Closed (fixed)
Project:
Drupal Security Team
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
20 Nov 2025 at 15:51 UTC
Updated:
10 Feb 2026 at 23:19 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
gregglesThanks for filing this issue and posting the proposed json.
Could you share an "interdiff" from the original file compared to this one? I've found that formatting issues and the vulnrichment data can make it hard to compare the data.
Currently we take the version info from the advisory and pass that along. If we need to add more versions to it then I guess we could add that info to the json and merge it on the end of the version we get from the advisory? I'm not sure I love that solution, but we should sort it out.
Comment #3
dorficus commentedSure thing. Here is the interdiff as requested
Comment #4
dorficus commentedBringing this back around before 2 week close
Comment #5
dorficus commentedComment #6
gregglesI think this is still needs work for this part:
Comment #7
dorficus commented@greggles I'm not sure I understand what the ask there is. I've put the json provided into vulnogram and it rendered correctly, although I did adjust the location of the D7 version to above 8 just so it was in numerical order.
Is there something that I missed, and if so, how would I go about correcting it? I definitely want to make sure I'm going about this the right way and would appreciate any advice/guidance on this.
Comment #8
aangel commentedLooking at the conversation so far, let me see if I get the gist.
If I've got that right, is the answer:
1. Merge it manually for now to unblock this
2. Submit a ticket to alter the pipeline for future instances
Or, we could just do #2 and make this issue the test case. (I can take this on if we like that approach.)
Comment #9
gregglesOn reconsidering this, I think my concern and proposed solution from #2 is not quite right. I'd been thinking of the script that generates the CVE json as the source of truth. However, the vulnrichment program makes its own adjustments so...the only source of truth is the MITRE CVE database.
I've now made the change proposed here - please double check if you can and let me know any oversights.
Comment #11
aangel commentedThanks for this, greggles...small version number fix needed.
JD asked for "through 7.103" but the CVE now says "affected from 7.0 before 7.103."
Would you mind submitting that change? Thank you!
Comment #12
gregglesGood call - I think it's fixed now (caching can vary depending on your source).
Comment #14
aangel commentedThanks for the help with this greggles. And I just noticed that the contribution record lists me as volunteering.
My work on these issues is actually under HeroDevs. No need to go back and fix things but if you were able to put this work on behalf of HD (just like JD), we would appreciate that.
Please let me know if you need anything from me to make that happen as I don't have perfect knowledge of the credit system.
Thanks again!
Comment #15
gregglesHi aangel - As a project maintainer for this project I can add credit to people. Then you as the individual manage credit to volunteering or the right company for each issue. At least...I think that's how it works. If you can't figure it out I'm happy to keep digging and try to find where/ how that attribution is controlled.
Comment #16
aangel commentedI think that's how it works....if the assignment process doesn't include the company as an option you can set then it's up to me to ensure the attribution is correct, which I can do.
I've updated the record here. Thanks.