
"0",
68+
"2.0",
69+
"2.0rc1",
70+
"2.1",
71+
"2.1.1",
72+
"2.10",
73+
"2.2",
74+
"2.2.1",
75+
"2.3",
76+
"2.3.1",
77+
"2.4",
78+
"2.4.1",
79+
"2.5",
80+
"2.5.1",
81+
"2.5.2",
82+
"2.5.3",
83+
"2.5.4",
84+
"2.5.5",
85+
"2.6",
86+
"2.7",
87+
"2.7.1",
88+
"2.7.2",
89+
"2.7.3",
90+
"2.8",
91+
"2.8.1",
92+
"2.9",
93+
"2.9.1",
94+
"2.9.2",
95+
"2.9.3",
96+
"2.9.4",
97+
"2.9.5",
98+
"2.9.6"
99+
],
100+
"fixed_versions": [
101+
"2.10.1"
102+
],
103+
"aliases": [
104+
"CVE-2019-10906",
105+
"GHSA-462w-v97r-4m45",
106+
"PYSEC-2019-217"
107+
]
108+
},
109+
{
110+
"affected_versions": [
111+
"0",
112+
"2.0",
113+
"2.0rc1",
114+
"2.1",
115+
"2.1.1",
116+
"2.2",
117+
"2.2.1",
118+
"2.3",
119+
"2.3.1",
120+
"2.4",
121+
"2.4.1",
122+
"2.5",
123+
"2.5.1",
124+
"2.5.2",
125+
"2.5.3",
126+
"2.5.4",
127+
"2.5.5",
128+
"2.6",
129+
"2.7",
130+
"2.7.1",
131+
"2.7.2",
132+
"2.7.3",
133+
"2.8"
134+
],
135+
"fixed_versions": [
136+
"9b53045c34e61013dc8f09b7e52a555fa16bed16"
137+
],
138+
"aliases": [
139+
"CVE-2016-10745",
140+
"GHSA-hj2j-77xm-mc5v",
141+
"PYSEC-2019-220"
142+
]
143+
},
144+
{
145+
"affected_versions": [
146+
"0",
147+
"2.0",
148+
"2.0rc1",
149+
"2.1",
150+
"2.1.1",
151+
"2.10",
152+
"2.10.1",
153+
"2.10.2",
154+
"2.10.3",
155+
"2.11.0",
156+
"2.11.1",
157+
"2.11.2",
158+
"2.2",
159+
"2.2.1",
160+
"2.3",
161+
"2.3.1",
162+
"2.4",
163+
"2.4.1",
164+
"2.5",
165+
"2.5.1",
166+
"2.5.2",
167+
"2.5.3",
168+
"2.5.4",
169+
"2.5.5",
170+
"2.6",
171+
"2.7",
172+
"2.7.1",
173+
"2.7.2",
174+
"2.7.3",
175+
"2.8",
176+
"2.8.1",
177+
"2.9",
178+
"2.9.1",
179+
"2.9.2",
180+
"2.9.3",
181+
"2.9.4",
182+
"2.9.5",
183+
"2.9.6"
184+
],
185+
"fixed_versions": [
186+
"2.11.3"
187+
],
188+
"aliases": [
189+
"CVE-2020-28493",
190+
"GHSA-g3rq-g295-4j3m",
191+
"PYSEC-2021-66",
192+
"SNYK-PYTHON-JINJA2-1012994"
193+
]
194+
}
195+
]
Lines changed: 71 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,71 @@
1+
[
2+
{
3+
"version": "2.4.1",
4+
"package": {
5+
"ecosystem": "PyPI",
6+
"name": "jinja2"
7+
}
8+
},
9+
{
10+
"version": "10",
11+
"package": {
12+
"ecosystem": "Android",
13+
"name": "System"
14+
}
15+
},
16+
{
17+
"version": "1.1.3-1",
18+
"package": {
19+
"name": "davical"
20+
}
21+
},
22+
{
23+
"version": "10.1.0-M8",
24+
"package": {
25+
"ecosystem": "Maven",
26+
"name": "org.apache.tomcat:tomcat"
27+
}
28+
},
29+
{
30+
"version": "v5.4.195",
31+
"package": {
32+
"ecosystem": "Linux",
33+
"name": "Kernel"
34+
}
35+
},
36+
{
37+
"version": "12.0.5",
38+
"package": {
39+
"ecosystem": "Packagist",
40+
"name": "dolibarr/dolibarr"
41+
}
42+
},
43+
{
44+
"version": "0.9.7",
45+
"package": {
46+
"ecosystem": "crates.io",
47+
"name": "sha2"
48+
}
49+
},
50+
{
51+
"version": "2.18.0",
52+
"package": {
53+
"ecosystem": "NuGet",
54+
"name": "Moment.js"
55+
}
56+
},
57+
{
58+
"version": "3.1.3",
59+
"package": {
60+
"ecosystem": "npm",
61+
"name": "semver-regex"
62+
}
63+
},
64+
{
65+
"version": "0.1.0",
66+
"package": {
67+
"ecosystem": "Go",
68+
"name": "github.com/cloudflare/cfrpki/validator/lib"
69+
}
70+
}
71+
]
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
pkg:pypi/jinja2@2.4.1
2+
pkg:android/System@10
3+
pkg:Debian:8/davical@1.1.3-1
4+
pkg:maven/org.apache.tomcat/tomcat@10.1.0-M8
5+
pkg:Linux/Kernel@v5.4.195
6+
pkg:Packagist/dolibarr/dolibarr@12.0.5
7+
pkg:crates.io/sha2@0.9.7
8+
pkg:nuget/Moment.js@2.18.0
9+
pkg:npm/semver-regex@3.1.3
10+
pkg:go/github.com/cloudflare/cfrpki/validator/lib@0.1.0

