-
Notifications
You must be signed in to change notification settings - Fork 16
Add a guide for submitting CVE requests #86
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
docs/cve-creation-guide.md
Outdated
|
|
||
| # Creating a CVE Request | ||
|
|
||
| This is an example of how to create a CVE with an older vulnerability from Mojolicious that did not have one previously assigned. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Should we use a general example like Foobar or something like that, rather than Mojolicious?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I can change it it an example but likely should be generic
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@stigtsp the thing I like about using this example is that it exists and you can review the source info
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@stigtsp I looked at it but the example is likely best. The point was to give an example that someone could follow
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Should we use a general example like
Foobaror something like that, rather than Mojolicious?
Then please use Foo::Bar or Foo-Bar to make the distinction clear in what to use
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I use Foo-Bar in the security policy guide.
docs/cve-creation-guide.md
Outdated
| You can provide additional information that you may have if it is relevant. | ||
|
|
||
| Some possible additional information: | ||
| 1. If the vulnerability is embargoed (not publicly acknowledged or under a non disclosure of some sort) mention it here |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Also, maybe worth mentioning that a vuln that has been discussed in public is by default public and not embargoed.
So References should not be given for anything embargoed
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
fixing
6209ce7 to
8d99138
Compare
|
Can we have this branch updated and see what's left before merging? :-) |
|
Where we are here? |
|
Since we've become CNA, this description has likely become a bit outdated. We are going to work on the CVE workflow at PTS, maybe this is a good time to discuss how to document this and make it more accessible. |
|
I shortened this substantially now that we have a CNA |
robrwo
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks alright. Some minor nits about wording.
| Send an email to cve-request@security.metacpan.org | ||
|
|
||
| # Reserving a CVE Identifier | ||
| If you have found a potential vulnerability in the scope of the CNA you can |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You should define what the scope of the CNA is.
| before a CVE identifier will be issued. However, a CPAN author or Perl | ||
| Security may **reserve** a CVE number without providing details. The CVE | ||
| identifier will be reserved and the requester will be recorded. | ||
|
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I would reword this to improve clarity
The Perl Security Team may reserve CVE identifiers, as may CPAN authors for the modules that they maintain. All others may be asked to provide the details of the vulnerability before a CVE identifier will be issued.
The CVE identifier will be reserved and the requester will be recorded.
No description provided.