Skip to content

Should the apache_httpd importer include data re fixed versions from httpd.apache.org/security/ HTML files? #1019

Description

@johnmhoran

Exploring the json URL we currently use in the apache_httpd.py fetch_links() function (https://httpd.apache.org/security/json/), if I navigate up 1 step to https://httpd.apache.org/security/, I see that https://httpd.apache.org/security/ contains links to 4 HTML files (listed below), each of which contains information re which CVEs are fixed in which versions of Apache HTTP Server.

Do we want to fetch, analyze and include this information in the fixed_version field of the affected_packages list for each advisory/CVE?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions