-
Notifications
You must be signed in to change notification settings - Fork 12
Open
Description
Reserved-but-public (RBP) IDs come in several flavors.
- Vendor CNA publishes official advisory/vulnerability information, there is delay before vendor CNA populate CVE entry
- Typographical mistake
- Accidentially publishing a valid ID for a not-yet-published vulnerability
- Others?
Case 1. is particularly painful for "hot" vulnerabilities, i.e., the period of time that starts when a new vulnerability is published and consumers are scrambling for information, including information provided in and indexed by CVE entries.
The Program should take a comprehensive look and make some decisions about RBP, including:
- Whether or not to disclose RESERVED state at all (via Services API and via bulk download), see Review ID reservation, specifically how/why reservation is conveyed to consumers #15
- Timeouts for CNAs to publish RBP entries
- What action, if any, to take when RBP timeouts occur
Metadata
Metadata
Assignees
Labels
No labels