Skip to content

Question: Deciding if a CVE number is verified as real? #1097

@jasnow

Description

@jasnow

What should our (ruby-advisory-db) policy be about deciding if a CVE number is verified as real?

Example

How would you improve this?

 * Normally if I need to check out to see if a CVE number is real, I google and 
    see if it shows up on one of these web sites:
   * [https://nvd.nist.gov/vuln/search or
   * https://www.cve.org/CVERecord, 
   * https://www.cvedetails.com/index.php,
   * https://cve.report].

If so, then I fill good using it in the ruby-advisory-db "cve:"
field and add it to the "related:"/"url:" field.

Other sources include:
 * CVE number in http://blog.rubygems.org blog
 * Project-specific comments, commits, issues, PRs, etc.
 * CVE number on https://github.com/advisories or https://advisories.gitlab.com
 * Advisory aggregator URLs (such as snyt, ubuntu, redhat, suse, debian, archlinux, puppet, or 
   https://www.whitesourcesoftware.com/vulnerability-database)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions