Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency Track not resolving the CVE Severity #4340

Open
2 tasks done
zadia1977 opened this issue Oct 29, 2024 · 1 comment
Open
2 tasks done

Dependency Track not resolving the CVE Severity #4340

zadia1977 opened this issue Oct 29, 2024 · 1 comment
Labels
defect Something isn't working in triage

Comments

@zadia1977
Copy link

Current Behavior

We have recently performed SBOM analysis and Dependency Track is not assigning the severity for many CVEs, even though the OSSIndex has it assigned.

Example.. (many more if you need them)

Purl = pkg:maven/org.apache.avro/avro@1.11.3
Link to OSSIndex = https://ossindex.sonatype.org/vulnerability/CVE-2024-47561?component-type=maven&component-name=org.apache.avro%2Favro&utm_source=dependency-track&utm_medium=integration&utm_content=v4.11.5
Image

Steps to Reproduce

1.Create new DT project
2. Add component 'pkg:maven/org.apache.avro/avro@1.11.3'
3. See DT resolve with CVE, but not assign severity
4. Link to OSSIndex = https://ossindex.sonatype.org/vulnerability/CVE-2024-47561?component-type=maven&component-name=org.apache.avro%2Favro&utm_source=dependency-track&utm_medium=integration&utm_content=v4.11.5

Expected Behavior

Resolve severity

Dependency-Track Version

4.11.x

Dependency-Track Distribution

Container Image

Database Server

PostgreSQL

Database Server Version

No response

Browser

Google Chrome

Checklist

@zadia1977 zadia1977 added defect Something isn't working in triage labels Oct 29, 2024
@zadia1977
Copy link
Author

I've been informed that DT uses NVD for Severity.... and most are 'under reanalysis', so is it possible to pull the Severity from OSSIndex if unable to resolve the severity from NVD (priority order)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
defect Something isn't working in triage
Projects
None yet
Development

No branches or pull requests

1 participant