Skip to content

Update CNT3 (Shared codebase, library, protocol, standard, etc.) #19

Description

@EvansJonathan

GOAL: Make the CNA Rules easier to use
CHANGE: Split CNT3 into a rule for codebases and another for standards, libraries, etc.
OUTCOME: Increased clarity in the process.
WORDING:

  • CNT3: Shared Codebase
    • Affects a single product, assign one CVE ID
    • Affects the same code in multiple products, assign a CVE ID to each affected codebase
    • Affects multiple products but with different code, assign a CVE ID to each product
    • Not sure or undefined, assign a CVE ID to each product
  • CNT 4: Libraries, Protocols, Standards, etc.
    • If there is a way to use the library, protocol, or standard without being vulnerable, then assign a CVE ID to each affected codebase or product.
    • If the using the library, protocol, or standard requires the product to be vulnerable, assign a single CVE ID.
    • Not sure, assign a CVE ID to each affected codebase.

GOAL: Make the Counting Rules inline with stakeholders' expectations
CHANGE: When there is a way to implement a standard without being vulnerable but the issue is relevant to all implementers, a single ID should be assigned.
OUTCOME: Less confusion by consumers and fewer incorrect uses of CVE IDs.
WORDING: If there is a way to use the library, protocol, or standard without being vulnerable, assign a single CVE ID.

GOAL: Improve process description
CHANGE: Specify whether shared hardware, hardware platforms, file formats, or data encodings are covered.
OUTCOME: Less vague or confusing language.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions