GOAL: Make the CNA Rules easier to use
CHANGE: Split CNT3 into a rule for codebases and another for standards, libraries, etc.
OUTCOME: Increased clarity in the process.
WORDING:
- CNT3: Shared Codebase
- Affects a single product, assign one CVE ID
- Affects the same code in multiple products, assign a CVE ID to each affected codebase
- Affects multiple products but with different code, assign a CVE ID to each product
- Not sure or undefined, assign a CVE ID to each product
- CNT 4: Libraries, Protocols, Standards, etc.
- If there is a way to use the library, protocol, or standard without being vulnerable, then assign a CVE ID to each affected codebase or product.
- If the using the library, protocol, or standard requires the product to be vulnerable, assign a single CVE ID.
- Not sure, assign a CVE ID to each affected codebase.
GOAL: Make the Counting Rules inline with stakeholders' expectations
CHANGE: When there is a way to implement a standard without being vulnerable but the issue is relevant to all implementers, a single ID should be assigned.
OUTCOME: Less confusion by consumers and fewer incorrect uses of CVE IDs.
WORDING: If there is a way to use the library, protocol, or standard without being vulnerable, assign a single CVE ID.
GOAL: Improve process description
CHANGE: Specify whether shared hardware, hardware platforms, file formats, or data encodings are covered.
OUTCOME: Less vague or confusing language.
GOAL: Make the CNA Rules easier to use
CHANGE: Split CNT3 into a rule for codebases and another for standards, libraries, etc.
OUTCOME: Increased clarity in the process.
WORDING:
GOAL: Make the Counting Rules inline with stakeholders' expectations
CHANGE: When there is a way to implement a standard without being vulnerable but the issue is relevant to all implementers, a single ID should be assigned.
OUTCOME: Less confusion by consumers and fewer incorrect uses of CVE IDs.
WORDING: If there is a way to use the library, protocol, or standard without being vulnerable, assign a single CVE ID.
GOAL: Improve process description
CHANGE: Specify whether shared hardware, hardware platforms, file formats, or data encodings are covered.
OUTCOME: Less vague or confusing language.