Repository navigation
Replies: 1 comment
|
Thanks for the detailed report! This is by design rather than a bug. The CVSS score shown on https://ubuntu.com/security/CVE-2016-2568 is not Ubuntu's own assessment — it is simply the NVD score that Ubuntu re-publishes. You can see this in the upstream data source, ubuntu-cve-tracker: https://git.launchpad.net/ubuntu-cve-tracker/tree/active/CVE-2016-2568 There the CVSS entry is explicitly tagged with its source (nvd), i.e. Ubuntu is just carrying over the NVD score, not scoring the vulnerability itself. So if we copied that value into the ubuntu_api block, we would have two problems:
What Ubuntu does assign is its own priority, and that is what you see reflected as "cvss2Severity": "low" / "cvss3Severity": "low" in the ubuntu_api block — the score stays 0 because Ubuntu does not publish a score of its own. Regarding the increase in sources compared with 0.39.3: that is expected. The newer detection path reports each source separately so that you can see exactly who said what, instead of silently merging values from different vendors. |
Uh oh!
There was an error while loading. Please reload this page.
When i build the latest image from HEAD(45714b6) i can see now it giving result from multiple sources . Sample output
Earlier on the latest release 0.39.3 there were only two
redhat_apiandubuntu_apiMy doubt here is why under
ubuntu_apiscore is coming as 0 but when i open the CVE in the browser https://ubuntu.com/security/CVE-2016-2568 it does shows the score which matches the one in NVD.Why can't we just add the same NVD score in the ubuntu_api key block . Is that by design or something it will be fixed later.
Sponsored by: https://obmondo.com/
All reactions