Public date and copyright year missing for CVE-2020-1945 in OVAL
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ubuntu CVE Tracker |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
I have previously filed a similar bug:
https:/
When reading the OVAL file, the public_date tag contains "unknown", and the rights tag says "Copyright (C) unknown Canonical Ltd.". Maybe another test for you to add :)
Here's the definition from the OVAL file.
```
<definition class="
<metadata>
read sensitive information leaked into /tmp, or potentially inject malicious code into a project that is built with Apache Ant.</description>
<affected family="unix">
</affected>
<reference source="CVE" ref_id=
<advisory>
<ref>http://
</advisory>
</metadata>
<criteria>
<criterion test_ref=
</criteria>
</definition>
```
From https:/
Kind regards.
Thanks for reporting this - I have updated this in the Ubuntu CVE Tracker via https:/ /git.launchpad. net/ubuntu- cve-tracker/ commit/ ?id=91f4418c846 74ff86b8aeb96af 5fbdf6fa27629f and so the OVAL should be regenerated soon with this new date. FYI - I took the date from the public announcement in https:/ /lists. apache. org/thread. html/r8e592bbfc 016a5dbe2a8c0e8 1ff99682b9c78c4 53621b82c14e7b7 5e%40%3Cdev. ant.apache. org%3E