vulntotal/tests/test_osv.py

Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
#
2+
# Copyright (c) nexB Inc. and others. All rights reserved.
3+
# http://nexb.com and https://github.com/nexB/vulnerablecode/
4+
# The VulnTotal software is licensed under the Apache License version 2.0.
5+
# Data generated with VulnTotal require an acknowledgment.
6+
#
7+
# You may not use this software except in compliance with the License.
8+
# You may obtain a copy of the License at: http://apache.org/licenses/LICENSE-2.0
9+
# Unless required by applicable law or agreed to in writing, software distributed
10+
# under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR
11+
# CONDITIONS OF ANY KIND, either express or implied. See the License for the
12+
# specific language governing permissions and limitations under the License.
13+
#
14+
# When you publish or redistribute any data created with VulnTotal or any VulnTotal
15+
# derivative work, you must accompany this data with the following acknowledgment:
16+
#
17+
# Generated with VulnTotal and provided on an "AS IS" BASIS, WITHOUT WARRANTIES
18+
# OR CONDITIONS OF ANY KIND, either express or implied. No content created from
19+
# VulnTotal should be considered or used as legal advice. Consult an Attorney
20+
# for any legal advice.
21+
# VulnTotal is a free software tool from nexB Inc. and others.
22+
# Visit https://github.com/nexB/vulnerablecode/ for support and download.
23+
24+
import json
25+
from pathlib import Path
26+
27+
from commoncode import testcase
28+
from packageurl import PackageURL
29+
30+
from vulnerabilities.tests import util_tests
31+
from vulntotal.datasources import osv
32+
33+
34+
class TestOSV(testcase.FileBasedTesting):
35+
test_data_dir = str(Path(__file__).resolve().parent / "test_data" / "osv")
36+
37+
def test_generate_payload(self):
38+
file_purls = self.get_test_loc("purls.txt")
39+
with open(file_purls) as f:
40+
purls = f.readlines()
41+
results = [osv.generate_payload(PackageURL.from_string(purl)) for purl in purls]
42+
expected_file = self.get_test_loc("payloads_data-expected.json", must_exist=False)
43+
util_tests.check_results_against_json(results, expected_file)
44+
45+
def test_parse_advisory(self):
46+
advisory_page = self.get_test_loc("advisory.txt")
47+
with open(advisory_page) as f:
48+
advisory = json.load(f)
49+
results = [adv.to_dict() for adv in osv.parse_advisory(advisory)]
50+
expected_file = self.get_test_loc("parse_advisory_data-expected.json", must_exist=False)
51+
util_tests.check_results_against_json(results, expected_file)

0 commit comments

Comments
 (0)