]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commit
cve-update-nvd2-native: handle missing vulnStatus
authorPeter Marko <peter.marko@siemens.com>
Fri, 28 Mar 2025 15:47:12 +0000 (16:47 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 28 Mar 2025 22:07:03 +0000 (22:07 +0000)
commit1508a97b175ccfc52a7ab64cbb4c9ce33d12bcb3
tree164bcda5902ff404079e5acdf9ab59416f28cbf9
parent8ce06538c9cde0f09909a5a2e61ec10b0d35df49
cve-update-nvd2-native: handle missing vulnStatus

There is a new CVE which is missing vulnStatus field:
https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-2682

This leads to:
File: '<snip>/poky/meta/recipes-core/meta/cve-update-nvd2-native.bb', lineno: 336, function: update_db
     0332:
     0333:    accessVector = None
     0334:    vectorString = None
     0335:    cveId = elt['cve']['id']
 *** 0336:    if elt['cve']['vulnStatus'] ==  "Rejected":
     0337:        c = conn.cursor()
     0338:        c.execute("delete from PRODUCTS where ID = ?;", [cveId])
     0339:        c.execute("delete from NVD where ID = ?;", [cveId])
     0340:        c.close()
Exception: KeyError: 'vulnStatus'

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-core/meta/cve-update-nvd2-native.bb