diff options
author | Peter Marko <peter.marko@siemens.com> | 2025-03-28 16:51:07 +0100 |
---|---|---|
committer | Steve Sakoman <steve@sakoman.com> | 2025-04-01 09:02:41 -0700 |
commit | ccd6eee7fcc83b32278319c3526a13fe856a74bc (patch) | |
tree | e2169793776352d257c986a13ac8d1b025130d4f | |
parent | 0e7a9c67b9167b1f4895328240d4e346803265d4 (diff) | |
download | poky-ccd6eee7fcc83b32278319c3526a13fe856a74bc.tar.gz |
cve-update-nvd2-native: handle missing vulnStatus
There is a new CVE which is missing vulnStatus field:
https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-2682
This leads to:
File: '<snip>/poky/meta/recipes-core/meta/cve-update-nvd2-native.bb', lineno: 336, function: update_db
0332:
0333: accessVector = None
0334: vectorString = None
0335: cveId = elt['cve']['id']
*** 0336: if elt['cve']['vulnStatus'] == "Rejected":
0337: c = conn.cursor()
0338: c.execute("delete from PRODUCTS where ID = ?;", [cveId])
0339: c.execute("delete from NVD where ID = ?;", [cveId])
0340: c.close()
Exception: KeyError: 'vulnStatus'
(From OE-Core rev: 453c5c8d9031be2b3a25e2a04e0f5f6325ef7298)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
-rw-r--r-- | meta/recipes-core/meta/cve-update-nvd2-native.bb | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/meta/recipes-core/meta/cve-update-nvd2-native.bb b/meta/recipes-core/meta/cve-update-nvd2-native.bb index 5d0a7564aa..b8faee68d6 100644 --- a/meta/recipes-core/meta/cve-update-nvd2-native.bb +++ b/meta/recipes-core/meta/cve-update-nvd2-native.bb | |||
@@ -333,7 +333,7 @@ def update_db(conn, elt): | |||
333 | accessVector = None | 333 | accessVector = None |
334 | vectorString = None | 334 | vectorString = None |
335 | cveId = elt['cve']['id'] | 335 | cveId = elt['cve']['id'] |
336 | if elt['cve']['vulnStatus'] == "Rejected": | 336 | if elt['cve'].get('vulnStatus') == "Rejected": |
337 | c = conn.cursor() | 337 | c = conn.cursor() |
338 | c.execute("delete from PRODUCTS where ID = ?;", [cveId]) | 338 | c.execute("delete from PRODUCTS where ID = ?;", [cveId]) |
339 | c.execute("delete from NVD where ID = ?;", [cveId]) | 339 | c.execute("delete from NVD where ID = ?;", [cveId]) |