Skip to content

POST /cve/:id/reject deletes some properties #2029

Description

@ElectricNroff

Sending this:

{"cnaContainer": {
    "rejectedReasons": [ {"lang": "en", "value": "for testing"}],
    "x_myProperty": true}}

to the POST /cve/:id/reject endpoint results in a 200 HTTP response code and a new record in the REJECTED state; however, x_myProperty is not in that record. By contrast, sending that same container to the PUT /cve/:id/reject endpoint afterward adds "x_myProperty": true to that record. This seems confusing in that one would expect idempotent behavior for POST then PUT of the same content. This affects cveawg-test.mitre.org today and may also affect older server versions. The CVE Record Format schema indicates that x_ properties are valid in the REJECTED state, and POST /cve/:id/reject should allow the caller to produce any valid document in that state. Also, the validation library (validateRejectedCveCnaContainer) indicates that including x_myProperty is valid:

{
  "valid": true,
  "error": null,
  "message": "SUCCESSFUL CVE JSON schema and rules validation.",
  "details": null,
  "warnings": []
}

https://github.com/CVEProject/cve-schema/blob/5533f6038cc0434e544e69240c704906d591de46/schema/CVE_Record_Format.json#L712-L718

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions