Skip to content

Version 0.6.0

Compare
Choose a tag to compare
@ra1nb0rn ra1nb0rn released this 04 Sep 18:15
· 30 commits to master since this release

Added

  • Integrated GitHub Security Advisory Database as data source.
  • Integrated VulnCheck's NVD++ with enhanced NVD information as data source.
  • Added very basic retrieval of NVD vulnerabilities via their vuln description text.
  • Add equivalent CPEs for Keycloak, NATS server and Nginx.
  • Equivalent CPEs are now also searched for via indirect connections (i.e. transitively).

Changed

  • Increased size of CVSS vectors in DB to accomodate longer CVSS 4.0 vectors.
  • The file structure was changed, such that the build code resides in its own directory.
  • Rejected CVEs without content are no longer stored in the local vuln DB.
  • Reworked C++ build code for NVD CVSS score to also accept secondary CVSS scores and CVSS 4.0.
  • Browsing the CPE dropdown in the web app now wraps around instead of staying fixed to beginning or end.

Fixed

  • Updated test cases.
  • Fixed processing of EoLD data and made it more resistant to formatting errors.