Bug 15382

Summary: CVE detail page crash for certain CVE values
Product: [Yocto Project Subprojects] Security Response Tool Reporter: David Reyna <david.reyna>
Component: GeneralAssignee: David Reyna <david.reyna>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium+    
Version: 5.0   
Target Milestone: 5.0   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description David Reyna 2024-02-03 11:22:16 UTC
When looking up the details for certain CVEs (e.g. CVE-2024-23180), the page load fails with the error: 

   TemplateSyntaxError at /srtgui/cve/CVE-2020-17533
with the error in In template /home/ubuntu/srtool/lib/srtgui/templates/cve-nist.html, error at line 158 with unkwn variable ref.1 or ref.2.
Comment 1 David Reyna 2024-02-03 11:26:44 UTC
FYI, The issue was the combination of a CVE reference with an empty "refsource" value combined with a "strip()" action when this data is passed from the backaend scripts up to the GUI, which resulted in an unexpected truncated record.