Skip to content

Visibility of curl CVEs without Git ranges #1926

@jess-lowe

Description

@jess-lowe

Some of the older curl vulnerabilities have nothing to distinguish their 'package' or ecosystem so aren't being categorized and therefore shown on osv.dev. Despite CVE-2016-8616 existing in datastore, it is not visible on the website.

image

Possible fixes could include some sort of "reverse git enumeration" where we look up commits from tags (instead of the tags from commits we currently do)

Metadata

Metadata

Assignees

No one assigned

    Labels

    backlogImportant but currently unprioritizeddata qualityIssues with data quality

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions