| Summary: | NIST import not working | ||
|---|---|---|---|
| Product: | [Yocto Project Subprojects] Security Response Tool | Reporter: | Ross Burton <ross.burton> |
| Component: | General | Assignee: | David Reyna <david.reyna> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Medium | ||
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Ross Burton
2018-11-09 12:48:42 UTC
Remove UTC offset to avoid timezone/day light savings errors. $ ./bin/srtool_nist.py -n --source="NIST 2018" --file=data/nvdcve-1.0-2018.json --url-file=nvdcve-1.0-2018.json.gz --url-meta=nvdcve-1.0-2018.meta BEGINNING NIST UPDATES PLEASE WAIT ... this can take some time [ 99] CVE-2018-9999 DATABASE UPDATE FINISHED Just discovered this in the NIST description field for new CVEs:
ERROR(1):b'Traceback (most recent call last):
File "bin/srtool_nist.py", line 695, in <module>
main(sys.argv[1:])
File "bin/srtool_nist.py", line 643, in main
fetch_cve(args.cve_detail,args.cve_file)
File "bin/srtool_nist.py", line 594, in fetch_cve
summary[\'cpe_list\'] += nist_scan_configuration_or(config, cve_name, 0)\n File "bin/srtool_nist.py", line 606, in nist_scan_configuration_or
for cpe in cpe_or_node[\'cpe\']:\nKeyError: \'cpe\''
NIST is its wisdom has added or replaced the "cpe" sub-table with "cpe-match" in the 2018 tables. The 2015 sub-table still uses "cpe". The updated code now accepts both table names when scanning CPE entries. Confirmed fixed. |