Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    How to change affected version range in Vulnerablity Assessment?

    Scheduled Pinned Locked Moved Support
    3 Posts 2 Posters 7 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I Offline
      itadmin_9894
      last edited by

      Hello

      Is there a way to change the range of affected package versions in a vulnerability assessment? Background: for the nuget package bootstrap the vulnerability CVE-2024-6531 is assessed for a wide range of versions, namely 4.5.3, 5.2.3, 3.0.0, 3.3.7, 4.6.1, 3.3.0, 3.4.1, 5.3.3, 3.3.2, 5.3.2, 4.3.1 (see screenshot). But the versions 5.3.2 and 5.3.3 are not affected by this vulnerability. I would like to exclude these versions, but don't know how?

      30456801-c30d-47d9-90df-ed1c73000cfc-image.png

      We use ProGet Basic in the Version 2023.18 (Build 15).

      Thank you for any feedback.

      atrippA 1 Reply Last reply Reply Quote 0
      • atrippA Offline
        atripp inedo-engineer @itadmin_9894
        last edited by

        Hi @itadmin_9894 ,

        It's not possible to edit vulnerability records, as they are updated/source from outside of your ProGet software.

        You're also using an older version of ProGet that sources data from OSS Index. That database is generally unreliable and outdated, so if you're concerned about vulnerabilities you should definitely upgrade:
        https://docs.inedo.com/docs/proget/installation/proget-old-versions-migration/proget-compliance-ossindex

        It looks like the similar/equivalent is here:
        https://security.inedo.com/vulnerability/details/PGV-245118T

        Cheers,
        Alana

        I 1 Reply Last reply Reply Quote 0
        • I Offline
          itadmin_9894 @atripp
          last edited by

          Hi @atripp ,

          Thank you for your quick reply. We will try your suggested approach and migrate from OSS Index to ProGet's Vulnerability Database. We will also update our server installation.

          There are other libraries with the same issue, so your statement regarding the reliability of OSS Index as a data source seems to be accurate.

          Best regards

          1 Reply Last reply Reply Quote 0

          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

          With your input, this post could be even better 💗

          Register Login
          • 1 / 1
          • First post
            Last post
          Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation