3 ms·
Right now the CVE process doesn't allow unilateral rejection of CVEs by maintainers because they have the opposite incentive. It is in their interest to deny th
by TrueDuality 3y ago
Right now the CVE process doesn't allow unilateral rejection of CVEs by maintainers because they have the opposite incentive. It is in their interest to deny that a vulnerability exists, both because there is a perception that more vulnerabilities discovered means lower quality software, but also because that is extra effort their team needs to handle. It's not ethical but its also not uncommon for companies to not investigate and just deny a bug is real. Sometimes it isn't even an ethical issue but just poorly described by the reporter, or something that seems absolutely implausible to the developers.
I don't know what improvements to the current process actually look like but it needs to be able to account for effectively fraud and apathy on both side of the equation.