Bug 15382 - CVE detail page crash for certain CVE values
Summary: CVE detail page crash for certain CVE values
Status: RESOLVED FIXED
Alias: None
Product: Security Response Tool
Classification: Yocto Project Subprojects
Component: General (show other bugs)
Version: 5.0
Hardware: x86 Multiple
: Medium+ normal
Target Milestone: 5.0
Assignee: David Reyna
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2024-02-03 11:22 UTC by David Reyna
Modified: 2024-02-03 11:26 UTC (History)
0 users

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description David Reyna 2024-02-03 11:22:16 UTC
When looking up the details for certain CVEs (e.g. CVE-2024-23180), the page load fails with the error: 

   TemplateSyntaxError at /srtgui/cve/CVE-2020-17533
with the error in In template /home/ubuntu/srtool/lib/srtgui/templates/cve-nist.html, error at line 158 with unkwn variable ref.1 or ref.2.
Comment 1 David Reyna 2024-02-03 11:26:44 UTC
FYI, The issue was the combination of a CVE reference with an empty "refsource" value combined with a "strip()" action when this data is passed from the backaend scripts up to the GUI, which resulted in an unexpected truncated record.