fasten-project/vulnerability-producer

Invalid CVE ids in the DB

Closed this issue · 1 comments

cg122 commented

This issue records found invalid CVE id in the DB and may help to track where they come from in vulnerability processing.

  • CVE-2016-3092-FU

CVE-2016-3092 is valid.

http://research-fasten:9001/api/mvn/vulnerabilities/CVE-2016-3092-FU

  • CVE-2016-5007-SEC

CVE-2016-5007 is valid.

http://research-fasten:9001/api/mvn/vulnerabilities/CVE-2016-5007-SEC

  • CVE-2017-4995-JK

CVE-2017-4995 is valid, and related to Spring Security. However, CVE-2017-4995-JK mapped to FasterXML:jackson-databind