Date: Mon, 21 Nov 2016 14:00:58 -0700 From: Kurt Seifried <kseifried@...hat.com> To: oss-security <oss-security@...ts.openwall.com> Cc: Scott Gravelle <scottg@...rezzio.com> Subject: Re: Multiple XSS vulnerabilities affecting five WordPress Plugins One aspect of this is the quality of CVE requests. Well formed requests are easy and fast to process. Poorly formed requests take more time (I'm not speaking about these WordPress issues in specific, but more in general terms). We (MITRE and the CVE board as well as efforts like the DWF) are also making significant changes to CVE, how they are assigned, CNAs, federation, the technology and more that should result in much easier and faster assignments. Also there are problems with OVE, for example what counting rules does it use? Where is the database of data? To be honest OVE is a nice idea, but falls very short of what people need from a vulnerability identifier. On Mon, Nov 21, 2016 at 1:28 PM, Henri Salo <henri@...v.fi> wrote: > On Mon, Nov 21, 2016 at 04:56:13PM +0000, Scott Gravelle wrote: > > Any plans to get CVEs assigned to these vulnerabilities you guys found? > Our > > vulnerability scanner does not have a feature to filter off OVE > > Maybe you should start handling OVE and other IDs too. Two reasons: > > 1) MITRE is not always assigning CVEs for WordPress plugin and theme > vulnerabilities for unknown reason. It's not like the CVEs are running out > 2) MITRE is not assigning CVEs to all software that has previously > received a > CVE, silently dropping the software to out-of-scope area. Example case: > http://www.openwall.com/lists/oss-security/2016/11/10/6 > > -- > Henri Salo > -- -- Kurt Seifried -- Red Hat -- Product Security -- Cloud PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 Red Hat Product Security contact: secalert@...hat.com
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.