Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reporting Capability For CVE Records That Haven’t Been Populated Despite Details Being Public #18

Open
PluginVulnerabilities opened this issue Jan 3, 2024 · 1 comment

Comments

@PluginVulnerabilities
Copy link

Proposed New Idea/Feature (required)

We keep running across publicly listed CVE IDs where CNAs are not populating the CVE record, but releasing details in to their own systems. This is sometimes true even months after they added it to their own system. Currently, there isn’t a mechanism to report this and therefore a method to monitor for CNAs repeatedly failing to populate CVE records despite publicly listing associated CVE IDs for them.

Additional Notes (Optional)

In addition to reporting a URL where the public usage can be seen, an option to list the date it was made public would increase the value of the data.

@zmanion
Copy link

zmanion commented Jan 17, 2024

There is an existing mechanism, although it could be more automated: https://cveform.mitre.org/ (select "Notify CVE about a publication").

While it doesn't directly address the new feature, the proposed changes to the CNA Operational Rules will specify tighter timelines for CNAs to populate Records for CVE IDs they own.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants