Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Data quality issue with CVE-2024-37890 #2330

Closed
zurada opened this issue Jun 20, 2024 · 3 comments
Closed

Data quality issue with CVE-2024-37890 #2330

zurada opened this issue Jun 20, 2024 · 3 comments
Labels
data quality Issues with data quality

Comments

@zurada
Copy link

zurada commented Jun 20, 2024

The CVE ID
https://osv.dev/vulnerability/CVE-2024-37890
Describe the data quality issue observed
Aliased GHSA GHSA-3h5v-q93c-6h6q could not be found in OSV.dev despite of fact it's in the GHSA database https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-3h5v-q93c-6h6q/GHSA-3h5v-q93c-6h6q.json
Suggested changes to record
GHSA-3h5v-q93c-6h6q should be present in the OSV.dev unless the requester does not understand when GHSA should or should not be present (please clarify its logic)

@zurada zurada added the data quality Issues with data quality label Jun 20, 2024
Copy link

✨ Thank you for your interest in OSV.dev's data quality! ✨

Please review our FAQ entry on how to most efficiently have this addressed.

@G-Rath
Copy link
Collaborator

G-Rath commented Jun 24, 2024

Adding to this, the advisory also does not have an affected package meaning that the API and tools like osv-scanner won't actually report this vulnerability in most cases unless you're using depending on the ws package via git directly, which is not going to be most people 😅

@michaelkedar
Copy link
Member

Thanks for flagging this.
I've triggered a re-import of this entry and it is now showing up on osv.dev

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
data quality Issues with data quality
Projects
None yet
Development

No branches or pull requests

3 participants