Skip to content

Reporting Capability For CVE Records That Haven’t Been Populated Despite Details Being Public #18

@PluginVulnerabilities

Description

@PluginVulnerabilities

Proposed New Idea/Feature (required)

We keep running across publicly listed CVE IDs where CNAs are not populating the CVE record, but releasing details in to their own systems. This is sometimes true even months after they added it to their own system. Currently, there isn’t a mechanism to report this and therefore a method to monitor for CNAs repeatedly failing to populate CVE records despite publicly listing associated CVE IDs for them.

Additional Notes (Optional)

In addition to reporting a URL where the public usage can be seen, an option to list the date it was made public would increase the value of the data.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions