-
Notifications
You must be signed in to change notification settings - Fork 1.7k
Open
Labels
2.xRelated to ModSecurity version 2.xRelated to ModSecurity version 2.x3.xRelated to ModSecurity version 3.xRelated to ModSecurity version 3.x
Description
I am the package maintainer of ModSecurity in Buildroot. Buildroot has automated tracking of CVEs which it does by checking the CPE for the corresponding release. It seems that for both 3.0.11 and 3.0.12 no CPE was registered. The newest CPE I can find in the NIST database is cpe:2.3:a:trustwave:modsecurity:3.0.10:::::::*
This has effectively broken the CVE reporting infrastructure for ModSecurity in Buildroot, causing us to miss CVE-2024-1019.
Will the creation of CPEs resume in the future for future versions or will this be deprecated?
Metadata
Metadata
Assignees
Labels
2.xRelated to ModSecurity version 2.xRelated to ModSecurity version 2.x3.xRelated to ModSecurity version 3.xRelated to ModSecurity version 3.x