+
Skip to content

Conversation

wagoodman
Copy link
Contributor

@wagoodman wagoodman commented Jun 30, 2025

Today it is possible to have NVD entries that have no range information for a CVE, such as with CVE-2010-4756, however, the correct interpretation of this is that all versions are vulnerable. This looks like it was introduced in the v6 development effort (based on the data shape changes I'm seeing, this class of bugs makes sense) and it led to a reduction in FPs with the exception for one finding (which is why it was merged).

Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
Copy link
Contributor

@kzantow kzantow left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Makes sense to me -- I can't see why we'd have entries that we assume the opposite 👍

@wagoodman wagoodman marked this pull request as ready for review July 1, 2025 13:49
@wagoodman
Copy link
Contributor Author

wagoodman commented Jul 1, 2025

bypassing quality gate -- it is not expected to pass since fixing this bug necessarily means adding FPs to known results. @westonsteimel and I have verified the results are what we'd expect.

@wagoodman wagoodman merged commit 33e1855 into main Jul 1, 2025
11 of 12 checks passed
@wagoodman wagoodman deleted the no-ranges-vulnerable branch July 1, 2025 14:51
@wagoodman wagoodman added the bug Something isn't working label Jul 1, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载