fix issue with duplicate vulns detected using nvd (#8613)

The OVAL analyzer falsely assumes that any vulnerabilities detected on a
host only come from OVAL. However, it is possible that NVD detects
vulnerabilities on these hosts even though it excludes software from
deb_packages and rpm_packages. For example, a python package twisted
v22.20 has a vulnerability CVE-2022-39348 detected by NVD. The OVAL
analyzer would delete this vulnerability, and it would be re-inserted by
the NVD scanner on the next run. This creates a loop.

The fix is to only delete vulnerabilities that are actually detected
using OVAL. We already store this in the source column in the
software_cve table.
This commit is contained in:
Michal Nicpon
2022-11-10 10:28:00 -07:00
committed by GitHub
parent ff969e8ddc
commit 9ad1721efd
9 changed files with 235 additions and 43 deletions
+2
View File
@@ -0,0 +1,2 @@
* Fixed a bug where duplicate vulnerability webhook requests, jira, and zendesk tickets were being made when scanning for vulnerabilities.
This affected ubuntu and redhat hosts that support OVAL vulnerability detection.