Fix 6 wrong CPE identities, a duplicate WebLogic rule and ProgressBar.js's detection - #511
Merged
Merged
Conversation
….js's detection NVD files these products' CVEs under a different identity than the rule's cpe carries: - Angular: angularjs:angular is AngularJS (15 names, 0 CVEs); Angular's 24 CVEs are under angular:angular - jQuery UI: jquery:jquery_ui has 0 CVEs; jqueryui:jquery_ui has 7, including CVE-2021-41182/41183/41184 and CVE-2022-31160 - Kentico CMS: kentico:kentico_cms has 3 CVEs on old releases (5.5 R2, 8.2); current Kentico (Xperience) CVEs are under kentico:xperience - Plesk: parallels:parallels_plesk_panel is the pre-2017 Parallels-era product, with no CVE on a current release; plesk:plesk has today's CVEs - ProfilePress: profilepress:profilepress has 0 CVEs; properfraction:profilepress has 35, including 4 CRITICAL Transifex's cpe (transifex:transifex) names the old desktop app, versions 0.1-0.10; this rule reads Transifex Live's JavaScript widget, which NVD does not list a product for. Dropped rather than left pointing at the wrong product. "Oracle WebLogic Server" has no patterns of its own, is reached only through Oracle Dynamic Monitoring Service's implies, and carries BEA's pre-Oracle identity (bea:weblogic_server: 130 names up to 10.0, none of its 150 CVEs on a current release). "Weblogic Server" detects the real Server header and had no cpe. Folded the duplicate into it and added its correct identity, oracle:weblogic_server (354 CVEs). ProgressBar.js matched any progressbar(.min).js and read ?ver=, so a site running WordPress's bundled jQuery UI progressbar widget (served at that same file name) was detected as ProgressBar.js under jQuery UI's version numbers. The patterns now require the package's own cdnjs, npm-CDN or dist paths.
enthec-opensource
pushed a commit
that referenced
this pull request
Sep 16, 2026
…ever carried These rules detect a real product with a real NVD identity, but have never had a cpe at all, so no CVE data was ever reachable for them: - MailChimp for WordPress: detects the mailchimp-for-wp WordPress plugin (wp-content/plugins path, the mc4wp JS global). Current CVEs for this plugin are filed under ibericode:mailchimp (4 CVEs, 142 dictionary names from 2.2 to 4.9.17), not the older mailchimp_for_wordpress_project identity a downstream fork's rule once carried. - Progress MOVEit: the X-Moveitisapi-Version header and the MOVEit Transfer mobile app IDs (meta.apple-itunes-app / google-play-app) are Transfer's own signals. NVD files Transfer's CVEs, including CVE-2023-34362 and CVE-2024-5806, under progress:moveit_transfer. - Divi: the WordPress theme/plugin this rule detects (requires: WordPress, the Divi/js/custom.js path) has its CVEs filed under elegantthemes:divi (7 CVEs), a different dictionary entry from elegant_themes:divi, which has 0. - UniFi OS: reads unifiConstant.VERSION, which the UniFi Network Application's web UI sets, not the consoles' own operating system. NVD files the Network Application's CVEs (9, 73 dictionary names from 6.2.23 to 10.5.54) under ui:unifi_network_application; ui:unifi_os names the consoles' OS instead (1 CVE, unrelated to what this rule reads). Follow-up to #511, which corrected 6 rules whose cpe already named the wrong product. Mixpanel is deliberately not included here: NVD's dictionary has no product for Mixpanel's browser SDK (the only mixpanel_project:mixpanel entry is an unrelated Drupal module), so there is no identity to add.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
I did an analysis on Wappalyzer CPEs and compared them to NVD. Six rules have a CPE that NVD does not file the product's CVEs under, one has a CPE for a different product entirely, two duplicate the same technology, and one rule's pattern matches another product's file. This PR fixes all four, each verified against the current NVD CPE dictionary and CVE data.
Wrong CPE identity
a.json)a:angularjs:angulara:angular:angularangularjs:angularis AngularJS in NVD's dictionary (15 names, 0 CVEs). Angular's 24 CVEs, and 1,339 dictionary names from 0.9.0 onward, are filed underangular:angular.j.json)a:jquery:jquery_uia:jqueryui:jquery_uijquery:jquery_uihas 0 CVEs.jqueryui:jquery_uihas 7: CVE-2010-5312, CVE-2012-6662, CVE-2016-7103, CVE-2021-41182, CVE-2021-41183, CVE-2021-41184, CVE-2022-31160.k.json)a:kentico:kentico_cmsa:kentico:xperiencekentico:kentico_cmshas 3 CVEs, on 5.5 R2 and 8.2. Kentico's current product (Xperience) files its CVEs — 50 of them, 6 CRITICAL, including CVE-2025-2746/2747/32370 — underkentico:xperience.p.json)a:parallels:parallels_plesk_panela:plesk:pleskparallels:parallels_plesk_panelis the pre-2017 Parallels-era product (48 names up to 11.0.9, 42 CVEs, none on a current release). Current Plesk CVEs (11, mostly on 18.0.x) are underplesk:plesk.p.json)a:profilepress:profilepressa:properfraction:profilepressprofilepress:profilepresshas 0 CVEs.properfraction:profilepresshas 35, 4 of them CRITICAL (CVE-2021-34621, CVE-2021-34623, CVE-2021-34624, CVE-2024-9947), across 477 dictionary names.t.json)a:transifex:transifexTransifex.live.lib_version).transifex:transifexnames the old desktop app, versions 0.1 to 0.10 — a different product NVD lists 2 CVEs for. There's no NVD product for the JS widget, so the rule is left without a cpe rather than pointing at the wrong one.Duplicate rule: Oracle WebLogic Server / Weblogic Server
o.json's "Oracle WebLogic Server" has no detection patterns of its own — it's only reached through "Oracle Dynamic Monitoring Service"'simplies— and itscpeisa:bea:weblogic_server, WebLogic's pre-Oracle identity (130 dictionary names up to 10.0, none of its 150 CVEs on a version anyone still runs).w.json's "Weblogic Server" detects the realServerresponse header, and had nocpeat all. Current WebLogic CVEs (354, 141 dictionary names) are filed undera:oracle:weblogic_server.This PR folds the duplicate: "Oracle Dynamic Monitoring Service" now implies "Weblogic Server", "Weblogic Server" gets
cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:*, and "Oracle WebLogic Server" is removed.ProgressBar.js detects WordPress's bundled jQuery UI widget
scriptSrcmatched anyprogressbar(.min).jsand read a?ver=query parameter:WordPress core registers its bundled jQuery UI progressbar widget at
wp-includes/js/jquery/ui/progressbar.min.js?ver=<jquery-ui-version>(currently 1.14.2). Any WordPress site loading that core script gets detected as ProgressBar.js, at jQuery UI's version — not ProgressBar.js's own, which tops out at 1.1.1 (npm, last published 2023).The patterns now require the package's own hosting:
…/ajax/libs/progressbar.js/<version>/progressbar(.min).js— version read…/progressbar.js@<version>/dist/progressbar(.min).js— version read…/progressbar.js/dist/progressbar(.min).js— detected, no versionTested against 11 URLs (4 legitimate ProgressBar.js CDN/package loads, 2 self-hosted copies, 5 WordPress/unrelated
progressbar*.jsfiles) in both JavaScript and Go's RE2 engine: every case matches the intended outcome.Verification
Ran locally (this repo's CI uses the same scripts under
.github/workflows/scripts/):structure_validator.py,order_validator.py,schema_validator.py,category_validator.py,group_validator.py,icon_path_validator.py— passtechnology_validator.pyfor every changed file (a,j,k,o,p,t,w) — passorder_validator.pyconfirms alphabetical technology-name order is preserved in each