|
"value": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority." |
https://www.cve.org/Resources/Roles/Cnas/CNA_Rules_v4.0.pdf says
4.5.3.7 When deciding to reject a published CVE Record, CNAs MUST use the formats and
mechanisms specified by the CVE Program and MUST provide an explanation.
"has been rejected or withdrawn" doesn't usefully serve as an explanation because it leaves the reader wondering whether it was rejected or whether it was withdrawn and why either of these two happened.
A better example (consistent with 4.5.3.6) would be
"value": "This CVE Record has been rejected because it is a duplicate of CVE-1900-12345."
```
cve-schema/schema/docs/cnaContainer-rejected-example.json
Line 10 in 30f59c7
https://www.cve.org/Resources/Roles/Cnas/CNA_Rules_v4.0.pdf says
"has been rejected or withdrawn" doesn't usefully serve as an explanation because it leaves the reader wondering whether it was
rejectedor whether it waswithdrawnand why either of these two happened.A better example (consistent with 4.5.3.6) would be