Do you want to work on this issue?
You can request for a bounty in order to promote it!
Vuls/VulsRepo reporting vulnerabilities that are not on the machine #1473
CA-dfox posted onGitHub
What did you do? (required. The issue will be closed when not provided.)
go-cve-dictionary fetch nvd
goval-dictionary fetch debian 7 8 9 10 11
goval-dictionary fetch ubuntu 14 16 18 19 20 21 22
goval-dictionary fetch redhat 5 6 7 8
gost fetch redhat
gost fetch debian
gost fetch ubuntu
vuls scan -config=/usr/share/vuls-data/kitchensink.config
vuls report -config=/usr/share/vuls-data/kitchensink.config -ignore-unfixed
What did you expect to happen?
Since the machine was completely updated, I would have expected all fixed vulnerabilities to not show up on the VulsRepo table or Vuls Tui.
What happened instead?
I am seeing CVEs that are not applicable show up in the VulsRepo table and in Vuls Tui. For example, I am seeing the following CVEs in the report: CVE-2016-7969, CVE-2017-9258 and CVE-2017-13194. When I try the fix for these, I get the following:
username@machinename:~$ sudo ua fix CVE-2017-13194
CVE-2017-13194: libvpx vulnerabilities
No affected source packages are installed.
✔ CVE-2017-13194 does not affect your system
- Current Output
Please re-run the command using -debug
and provide the output below.
Steps to reproduce the behaviour
See above. In VulsRepo, I am filtering on fixed CVEs.
Configuration (MUST fill this out):
- Go version (
go version
):go version go1.17 linux/amd64
- Go environment (
go env
):GO111MODULE="" GOARCH="amd64" GOBIN="" _GOCACHE="/home/username/.cache/go-build"_ GOENV="/home/username/.config/go/env" GOEXE="" GOEXPERIMENT="" GOFLAGS="" GOHOSTARCH="amd64" GOHOSTOS="linux" GOINSECURE="" GOMODCACHE="/home/username/go/pkg/mod" GONOPROXY="" GONOSUMDB="" GOOS="linux" GOPATH="/home/username/go" GOPRIVATE="" GOPROXY=",direct" GOROOT="/usr/lib/go-1.17" GOSUMDB="" GOTMPDIR="" GOTOOLDIR="/usr/lib/go-1.17/pkg/tool/linux_amd64" GOVCS="" GOVERSION="go1.17" GCCGO="gccgo" AR="ar" CC="gcc" CXX="g++" CGO_ENABLED="1" GOMOD="/dev/null" CGO_CFLAGS="-g -O2" CGO_CPPFLAGS="" CGO_CXXFLAGS="-g -O2" CGO_FFLAGS="-g -O2" CGO_LDFLAGS="-g -O2" PKG_CONFIG="pkg-config" GOGCCFLAGS="-fPIC -m64 -pthread -fmessage-length=0 -fdebug-prefix-map=/tmp/go-build2283081390=/tmp/go-build -gno-record-gcc-switches"
- Vuls environment:
Hash : vuls-v0.19.7-build-20220429_134618_91ed318
To check the commit hash of HEAD $ vuls -v
$ cd $GOPATH/src/ $ git rev-parse --short HEAD
- config.toml:
#[servers.] #host = "" #port = "22" #user = "user" #sshConfigPath = "/home/username/.ssh/config" #keyPath = "/home/username/.ssh/id_rsa" #scanMode = ["fast", "fast-root", "deep", "offline"] #scanModules = ["ospkg", "wordpress", "lockfile", "port"] #type = "pseudo" #memo = "systemname" #findLock = true #lockfiles = ["/path/to/package-lock.json"] #cpeNames = [ "cpe:/a:rubyonrails:ruby_on_rails:4.2.1" ] #owaspDCXMLPath = "/path/to/dependency-check-report.xml" #ignoreCves = ["CVE-2014-0160"] #containersOnly = false #containerType = "docker" #or "lxd" or "lxc" default: docker #containersIncluded = ["${running}"] #containersExcluded = ["container_name_a"] #confidenceScoreOver = 80