Skip to content

GHSA-qq97-vm5h-rrhg out-of sync. Why does it have different states? #224

Description

@mayrstefan

When analyzing aquasecurity/trivy#2034 I was surprised to find the advisory id GHSA-qq97-vm5h-rrhg in two different states:

  1. GHSA-qq97-vm5h-rrhg from the repo maintainers which seems to be the most up-to-date version, including the CVE number
  2. GHSA-qq97-vm5h-rrhg as a public Github Advisory which has not been updated

Because I did not find a machine readable format of the first one I have to ask:

  • is there any automation to keep the official advisories in-sync (bot for automated pull requests on updates)?
  • where is the official process documented?
  • one id, two links, different information: which one is expected to be used by the public? I guess the second one because the on mouse over preview has more details

Activity

  1. mayrstefan commented on Apr 26, 2022

    @mayrstefan
    Author

    Even more confusing: both links have a different security rating. Although https://nvd.nist.gov/vuln/detail/CVE-2021-41190 mentions Github with a low scoring we can find this id on Github with a medium scoring.

  2. ravage84 commented on Jan 17, 2023

    @ravage84

    @mayrstefan while I was researching a similar case, I came across this statement:

    Edits to global advisories will not change or affect how the advisory appears on the repository. For more information, see "Editing security advisories in the GitHub Advisory Database."

    https://github.com/proxy/docs.github.com/en/code-security/security-advisories/repository-security-advisories/publishing-a-repository-security-advisory

  3. Marcono1234 commented on Jun 18, 2023

    @Marcono1234
    Contributor

    This differentiation between Repository Advisory and Database Advisory which both have the exact same GHSA ID is really confusing. In #1136 (comment) it was mentioned:

    They can actually differ in content. The GitHub Security Lab Curation team reviews each and every advisory that makes it into the "reviewed" category on our system, and they'll sometimes add additional details or fix the spelling of a package name, etc. We don't want to force those changes on anyone's repository, so we let them update as they see fit.

    But as mentioned above in this issue, this difference in content is more likely to cause confusion than help anyone (?). And when you just write the name of an advisory, such as GHSA-qq97-vm5h-rrhg, GitHub seems to automatically add a link to the Database Advisory, making it even more unlikely that users will see the Repository Advisory.

    And to increase the confusion, when you write the URLs https://github.com/distribution/distribution/security/advisories/GHSA-qq97-vm5h-rrhg (Repository Advisory) and https://github.com/advisories/GHSA-qq97-vm5h-rrhg (Database Advisory) for example in a comment on an issue, the GitHub UI shows for both the link text GHSA-qq97-vm5h-rrhg.

    Here are some more negative examples in the context of withdrawn advisories:

    Repository Advisory (not withdrawn) Database Advisory (withdrawn)
    GHSA-9pgh-qqpf-7wqj GHSA-9pgh-qqpf-7wqj
    GHSA-cvx8-ppmc-78hm GHSA-cvx8-ppmc-78hm
    GHSA-mcwm-2wmc-6hv4 GHSA-mcwm-2wmc-6hv4
  4. mbauman commented on Sep 10, 2025

    @mbauman

    This is quite unexpected and causes challenges when incorporating repository GHSA IDs as aliases into other vulnerability datasets.

    It means that the advisory ID of "ghsa_id": "GHSA-qq97-vm5h-rrhg" as reported by GHSA-qq97-vm5h-rrhg is not really its ID! In most cases, repository GHSAs simply don't exist in the global advisory db and cannot be found without knowing its originating owner/repo, which is also challenging.

  5. Marcono1234 commented on Sep 10, 2025

    @Marcono1234
    Contributor

    In most cases, repository GHSAs simply don't exist in the global advisory db and cannot be found without knowing its originating owner/repo, which is also challenging.

    If I understand it correctly, https://github.com/advisories only shows entries from the Advisory DB, that is "global advisories", never repository advisories. As mentioned above, initially they might be identical though over time they can diverge.

    Also, at least for GHSA-qq97-vm5h-rrhg it says on the global advisory "Published on Feb 7, 2022 in distribution/distribution" and at the bottom in the timeline "milosgajdos published to distribution/distribution on Feb 7, 2022". So that is probably how you can find out if a corresponding repository advisory exists.

    (Edit: Changed my comment due to a misunderstanding by me.)

  6. mbauman commented on Sep 10, 2025

    @mbauman

    Yeah, my biggest challenge here is that any repository advisory that is not part of a supported ecosystem does not have a corresponding Global GHSA — even if it was reviewed by GitHub staff and assigned a CVE (cf. #3266).

    Therefore, GHSA-4g68-4pxg-mw93 (a Repository GHSA) is inaccessible from the global advisories REST endpoint of https://github.com/proxy/api.github.com/advisories/GHSA-4g68-4pxg-mw93. Interestingly, the plaintext of the ID (as written here) does auto-link to the repository! So there is some internal machinery here that is able to look up a GHSA and will link to either the global or repository advisory of that ID.

    But since I don't have public access to such a repository GHSA lookup API, I cannot directly use GHSA-4g68-4pxg-mw93 as an identifier directly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions