Skip to content

correct the cve-id of CVE-2016-5007 #384

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

MarkLee131
Copy link

No description provided.

@copernico
Copy link
Contributor

copernico commented Jul 11, 2024

@serenaponta @henrikplate Why did we need the -SEC modifier for the id of this vulnerability?

@serenaponta
Copy link
Collaborator

@copernico we had to create two entried as we identified fix commits in separate repositories and they were analysed as CVE-2016-5007 for "https://github.com/spring-projects/spring-framework.git and CVE-2016-5007-SEC for https://github.com/spring-projects/spring-security.git in Eclipse Steady (where each vulnerability was linked to a single repository). I am not sure the current repository in branch vulnerability-data includes both.

@copernico
Copy link
Contributor

I guess the correct solution would be to have a single statement pointing to the two fixes (from different repositories, which would make this diverge from the one-repo-per-vulnerability model that Steady is based on).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants