Skip to content

vulnfeeds dynamic vendor product repo caching causing false hits #4865

@jheider-sit

Description

@jheider-sit

The CVE ID
https://osv.dev/vulnerability/CVE-2021-38946

Describe the data quality issue observed
CVE-2021-38946 is currently associated in OSV with: github.com/highcharts/highcharts

However, according to the official CVE record and the National Vulnerability Database, this CVE affects IBM Cognos Analytics (XSS vulnerability), not Highcharts.

There are no vendor advisories, GitHub Security Advisories, or Highcharts security notices linking this CVE to the Highcharts repository.

Suggested changes to record
Remove the affected packages pointing to highchart or provide information in summary how highchart is related to this CVE.

Sub-issues

Metadata

Metadata

Assignees

Labels

data qualityIssues with data quality

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions