Skip to content

Commit 491c318

Browse files
committed
test OSVDataSource
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
1 parent ab161ff commit 491c318

5 files changed

Lines changed: 313 additions & 0 deletions

File tree

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"vulns":[{"id":"PYSEC-2014-8","details":"The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.","aliases":["CVE-2014-1402"],"modified":"2021-07-05T00:01:22.043149Z","published":"2014-05-19T14:55:00Z","references":[{"type":"WEB","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734747"},{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2014-0028.html"},{"type":"WEB","url":"http://jinja.pocoo.org/docs/changelog/"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/01/10/3"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1051421"},{"type":"ADVISORY","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2014:096"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/01/10/2"},{"type":"ADVISORY","url":"http://secunia.com/advisories/59017"},{"type":"ADVISORY","url":"http://secunia.com/advisories/58918"},{"type":"ADVISORY","url":"http://secunia.com/advisories/60770"},{"type":"ADVISORY","url":"http://secunia.com/advisories/60738"},{"type":"ADVISORY","url":"http://secunia.com/advisories/56287"},{"type":"WEB","url":"http://www.gentoo.org/security/en/glsa/glsa-201408-13.xml"},{"type":"WEB","url":"https://oss.oracle.com/pipermail/el-errata/2014-June/004192.html"},{"type":"ADVISORY","url":"http://secunia.com/advisories/58783"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-0748.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-0747.html"}],"affected":[{"package":{"name":"jinja2","ecosystem":"PyPI","purl":"pkg:pypi/jinja2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.2"}]}],"versions":["2.0","2.0rc1","2.1","2.1.1","2.2","2.2.1","2.3","2.3.1","2.4","2.4.1","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6","2.7","2.7.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jinja2/PYSEC-2014-8.yaml"}}],"schema_version":"1.2.0"},{"id":"PYSEC-2014-82","details":"FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.","aliases":["CVE-2014-0012"],"modified":"2021-08-27T03:22:05.027573Z","published":"2014-05-19T14:55:00Z","references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1051421"},{"type":"WEB","url":"https://github.com/mitsuhiko/jinja2/pull/292"},{"type":"FIX","url":"https://github.com/mitsuhiko/jinja2/commit/acb672b6a179567632e032f547582f30fa2f4aa7"},{"type":"WEB","url":"http://seclists.org/oss-sec/2014/q1/73"},{"type":"WEB","url":"https://github.com/mitsuhiko/jinja2/pull/296"},{"type":"ADVISORY","url":"http://secunia.com/advisories/60738"},{"type":"WEB","url":"http://www.gentoo.org/security/en/glsa/glsa-201408-13.xml"},{"type":"ADVISORY","url":"http://secunia.com/advisories/56328"}],"affected":[{"package":{"name":"jinja2","ecosystem":"PyPI","purl":"pkg:pypi/jinja2"},"ranges":[{"type":"GIT","repo":"https://github.com/mitsuhiko/jinja2","events":[{"introduced":"0"},{"fixed":"acb672b6a179567632e032f547582f30fa2f4aa7"}]},{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.3"}]}],"versions":["2.0","2.0rc1","2.1","2.1.1","2.2","2.2.1","2.3","2.3.1","2.4","2.4.1","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6","2.7","2.7.1","2.7.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jinja2/PYSEC-2014-82.yaml"}}],"schema_version":"1.2.0"},{"id":"PYSEC-2019-217","details":"In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.","aliases":["CVE-2019-10906","GHSA-462w-v97r-4m45"],"modified":"2021-11-22T04:57:52.862665Z","published":"2019-04-07T00:29:00Z","references":[{"type":"ARTICLE","url":"https://palletsprojects.com/blog/jinja-2-10-1-released"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b2380d147b508bbcb90d2cad443c159e63e12555966ab4f320ee22da@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/46c055e173b52d599c648a98199972dbd6a89d2b4c4647b0500f2284@%3Cdevnull.infra.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/f0c4a03418bcfe70c539c5dbaf99c04c98da13bfa1d3266f08564316@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/7f39f01392d320dfb48e4901db68daeece62fd60ef20955966739993@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/57673a78c4d5c870d3f21465c7e2946b9f8285c7c57e54c2ae552f02@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/320441dccbd9a545320f5f07306d711d4bbd31ba43dc9eebcfc602df@%3Cdevnull.infra.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/2b52b9c8b9d6366a4f1b407a8bde6af28d9fc73fdb3b37695fd0d9ac@%3Cdevnull.infra.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/09fc842ff444cd43d9d4c510756fec625ef8eb1175f14fd21de2605f@%3Cdevnull.infra.apache.org%3E"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QCDYIS254EJMBNWOG4S5QY6AOTOR4TZU/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DSW3QZMFVVR7YE3UT4YRQA272TYAL5AF/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TS7IVZAJBWOHNRDMFJDIZVFCMRP6YIUQ/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1152"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1237"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1329"},{"type":"WEB","url":"https://usn.ubuntu.com/4011-1/"},{"type":"WEB","url":"https://usn.ubuntu.com/4011-2/"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-462w-v97r-4m45"}],"affected":[{"package":{"name":"jinja2","ecosystem":"PyPI","purl":"pkg:pypi/jinja2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.10.1"}]}],"versions":["2.0","2.0rc1","2.1","2.1.1","2.10","2.2","2.2.1","2.3","2.3.1","2.4","2.4.1","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6","2.7","2.7.1","2.7.2","2.7.3","2.8","2.8.1","2.9","2.9.1","2.9.2","2.9.3","2.9.4","2.9.5","2.9.6"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jinja2/PYSEC-2019-217.yaml"}}],"schema_version":"1.2.0"},{"id":"PYSEC-2019-220","details":"In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.","aliases":["CVE-2016-10745","GHSA-hj2j-77xm-mc5v"],"modified":"2021-11-22T04:57:52.929678Z","published":"2019-04-08T13:29:00Z","references":[{"type":"ARTICLE","url":"https://palletsprojects.com/blog/jinja-281-released/"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/9b53045c34e61013dc8f09b7e52a555fa16bed16"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1022"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1237"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1260"},{"type":"WEB","url":"https://usn.ubuntu.com/4011-1/"},{"type":"WEB","url":"https://usn.ubuntu.com/4011-2/"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3964"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4062"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hj2j-77xm-mc5v"}],"affected":[{"package":{"name":"jinja2","ecosystem":"PyPI","purl":"pkg:pypi/jinja2"},"ranges":[{"type":"GIT","repo":"https://github.com/pallets/jinja","events":[{"introduced":"0"},{"fixed":"9b53045c34e61013dc8f09b7e52a555fa16bed16"}]},{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.1"}]}],"versions":["2.0","2.0rc1","2.1","2.1.1","2.2","2.2.1","2.3","2.3.1","2.4","2.4.1","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6","2.7","2.7.1","2.7.2","2.7.3","2.8"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jinja2/PYSEC-2019-220.yaml"}}],"schema_version":"1.2.0"},{"id":"PYSEC-2021-66","details":"This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.","aliases":["CVE-2020-28493","SNYK-PYTHON-JINJA2-1012994","GHSA-g3rq-g295-4j3m"],"modified":"2021-03-22T16:34:00Z","published":"2021-02-01T20:15:00Z","references":[{"type":"WEB","url":"https://github.com/pallets/jinja/blob/ab81fd9c277900c85da0c322a2ff9d68a235b2e6/src/jinja2/utils.py%23L20"},{"type":"WEB","url":"https://github.com/pallets/jinja/pull/1343"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-PYTHON-JINJA2-1012994"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PVAKCOO7VBVUBM3Q6CBBTPBFNP5NDXF4/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g3rq-g295-4j3m"}],"affected":[{"package":{"name":"jinja2","ecosystem":"PyPI","purl":"pkg:pypi/jinja2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.3"}]}],"versions":["2.0rc1","2.0","2.1","2.1.1","2.2","2.2.1","2.3","2.3.1","2.4","2.4.1","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6","2.7","2.7.1","2.7.2","2.7.3","2.8","2.8.1","2.9","2.9.1","2.9.2","2.9.3","2.9.4","2.9.5","2.9.6","2.10","2.10.1","2.10.2","2.10.3","2.11.0","2.11.1","2.11.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jinja2/PYSEC-2021-66.yaml"}}],"schema_version":"1.2.0"}]}
Lines changed: 195 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,195 @@
1+
[
2+
{
3+
"affected_versions": [
4+
"0",
5+
"2.0",
6+
"2.0rc1",
7+
"2.1",
8+
"2.1.1",
9+
"2.2",
10+
"2.2.1",
11+
"2.3",
12+
"2.3.1",
13+
"2.4",
14+
"2.4.1",
15+
"2.5",
16+
"2.5.1",
17+
"2.5.2",
18+
"2.5.3",
19+
"2.5.4",
20+
"2.5.5",
21+
"2.6",
22+
"2.7",
23+
"2.7.1"
24+
],
25+
"fixed_versions": [
26+
"2.7.2"
27+
],
28+
"aliases": [
29+
"CVE-2014-1402",
30+
"PYSEC-2014-8"
31+
]
32+
},
33+
{
34+
"affected_versions": [
35+
"0",
36+
"2.0",
37+
"2.0rc1",
38+
"2.1",
39+
"2.1.1",
40+
"2.2",
41+
"2.2.1",
42+
"2.3",
43+
"2.3.1",
44+
"2.4",
45+
"2.4.1",
46+
"2.5",
47+
"2.5.1",
48+
"2.5.2",
49+
"2.5.3",
50+
"2.5.4",
51+
"2.5.5",
52+
"2.6",
53+
"2.7",
54+
"2.7.1",
55+
"2.7.2"
56+
],
57+
"fixed_versions": [
58+
"acb672b6a179567632e032f547582f30fa2f4aa7"
59+
],
60+
"aliases": [
61+
"CVE-2014-0012",
62+
"PYSEC-2014-82"
63+
]
64+
},
65+
{
66+
"affected_versions": [
67+
"0",
68+
"2.0",
69+
"2.0rc1",
70+
"2.1",
71+
"2.1.1",
72+
"2.10",
73+
"2.2",
74+
"2.2.1",
75+
"2.3",
76+
"2.3.1",
77+
"2.4",
78+
"2.4.1",
79+
"2.5",
80+
"2.5.1",
81+
"2.5.2",
82+
"2.5.3",
83+
"2.5.4",
84+
"2.5.5",
85+
"2.6",
86+
"2.7",
87+
"2.7.1",
88+
"2.7.2",
89+
"2.7.3",
90+
"2.8",
91+
"2.8.1",
92+
"2.9",
93+
"2.9.1",
94+
"2.9.2",
95+
"2.9.3",
96+
"2.9.4",
97+
"2.9.5",
98+
"2.9.6"
99+
],
100+
"fixed_versions": [
101+
"2.10.1"
102+
],
103+
"aliases": [
104+
"CVE-2019-10906",
105+
"GHSA-462w-v97r-4m45",
106+
"PYSEC-2019-217"
107+
]
108+
},
109+
{
110+
"affected_versions": [
111+
"0",
112+
"2.0",
113+
"2.0rc1",
114+
"2.1",
115+
"2.1.1",
116+
"2.2",
117+
"2.2.1",
118+
"2.3",
119+
"2.3.1",
120+
"2.4",
121+
"2.4.1",
122+
"2.5",
123+
"2.5.1",
124+
"2.5.2",
125+
"2.5.3",
126+
"2.5.4",
127+
"2.5.5",
128+
"2.6",
129+
"2.7",
130+
"2.7.1",
131+
"2.7.2",
132+
"2.7.3",
133+
"2.8"
134+
],
135+
"fixed_versions": [
136+
"9b53045c34e61013dc8f09b7e52a555fa16bed16"
137+
],
138+
"aliases": [
139+
"CVE-2016-10745",
140+
"GHSA-hj2j-77xm-mc5v",
141+
"PYSEC-2019-220"
142+
]
143+
},
144+
{
145+
"affected_versions": [
146+
"0",
147+
"2.0",
148+
"2.0rc1",
149+
"2.1",
150+
"2.1.1",
151+
"2.10",
152+
"2.10.1",
153+
"2.10.2",
154+
"2.10.3",
155+
"2.11.0",
156+
"2.11.1",
157+
"2.11.2",
158+
"2.2",
159+
"2.2.1",
160+
"2.3",
161+
"2.3.1",
162+
"2.4",
163+
"2.4.1",
164+
"2.5",
165+
"2.5.1",
166+
"2.5.2",
167+
"2.5.3",
168+
"2.5.4",
169+
"2.5.5",
170+
"2.6",
171+
"2.7",
172+
"2.7.1",
173+
"2.7.2",
174+
"2.7.3",
175+
"2.8",
176+
"2.8.1",
177+
"2.9",
178+
"2.9.1",
179+
"2.9.2",
180+
"2.9.3",
181+
"2.9.4",
182+
"2.9.5",
183+
"2.9.6"
184+
],
185+
"fixed_versions": [
186+
"2.11.3"
187+
],
188+
"aliases": [
189+
"CVE-2020-28493",
190+
"GHSA-g3rq-g295-4j3m",
191+
"PYSEC-2021-66",
192+
"SNYK-PYTHON-JINJA2-1012994"
193+
]
194+
}
195+
]
Lines changed: 70 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,70 @@
1+
[
2+
{
3+
"version": "2.4.1",
4+
"package": {
5+
"ecosystem": "PyPI",
6+
"name": "jinja2"
7+
}
8+
},
9+
{
10+
"version": "10",
11+
"package": {
12+
"ecosystem": "Android",
13+
"name": "System"
14+
}
15+
},
16+
{
17+
"version": "1.1.3-1",
18+
"package": {
19+
"name": "davical"
20+
}
21+
},
22+
{
23+
"version": "10.1.0-M8",
24+
"package": {
25+
"ecosystem": "Maven",
26+
"name": "org.apache.tomcat:tomcat"
27+
}
28+
},
29+
{
30+
"version": "v5.4.195",
31+
"package": {
32+
"ecosystem": "Linux",
33+
"name": "Kernel"
34+
}
35+
},
36+
{
37+
"version": "12.0.5",
38+
"package": {
39+
"name": "dolibarr/dolibarr"
40+
}
41+
},
42+
{
43+
"version": "0.9.7",
44+
"package": {
45+
"ecosystem": "crates.io",
46+
"name": "sha2"
47+
}
48+
},
49+
{
50+
"version": "2.18.0",
51+
"package": {
52+
"ecosystem": "NuGet",
53+
"name": "Moment.js"
54+
}
55+
},
56+
{
57+
"version": "3.1.3",
58+
"package": {
59+
"ecosystem": "npm",
60+
"name": "semver-regex"
61+
}
62+
},
63+
{
64+
"version": "1.1.0",
65+
"package": {
66+
"ecosystem": "Go",
67+
"name": "github.com/cloudflare/cfrpki"
68+
}
69+
}
70+
]
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
pkg:pypi/jinja2@2.4.1
2+
pkg:android/System@10
3+
pkg:debian:8/davical@1.1.3-1
4+
pkg:maven/org.apache.tomcat/tomcat@10.1.0-M8
5+
pkg:linux/Kernel@v5.4.195
6+
pkg:packagist/dolibarr/dolibarr@12.0.5
7+
pkg:crates.io/sha2@0.9.7
8+
pkg:nuget/Moment.js@2.18.0
9+
pkg:npm/semver-regex@3.1.3
10+
pkg:golang/github.com/cloudflare/cfrpki@1.1.0

