<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>15242</bug_id>
          
          <creation_ts>2023-10-19 10:43:49 +0000</creation_ts>
          <short_desc>Description/CVSS not shown in details for some entries</short_desc>
          <delta_ts>2023-10-21 06:28:33 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>6</classification_id>
          <classification>Yocto Project Subprojects</classification>
          <product>Security Response Tool</product>
          <component>General</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>5.0</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Marta Rybczynska">rybczynska</reporter>
          <assigned_to name="David Reyna">david.reyna</assigned_to>
          
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>96729</commentid>
    <comment_count>0</comment_count>
    <who name="Marta Rybczynska">rybczynska</who>
    <bug_when>2023-10-19 10:43:49 +0000</bug_when>
    <thetext>Using aab3d2492

For some entries, the description is shown on the Triage page, but not when entering that CVE. When that happens, CVSS isn&apos;t shown either.

Links to advisories are there.

Examples of affected CVES:
CVE-2022-22375
CVE-2022-22380</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>96748</commentid>
    <comment_count>1</comment_count>
    <who name="David Reyna">david.reyna</who>
    <bug_when>2023-10-19 15:37:03 +0000</bug_when>
    <thetext>The CVEs page shows the original captured summary data, per the CVE table.

The CVE detail page attempts to fetch the full record from the respective downloaded source archive (JSON) so that it can also fill in content like the CPEs and references.

There must be a read problem extracting the indicated CVE records.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>96762</commentid>
    <comment_count>2</comment_count>
    <who name="David Reyna">david.reyna</who>
    <bug_when>2023-10-21 06:28:33 +0000</bug_when>
    <thetext>It turns out that these CVEs haddescription fields with embedded leading blank lines, and that as breaking the parsing and transfer of that text to the SRTool CVE details page.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>