| Summary: | Need to consider how to handle triage for reserved CVEs | ||
|---|---|---|---|
| Product: | [Yocto Project Subprojects] Security Response Tool | Reporter: | Ross Burton <ross.burton> |
| Component: | General | Assignee: | David Reyna <david.reyna> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Medium | ||
| Version: | unspecified | ||
| Target Milestone: | 2.7 | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Ross Burton
2018-11-09 12:59:09 UTC
In the latest update: 1. After the NIST CVEs are scanned, the MITRE database is scanned for any CVEs that have not been created from the NIST data. This data is the missing "reserved" CVEs. 2. When the "New" CVEs are scanned and scored, the CVE data from the alternate CVE sources are automatically registered (except for sources that are without bulk downloads and are REST accessed only). This provides the comparison CVE sources automatically for the triage process. Implemented |