Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Data quality issue CVE-2023-24163 #2195

Closed
achibear opened this issue May 9, 2024 · 3 comments
Closed

Data quality issue CVE-2023-24163 #2195

achibear opened this issue May 9, 2024 · 3 comments
Assignees
Labels
data quality Issues with data quality

Comments

@achibear
Copy link

achibear commented May 9, 2024

The CVE ID
This issue is related with CVE-2023-24163 and GHSA-6c25-cxcc-pmc4

Describe the data quality issue observed
Recently, we found that last affected version of CVE-2023-24163 is incorrect. According to its release note and issue pages, hutool fixed CVE-2023-24163 in verision 5.8.21. However, last affected version listed in OSV is 5.8.11. This incorrect information may mislead developers using this software.

Suggested changes to record
Update the fix version to 5.8.21.

Additional context
References:
gitee issue page: https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link
github issue page: dromara/hutool#3149
hutool release note: https://github.com/dromara/hutool/releases

@andrewpollock
Copy link
Contributor

Hello,

Thank you for your interest in OSV.dev's data quality and taking the time to report this issue.

In short, OSV.dev is not the source of these vulnerability records, as discussed in our FAQ.

There are two distinct vulnerability records involved here:

For GHSA-6c25-cxcc-pmc4, this is self-service reportable and fixable at https://github.com/advisories/GHSA-6c25-cxcc-pmc4/improve, but I have reported this myself and created github/advisory-database#4416

For CVE-2023-24163, this originates from the NVD, and https://nvd.nist.gov/vuln/detail/CVE-2023-24163 states email through any corrections. I have dropped them an email citing this issue.

That said, the source of the record, including the version information in the description ultimately comes from the CVE List, and from the MITRE CNA-LR, I have also notified them via https://cveform.mitre.org/

I expect the GitHub Advisory Database record correction to go through promptly, but I do not know how long the NVD or CVE List corrections will take.

@andrewpollock
Copy link
Contributor

GHSA-6c25-cxcc-pmc4 is now correct in the GitHub Advisory Database and OSV.dev
CVE-2023-24163 is now correct in the CVE List, and this will eventually flow through to the NVD and OSV.dev once it has.

@andrewpollock
Copy link
Contributor

The NVD has also advised they have made the corrections, so our next conversion run should reflect them in OSV.dev.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
data quality Issues with data quality
Projects
None yet
Development

No branches or pull requests

2 participants