Bug 15242

Summary: Description/CVSS not shown in details for some entries
Product: [Yocto Project Subprojects] Security Response Tool Reporter: Marta Rybczynska <rybczynska>
Component: GeneralAssignee: David Reyna <david.reyna>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium    
Version: unspecified   
Target Milestone: 5.0   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Marta Rybczynska 2023-10-19 10:43:49 UTC
Using aab3d2492

For some entries, the description is shown on the Triage page, but not when entering that CVE. When that happens, CVSS isn't shown either.

Links to advisories are there.

Examples of affected CVES:
CVE-2022-22375
CVE-2022-22380
Comment 1 David Reyna 2023-10-19 15:37:03 UTC
The CVEs page shows the original captured summary data, per the CVE table.

The CVE detail page attempts to fetch the full record from the respective downloaded source archive (JSON) so that it can also fill in content like the CPEs and references.

There must be a read problem extracting the indicated CVE records.
Comment 2 David Reyna 2023-10-21 06:28:33 UTC
It turns out that these CVEs haddescription fields with embedded leading blank lines, and that as breaking the parsing and transfer of that text to the SRTool CVE details page.