Skip to content

Handle Gitlab false positive #1447

@pombredanne

Description

@pombredanne

This https://gitlab.com/gitlab-org/advisories-community/-/blob/main/maven/org.owasp.antisamy/antisamy/CVE-2023-49093.yml started as an advisory and then became a "False positive"
Gitlab updates the description and title in these cases, and there are 150+ such advisories.

The outcome is invalid data. We should support these and update accordingly

See https://public.vulnerablecode.io/packages/pkg:maven/org.owasp.antisamy/[email protected]?search=antisamy

There https://public.vulnerablecode.io/vulnerabilities/VCID-zx5k-4m3n-aaaj does NOT apply to antisamy

Screenshot 2024-03-26 at 12-38-37 VulnerableCode Package Details - pkg maven_org owasp antisamy_antisamy@1 7 4

See attached for a list of patterns found in GitLab advisories
fp.txt

@julianthome gentle ping... do you know if there is a list of patterns we can track? Thanks!

In the same domain, we should also find is there are other related unstructured patterns in GitLab and also:

  • Handle "Disputed" markers in CVEs texts
  • Handle "Awaiting Analysis" in CVEs

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions