Date: Mon, 21 Nov 2016 22:28:16 +0200 From: Henri Salo <henri@...v.fi> To: Scott Gravelle <scottg@...rezzio.com> Cc: oss-security@...ts.openwall.com Subject: Re: Multiple XSS vulnerabilities affecting five WordPress Plugins On Mon, Nov 21, 2016 at 04:56:13PM +0000, Scott Gravelle wrote: > Any plans to get CVEs assigned to these vulnerabilities you guys found? Our > vulnerability scanner does not have a feature to filter off OVE Maybe you should start handling OVE and other IDs too. Two reasons: 1) MITRE is not always assigning CVEs for WordPress plugin and theme vulnerabilities for unknown reason. It's not like the CVEs are running out 2) MITRE is not assigning CVEs to all software that has previously received a CVE, silently dropping the software to out-of-scope area. Example case: http://www.openwall.com/lists/oss-security/2016/11/10/6 -- Henri Salo
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