Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Need to identify and flag REJECTED CVEs #1221

Closed
mjherzog opened this issue Jul 4, 2023 · 1 comment
Closed

Need to identify and flag REJECTED CVEs #1221

mjherzog opened this issue Jul 4, 2023 · 1 comment

Comments

@mjherzog
Copy link
Member

mjherzog commented Jul 4, 2023

For the purls:

  • pkg:maven/com.fasterxml.woodstox/woodstox-core@5.3.0
  • pkg:maven/com.fasterxml.woodstox/woodstox-core@6.2.4

There are 4 REJECTED CVEs in the NVD:

  • 2022-40153
  • 2022-40154
  • 2022-40155
  • 2022-40156

For the purl: pkg:maven/com.thoughtworks.xstream/xstream@1.4.20 there are 2 REJECTED CVEs:

  • 2022-40153
  • 2022-40156

The real CVE for this vuln is 2022-40152

The NVD page for each REJECTED CVE says:

Rejected
CVE has been marked "REJECT" in the CVE List. These CVEs are stored in the NVD, but do not show up in search results.
Current Description
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.

I found these cases from reviewing a VCIO report for a product so the cases are incidental.

We need to identify and flag REJECT CVEs. I am not sure how to report these cases or how common they are.
A first solution step should be to investigate how common REJECT CVEs are in the NVD.

@TG1999
Copy link
Contributor

TG1999 commented Nov 15, 2023

Done in #1232

@TG1999 TG1999 closed this as completed Nov 20, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants