logoalt Hacker News

brewmarchetoday at 1:37 PM2 repliesview on HN

Yes, I’ve also experienced this kind of attitude. Some scanning tools can detect that certain CVEs do not apply because the specific functionality is not used.

I hope your team was OK with you uninstalling the VMware package manually (this is actually not a bad outcome if you don’t use that package)

There are also ridiculous CVEs like CVE-2018-20225 for pip, which will not get fixed as that behaviour is by design (but here as well it might be a good idea to strip pip if it’s not used)


Replies

roenxitoday at 2:17 PM

> An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index.

https://nvd.nist.gov/vuln/detail/cve-2018-20225

Because I'm sure the public wants to know.

show 1 reply
dataflowtoday at 3:58 PM

I don't understand what's ridiculous about that pip CVE, could you explain? Just because something is by design that doesn't mean it's not a vulnerability or somehow unexploitable.

show 1 reply