Skip to content

Can CNAs publish vulnerability advisories lacking CVE IDs? #12

@zmanion

Description

@zmanion

Related to #9, we've observed "vendor" CNAs publishing advisories for vulnerabilities but lacking CVE IDs (nothing assigned by the CNA or another CNA, like a researcher or coordinator CNA).

The CVE Program tries not to dictate CNA (vendor or otherwise) vulnerabiltiy coordination, remediation, disclosure, and publication practices. CNAs are not required to fix vulnerabilities or publish advisories, and CNAs are to some extent not required to assign CVE IDs (although they may have a right of first refusal).

If a CNA publishes about a vulnerability, it seems reasonable to require that the CNA also assign and publish a CVE ID (or use a CVE ID assigned by another CNA). If the CNA does not, the burden falls on some other part of the CVE Program (likely a CNA-LR). A CNA close to (with appropriate scope for) a vulnerability, typically the vendor, is the least cost avoider, i.e., the least expensive way to produce a CVE ID assignment.

Should CNAs be required to assign (or use another assignment) for vulnerabilities the CNA publishes about? Should such a requirement be tied to the "vendor" CNA role?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions