Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-24992 has a non-compliant URL #18

Open
ostefano opened this issue May 3, 2024 · 1 comment
Open

CVE-2024-24992 has a non-compliant URL #18

ostefano opened this issue May 3, 2024 · 1 comment

Comments

@ostefano
Copy link

ostefano commented May 3, 2024

Just FYI, CVE-2024-24992 has an URL that starts with ZDI-CAN-22854https://.

Raising this because my understanding is that you were already validating things against the JSONschema so maybe something is off?

@rhelmke
Copy link
Collaborator

rhelmke commented May 5, 2024

Thanks, Stefano. Our validation does not reject repo pushes when it fails, as everything else than a mere mirror of the original API responses would introduce inconsistencies. The validator caught the error, that's good.

But I don't understand how these data pollution issues can happen on the NVD site of things. 🤔 It is really interesting that this (probably copy-paste) error passed both HackerOne and NVD checks. I sent a message to H1, lets see what happens - gotta keep the data clean 😎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants