project-kb
project-kb copied to clipboard
It is impossible to specify an open-ended version interval
For example, CVE-2021-27582 states that version 1.3.3 is vulnerable, but that is the last available. In this case, the commit interval should be left "open" to the right (that is, find all commits after the tag corresponding to 1.3.3 until today).
This CVE would be rather easy to solve, if it weren't for this shortcoming of the current CLI, since the "right" commit is listed right in the advisory page!
Once merged this branch it can be closed