vulntotal/tests/test_osv.py

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
#
2+
# Copyright (c) nexB Inc. and others. All rights reserved.
3+
# VulnerableCode is a trademark of nexB Inc.
4+
# SPDX-License-Identifier: Apache-2.0
5+
# See http://www.apache.org/licenses/LICENSE-2.0 for the license text.
6+
# See https://github.com/nexB/vulnerablecode for support or download.
7+
# See https://aboutcode.org for more information about nexB OSS projects.
8+
#
9+
10+
import json
11+
from pathlib import Path
12+
13+
from commoncode import testcase
14+
from packageurl import PackageURL
15+
16+
from vulnerabilities.tests import util_tests
17+
from vulntotal.datasources import osv
18+
19+
20+
class TestOSV(testcase.FileBasedTesting):
21+
test_data_dir = str(Path(__file__).resolve().parent / "test_data" / "osv")
22+
23+
def test_generate_payload(self):
24+
file_purls = self.get_test_loc("purls.txt")
25+
with open(file_purls) as f:
26+
purls = f.readlines()
27+
results = [osv.generate_payload(PackageURL.from_string(purl)) for purl in purls]
28+
expected_file = self.get_test_loc("payloads_data-expected.json", must_exist=False)
29+
util_tests.check_results_against_json(results, expected_file)
30+
31+
def test_parse_advisory(self):
32+
advisory_page = self.get_test_loc("advisory.txt")
33+
with open(advisory_page) as f:
34+
advisory = json.load(f)
35+
results = [adv.to_dict() for adv in osv.parse_advisory(advisory)]
36+
expected_file = self.get_test_loc("parse_advisory_data-expected.json", must_exist=False)
37+
util_tests.check_results_against_json(results, expected_file)

0 commit comments

Comments
 (0)