[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

what text is being sent to researchers re: OSS assignments?



Reference:

https://www.stevencampbell.info/2016/12/my-first-cve-2016-1000329-in-blogphp/

   I submitted my CVE request through Mitre who notified me that open
   source software CVE requests are now processed via the Distributed
   Weakness Filing before being sent to Mitre for inclusion in their
   database.

This creates an obvious disconnect and potentially duplicate assignments and confusion, if researchers are being told to go to DWF for *all* OSS assignments. For example, Apache is a CNA and has many OSS projects, but vulnerabilities in their software should go to them, not DWF. Could MITRE share the text that is being sent out currently?

.b


Page Last Updated or Reviewed: December 19, 2016