Skip to content

Handle Gitlab false positive #1447

Description

@pombredanne

This https://gitlab.com/gitlab-org/advisories-community/-/blob/main/maven/org.owasp.antisamy/antisamy/CVE-2023-49093.yml started as an advisory and then became a "False positive"
Gitlab updates the description and title in these cases, and there are 150+ such advisories.

The outcome is invalid data. We should support these and update accordingly

See https://public.vulnerablecode.io/packages/pkg:maven/org.owasp.antisamy/antisamy@1.7.4?search=antisamy

There https://public.vulnerablecode.io/vulnerabilities/VCID-zx5k-4m3n-aaaj does NOT apply to antisamy

Screenshot 2024-03-26 at 12-38-37 VulnerableCode Package Details - pkg maven_org owasp antisamy_antisamy@1 7 4

See attached for a list of patterns found in GitLab advisories
fp.txt

@julianthome gentle ping... do you know if there is a list of patterns we can track? Thanks!

In the same domain, we should also find is there are other related unstructured patterns in GitLab and also:

  • Handle "Disputed" markers in CVEs texts
  • Handle "Awaiting Analysis" in CVEs

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions