4 ms·
Are you sure about the "CVE explosion"? From the CNA counting rules https://cve.mitre.org/cve/cna/rules.html#section_7_assignment_rules https://cve.mitre.org/cv
by dcsommer 5y ago
Are you sure about the "CVE explosion"? From the CNA counting rules https://cve.mitre.org/cve/cna/rules.html#section_7_assignment_rules https://cve.mitre.org/cve/cna/rules.html#section_7_assignmen... :
7.2.4 If multiple products are affected by the same independently fixable vulnerability, then the CNA:
a. MUST NOT assign more than one CVE ID if the products are affected, because they share the vulnerable code. The assigned CVE ID will be shared by the affected products.
- ris 5y agoI'm not sure what would actually happen in reality, whether a single CVE would get endless addenda listing the packages affected by an upstream vulnerability. I certainly see plenty of new CVEs go past which are of the form "xyz had a vendored version of abc, which was vulnerable to ..."