Bug 15242 - Description/CVSS not shown in details for some entries
Summary: Description/CVSS not shown in details for some entries
Status: RESOLVED FIXED
Alias: None
Product: Security Response Tool
Classification: Yocto Project Subprojects
Component: General (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium normal
Target Milestone: 5.0
Assignee: David Reyna
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2023-10-19 10:43 UTC by Marta Rybczynska
Modified: 2023-10-21 06:28 UTC (History)
0 users

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marta Rybczynska 2023-10-19 10:43:49 UTC
Using aab3d2492

For some entries, the description is shown on the Triage page, but not when entering that CVE. When that happens, CVSS isn't shown either.

Links to advisories are there.

Examples of affected CVES:
CVE-2022-22375
CVE-2022-22380
Comment 1 David Reyna 2023-10-19 15:37:03 UTC
The CVEs page shows the original captured summary data, per the CVE table.

The CVE detail page attempts to fetch the full record from the respective downloaded source archive (JSON) so that it can also fill in content like the CPEs and references.

There must be a read problem extracting the indicated CVE records.
Comment 2 David Reyna 2023-10-21 06:28:33 UTC
It turns out that these CVEs haddescription fields with embedded leading blank lines, and that as breaking the parsing and transfer of that text to the SRTool CVE details page.