Skip to content

telemetry: Wrong CVE CVE-2021-29937 reported for openbmc telemetry project #4058

@MarcinDigitic

Description

@MarcinDigitic

Issue CVE-2021-29937 is reported by cve_check for telemetry project from openbmc github. However, the issue is valid for telemetry rust project and not telemetry from openbmc.
Checked with openbmc project: https://github.com/openbmc/openbmc
Telemetry project: meta-phosphor/recipes-phosphor/telemetry/telemetry_git.bb

Consider adding such line to the telemetry_git.bb file:

# CVE-2021-29937: Not applicable to openbmc telemetry project
CVE_STATUS[CVE-2021-29937] = "cpe-incorrect: Issue only affects telemetry rust project and not the openbmc telemetry project"

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions