fleet/server/vulnerabilities
Ian Littman 49300bc844
Don't panic on zero-length NVD description_data array fields (#21250)
#21242

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

<!-- Note that API documentation changes are now addressed by the
product design team. -->

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Committing-Changes.md#changes-files)
for more information.
- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements)

QA'd manually (see repro scenario in the linked bug). Happy to dig into
adding tests here if it's worth the time to build them now that the
upstream data feed has been patchd.
2024-08-14 10:53:47 -05:00
..
customcve Custom Vulnerability Matching (#20118) 2024-07-09 11:50:22 -06:00
io Moving Go integration tests to integration test job (#21126) 2024-08-07 14:00:25 +02:00
macoffice Moving Go integration tests to integration test job (#21126) 2024-08-07 14:00:25 +02:00
msrc Update Windows OS Version Reporting (#17682) 2024-05-01 12:02:16 -06:00
nvd Don't panic on zero-length NVD description_data array fields (#21250) 2024-08-14 10:53:47 -05:00
oval Custom Vulnerability Matching (#20118) 2024-07-09 11:50:22 -06:00
testdata Handle flaky vulnerability tests (#11262) 2023-04-21 19:37:29 -04:00
utils friday tidy up party (#18106) 2024-04-08 08:42:42 -03:00