Skip to content

Is it a goal of the CVE 5.0 format to contain contextual information from the CVE description? #214

Answered by chandanbn
ammerzon asked this question in Q&A
Discussion options

You must be logged in to vote

Your suggested JSON representation looks good (eg., tomcat in platforms)

There is also a configurations field that could be used for calling out specific circumstances (like Tomcat plus JDK9+) that make the vulnerability exploitable.

While the intent of the structured representation is to reduce reliance on a blob of text containing all knowledge, it is also to highlight certain parts of information that have a high value to the audience- and to make sure it is captured if available.

That fact that a vuln is only relevant in circumstances (versions, platforms, configs) may reduce unnecessary churn when people have to deal with the vuln.

Thanks
Chandan

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@ammerzon
Comment options

Answer selected by ammerzon
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants