Display version constraints for a CVE in the suggestion view #334

Closed
opened 2024-11-11 10:24:15 +00:00 by fricklerhandwerk · 2 comments
fricklerhandwerk commented 2024-11-11 10:24:15 +00:00 (Migrated from github.com)

As a security team member I want to see at a glance which versions of suggested packages are affected (assuming the suggestions are relevant). Currently we'd have to click through the upstream CVE description.

Version constraints are part of an CPE identifier, which should be shown in full. That means the same workflow would allow for seeing which affected software information (e.g. package name) the CVE provides.

As a security team member I want to see at a glance which versions of suggested packages are affected (assuming the suggestions are relevant). Currently we'd have to click through the upstream CVE description. Version constraints are part of an CPE identifier, which should be shown in full. That means the same workflow would allow for seeing which affected software information (e.g. package name) the CVE provides.
fricklerhandwerk commented 2024-11-15 09:48:54 +00:00 (Migrated from github.com)

Here's an example CVE where we have an affected channel: https://nvd.nist.gov/vuln/detail/CVE-2023-40660

Currently we can't see that at all without digging into the CVE description

image

Here's an example CVE where we have an affected channel: https://nvd.nist.gov/vuln/detail/CVE-2023-40660 Currently we can't see that at all without digging into the CVE description ![image](https://github.com/user-attachments/assets/8ae17d7c-dad8-4438-a817-bec0b7905b8e)
erictapen commented 2024-11-15 15:47:16 +00:00 (Migrated from github.com)

@RaitoBezarius Can you estimate when you could make version constraints available in the view code? If it works out I would try to start monday on this.

@RaitoBezarius Can you estimate when you could make version constraints available in the view code? If it works out I would try to start monday on this.
Sign in to join this conversation.
No description provided.