Repository navigation
fix: add NetScaler security bulletins and stop false positives from CVE-record build bounds - #84
Merged
Merged
Conversation
… plain versions NetScaler's CVE record ranges give a release branch and a build separately (version "14.1", lessThan "56.73", versionType "patch"). They were read as 14.1.0 up to 56.73.0, which covers every later build of the branch, so fixed builds such as 14.1-56.73 and 14.1-60.52 were reported as affected. Drop these ranges in the CNA fetcher and add a migration that removes the rows already stored. Until the dedicated NetScaler advisory source lands, affected NetScaler builds are not reported from CVE records.
Read the NetScaler ADC / Gateway / Console security bulletins of 2022 and
later from support.citrix.com over plain HTTP (about 20 pages, daily at
16:45 UTC) and store one advisory per CVE with the first fixed build of each
release branch.
- A NetScaler version is a branch and a build ("14.1-73.32"). It gets its own
ordering (citrix-version.ts), since the generic encoding keeps only the 73
of 73.32.
- FIPS / NDcPP builds run on their own numbering and are a separate product.
- A branch the bulletin calls end of life and vulnerable is stored as
out_of_support. Lines under a "CVE-x:" heading or "affected by CVE-x"
apply to that CVE only, including a single affected build.
- A fixed build written with a dot ("12.1.65.21") is read as 12.1-65.21.
- Product aliases map NetScaler / Citrix names and the NVD CPE tokens to the
stored names.
1 of 2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
NetScaler CVE records give a release branch and a build separately (
version: "14.1",lessThan: "56.73",versionType: "patch"). The CNA fetcher read this as 14.1.0 up to 56.73.0, which covers every later build of the branch, so fixed builds (for example 14.1-56.73 and 14.1-60.52 for CVE-2025-12101) were reported as affected.Changes
netscalerBuildBound). A migration (migrate:remove-netscaler-cna-build-ranges) deletes the 102 rows already stored. Until the advisory source below runs, affected NetScaler builds are not reported from CVE records.advisory-citrix, daily 16:45 UTC, about 20 pages over plain HTTP, no browser): reads the ADC / Gateway / Console security bulletins of 2022 and later from support.citrix.com and stores one advisory per CVE with the first fixed build of each release branch.14.1-73.32) and gets its own ordering (citrix-version.ts).out_of_support.CVE-x:heading or "affected by CVE-x" apply to that CVE only, including a single affected build (CVE-2026-4368).12.1.65.21) is read as12.1-65.21.Scope limits
Bulletins before 2022 (for example CVE-2019-19781), other Citrix products (Workspace app, StoreFront, XenServer, SD-WAN) and CVEs whose bulletin is not published yet are not covered. Documented in known issues.
Test plan
vitest(702 tests),tsc --noEmit,eslint srcfixedVersion; the CitrixBleed (CVE-2023-4966) boundary is correctpnpm import:citrixonce instead of waiting for the 16:45 job