Skip to content

Clarify apache_httpd importer references and severities #1006

Description

@johnmhoran

The Apache HTTP Server advisories are published as a series of JSON files, one advisory per file. The most recent, for example, is https://httpd.apache.org/security/json/CVE-2022-31813.json. This excerpt shows the potential reference and severity data:

{
  "data_type": "CVE",
  "data_format": "MITRE",
  "data_version": "4.0",
  "generator": {
    "engine": "Vulnogram 0.0.9"
  },
  "CVE_data_meta": {
    "ID": "CVE-2022-31813",
    "ASSIGNER": "security@apache.org",
    "DATE_PUBLIC": "",
    "TITLE": "mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism",
    "AKA": "",
    "STATE": "REVIEW"
  },
  
  . . .
  
  "references": {
    "reference_data": [
      {
        "refsource": "CONFIRM",
        "url": "",
        "name": ""
      }
    ]
  },
  "configuration": [],
  "impact": [
    {
      "other": "low"
    }
  ],
  
  . . .
  
}

My understanding is that without a reference URL we cannot report the low severity value.

  • One potential solution is to use the JSON file URL as the reference URL, which the current apache_httpd.py already effectively does by reconstructing that URL with the ["CVE_data_meta"]["ID"] value.

  • However, even if that's the right approach, this does not look like a valid reference:

  "references": {
    "reference_data": [
      {
        "refsource": "CONFIRM",
        "url": "",
        "name": ""
      }
    ]
  },
  • In that case (or when the entry is simply "references": {},), what does our JSON reference entry look like, and does this affect our reporting the low severity value? Is this the desired result?
    "references": [
        {
        "reference_id": "CVE-2022-31813",
        "url": "https://httpd.apache.org/security/json/CVE-2022-31813.json",
        "severities": [
            {
            "system": "apache_httpd",
            "value": "low"
            }
        ]
        }
    ],

And one question re version/versionrange:

The current code uses SemverVersion and VersionRange; for postgresql.py we're using GenericVersion and GenericVersionRange; and perhaps we might even want to create a univers version scheme for apache_httpd. What factors do we consider in making this choice? The relevant JSON data from the advisory we've been discussing, for example, is

                "version": {
                  "version_data": [
                    {
                      "version_name": "Apache HTTP Server 2.4",
                      "version_affected": "<=",
                      "version_value": "2.4.53",
                      "platform": ""
                    }
                  ]
                }

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions