question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Version 4.0.2 can not download NVD

See original GitHub issue

Describe the bug I constantly see the next messages:

An exception occurred downloading NVD CVE - 2008
Some CVEs may not be reported.

** Version of dependency-check used ** The problem occurs using version 4.0.2 of the gradle plugin.

** Log file ** https://gist.github.com/emartynov/73291c24c2fb8e09e8c2f9aa69941ac2

Issue Analytics

  • State:closed
  • Created 4 years ago
  • Reactions:3
  • Comments:5 (3 by maintainers)

github_iconTop GitHub Comments

1reaction
jeremylongcommented, Jun 5, 2019

The entire downloading of the NVD has been re-written for the soon to be published 5.0.0. The NVD has changed their rate limiting. You can try the 5.0.0-M3 milestone release to see the changes - or wait hopefully less then a week for the 5.0.0 release.

0reactions
jeremylongcommented, Jun 6, 2019

@emartynov if the 60 modules are all in a single build - there should be no issue as the update process use a lock and waits to make sure only one instance of ODC is updating the database at a time.

Read more comments on GitHub >

github_iconTop Results From Across the Web

Unable to download the NVD CVE data - Stack Overflow
when i do build am getting Unable to download the NVD CVE data.do I have to include any dependency to resole that issue...
Read more >
CVE-2021-44228 - NVD
Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Read more >
CVE-2021-24825 - NVD
Current Description. The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, ...
Read more >
Data Feeds - NVD
If no changes have been made there is no benefit to downloading either the .zip or .gz files. This approach should result in...
Read more >
CVE-2021-22819 Detail - NVD
CVSS Version 2.0 ... NIST does not necessarily endorse the views expressed, ... https://download.schneider-electric.com/files?
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found