RE: EXT :Re: [poky] CVE CHECK scorev3

"Smith, Grant [US] (MS)" <[email protected]>
Newsgroups org.yoctoproject.lists.poky
Message-ID <BN0P110MB1659F246018B1D8BCFF4D98DC7D1A@BN0P110MB1659.NAMP110.PROD.OUTLOOK.COM>
Marta,

I have attached the resulting `cve-summary.json` file. The exact poky version I am using is the tag: yocto-4.2.3 (Commit SHA: aa63b25cbe25d89ab07ca11ee72c17cab68df8de).

Cheers,
Grant

-----Original Message-----
From: Marta Rybczynska <[email protected]> 
Sent: Saturday, October 14, 2023 3:34 AM
To: Steve Sakoman <[email protected]>
Cc: Smith, Grant [US] (MS) <[email protected]>; [email protected]; Ross Burton <[email protected]>
Subject: EXT :Re: [poky] CVE CHECK scorev3

On Fri, Oct 13, 2023 at 4:23 PM Steve Sakoman <[email protected]> wrote:
>
> On Wed, Oct 11, 2023 at 2:19 PM <[email protected]> wrote:
> >
> > All,
> >
> >
> >
> > In the poky layer (yocto-4.2.3 branch) I am using the built in cve-checker and running into an issue where it is unable to produce the scorev3 metric. All CVEs have a scorev3 equivalent to 0.0. When looking at poky (yocto-4.0.9 branch) I noticed that the cve-checker uses the 1.1 version of the NVD database and can successfully produce scorev3 when running a test build.
>
> You are using an old version of kirkstone (4.0.9), the current version 
> is 4.0.13.  The current version now uses the new version of the 
> cve-checker.  I just checked and the code is identical in kirkstone 
> and mickledore, with the exception of this commit which is required 
> for some older distros which are supported by kirkstone but not
> mickledore:
>
> https://git.yoctoproject.org/poky/commit/?h=kirkstone&id=cd1d34d5106c4
> 484372552bb3cf93198f7b25d76
>
> So kirkstone and mickledore should be producing identical results 
> (assuming the same recipe versions of course)
>
> Looking at a random sampling of json files though, I also see
> "scorev3": "0.0" in all of them.
>
> So I suspect that there is a bug, and it is present in all branches 
> (master, mickledore, kirkstone, dunfell)
>
> Steve


Hello,
I've looked into the current results of master and kirkstone and nothing unusual.
There are quite many entries with cvss3 at 0.0, but that's normal.

Steve, Grant, if you have situations with all cvss3 at 0.0, I will need your results file and the exact hash of the poky versions you use.

Kind regards,
Marta
cve-summary.json (application/octet-stream, 738.1 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.