Skip to content

Conversation

@MarkLee131
Copy link

No description provided.

@copernico
Copy link
Contributor

copernico commented Jul 11, 2024

@serenaponta @henrikplate Why did we need the -SEC modifier for the id of this vulnerability?

@serenaponta
Copy link
Collaborator

@copernico we had to create two entried as we identified fix commits in separate repositories and they were analysed as CVE-2016-5007 for "https://github.com/spring-projects/spring-framework.git and CVE-2016-5007-SEC for https://github.com/spring-projects/spring-security.git in Eclipse Steady (where each vulnerability was linked to a single repository). I am not sure the current repository in branch vulnerability-data includes both.

@copernico
Copy link
Contributor

I guess the correct solution would be to have a single statement pointing to the two fixes (from different repositories, which would make this diverge from the one-repo-per-vulnerability model that Steady is based on).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants