summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorPeter Marko <peter.marko@siemens.com>2025-03-28 16:51:07 +0100
committerSteve Sakoman <steve@sakoman.com>2025-04-01 09:02:41 -0700
commitccd6eee7fcc83b32278319c3526a13fe856a74bc (patch)
treee2169793776352d257c986a13ac8d1b025130d4f
parent0e7a9c67b9167b1f4895328240d4e346803265d4 (diff)
downloadpoky-ccd6eee7fcc83b32278319c3526a13fe856a74bc.tar.gz
cve-update-nvd2-native: handle missing vulnStatus
There is a new CVE which is missing vulnStatus field: https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-2682 This leads to: File: '<snip>/poky/meta/recipes-core/meta/cve-update-nvd2-native.bb', lineno: 336, function: update_db 0332: 0333: accessVector = None 0334: vectorString = None 0335: cveId = elt['cve']['id'] *** 0336: if elt['cve']['vulnStatus'] == "Rejected": 0337: c = conn.cursor() 0338: c.execute("delete from PRODUCTS where ID = ?;", [cveId]) 0339: c.execute("delete from NVD where ID = ?;", [cveId]) 0340: c.close() Exception: KeyError: 'vulnStatus' (From OE-Core rev: 453c5c8d9031be2b3a25e2a04e0f5f6325ef7298) Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
-rw-r--r--meta/recipes-core/meta/cve-update-nvd2-native.bb2
1 files changed, 1 insertions, 1 deletions
diff --git a/meta/recipes-core/meta/cve-update-nvd2-native.bb b/meta/recipes-core/meta/cve-update-nvd2-native.bb
index 5d0a7564aa..b8faee68d6 100644
--- a/meta/recipes-core/meta/cve-update-nvd2-native.bb
+++ b/meta/recipes-core/meta/cve-update-nvd2-native.bb
@@ -333,7 +333,7 @@ def update_db(conn, elt):
333 accessVector = None 333 accessVector = None
334 vectorString = None 334 vectorString = None
335 cveId = elt['cve']['id'] 335 cveId = elt['cve']['id']
336 if elt['cve']['vulnStatus'] == "Rejected": 336 if elt['cve'].get('vulnStatus') == "Rejected":
337 c = conn.cursor() 337 c = conn.cursor()
338 c.execute("delete from PRODUCTS where ID = ?;", [cveId]) 338 c.execute("delete from PRODUCTS where ID = ?;", [cveId])
339 c.execute("delete from NVD where ID = ?;", [cveId]) 339 c.execute("delete from NVD where ID = ?;", [cveId])