Skip to content

rejected example is inconsistent with 4.5.3.7 in CNA Rules 4.0 #313

Description

@ElectricNroff

"value": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority."

https://www.cve.org/Resources/Roles/Cnas/CNA_Rules_v4.0.pdf says

4.5.3.7 When deciding to reject a published CVE Record, CNAs MUST use the formats and
mechanisms specified by the CVE Program and MUST provide an explanation.

"has been rejected or withdrawn" doesn't usefully serve as an explanation because it leaves the reader wondering whether it was rejected or whether it was withdrawn and why either of these two happened.

A better example (consistent with 4.5.3.6) would be

"value": "This CVE Record has been rejected because it is a duplicate of CVE-1900-12345."
```

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions