Skip to content

Update titles/descriptions for NVD advisories. #441

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
FionaDL opened this issue Apr 2, 2020 · 6 comments
Closed

Update titles/descriptions for NVD advisories. #441

FionaDL opened this issue Apr 2, 2020 · 6 comments
Assignees

Comments

@FionaDL
Copy link
Contributor

FionaDL commented Apr 2, 2020

As suggested by @postmodern in comment #251 (comment)
it would be nice to update the titles/descriptions for each advisory on using NVD as a url. However, one thing I noticed is that there are no titles on NVD site. The descriptions could be updated. What do you think is the best approach @postmodern ?

@postmodern
Copy link
Member

Hmm let's wait on titles since that will require manually summarizing the description. Descriptions can be scraped from NVD (//p[@data-testid="vuln-description"]).

@simar7
Copy link
Contributor

simar7 commented Aug 21, 2020

hi @postmodern and @FionaDL I was trying to take a quick peek at this but noticed that most CVE yaml files already have a title in them. For instance

title: Kafo default_values.yaml Insecure Permissions Local Information Disclosure

What are we missing then? Sorry if this is something that's obvious as I'm not able to find it.

@simar7
Copy link
Contributor

simar7 commented Aug 21, 2020

Was the idea to update these titles as they are possibly coming from OSVDB and might have copyright issues? Sorry just trying to fill in myself on the context.

@FionaDL
Copy link
Contributor Author

FionaDL commented Aug 24, 2020

Hi @simar7 ! Yes, I think the idea was that since the titles are leftover from the old links to the OSVDB website that we should update the titles and descriptions to match the links that they are now pointing at. Unfortunately the https://nvd.nist.gov site doesn't seem to use titles. They do have updated descriptions though.

@simar7
Copy link
Contributor

simar7 commented Aug 25, 2020

Hi @simar7 ! Yes, I think the idea was that since the titles are leftover from the old links to the OSVDB website that we should update the titles and descriptions to match the links that they are now pointing at. Unfortunately the https://nvd.nist.gov site doesn't seem to use titles. They do have updated descriptions though.

Thanks. I've created a PR here to address it #456

@postmodern
Copy link
Member

Closing since #456 was merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants