Replies: 1 comment
-
It seems there is generally no "sync" done in both ways (at least partly) because i have also seen the opposite: Within the Mire CVE entry more recent info was found in comparison to the GHSA advisory. One example: GHSA-r4wh-9cw3-v2jg which lists Adobe Premiere Pro as being affected while actually Adobe Bridge is the affected product (got changed later in the Mitre CVE entry) On a related note: I also wonder how the "Reject" state is handled / synced, e.g. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
That happened in the past:
CVE-2023-30451
via Mitre and published their findings directlyCVE-2023-30451
This is the scenario today:
GHSA-w6x2-jg8h-p6mp
(e.g. version ranges, fixes, assessment & description)Thanks in advance for any guidance on this topic 🙏
Beta Was this translation helpful? Give feedback.
All reactions