-
-
Notifications
You must be signed in to change notification settings - Fork 237
Open
Labels
Description
This https://gitlab.com/gitlab-org/advisories-community/-/blob/main/maven/org.owasp.antisamy/antisamy/CVE-2023-49093.yml started as an advisory and then became a "False positive"
Gitlab updates the description and title in these cases, and there are 150+ such advisories.
The outcome is invalid data. We should support these and update accordingly
There https://public.vulnerablecode.io/vulnerabilities/VCID-zx5k-4m3n-aaaj does NOT apply to antisamy
See attached for a list of patterns found in GitLab advisories
fp.txt
@julianthome gentle ping... do you know if there is a list of patterns we can track? Thanks!
In the same domain, we should also find is there are other related unstructured patterns in GitLab and also:
- Handle "Disputed" markers in CVEs texts
- Handle "Awaiting Analysis" in CVEs