Skip to content

Commit 3f6c05e

Browse files
rrobergerlxdev
andauthored
10/14/25 release branch (#3726)
* #3724 News article @ 9/17/25 Board Minutes Summary * #3723 Add 1 new podcast @ the CWG * #3722 Add 2 new CNAs * #3725 Updates for the "CVE Technical Workshop 2025" event * boardMeetings: add 9/17 board meeting summary * search: display CVE record directly following search of CVE ID that returns only corresponding CVE record --------- Co-authored-by: Roy Lane <[email protected]>
1 parent b065c67 commit 3f6c05e

File tree

7 files changed

+296
-48
lines changed

7 files changed

+296
-48
lines changed

src/assets/data/CNAsList.json

Lines changed: 113 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27383,5 +27383,118 @@
2738327383
]
2738427384
},
2738527385
"country": "USA"
27386+
},
27387+
{
27388+
"shortName": "BCNY",
27389+
"cnaID": "CNA-2025-0054",
27390+
"organizationName": "The Browser Company of New York",
27391+
"scope": "The Browser Company of New York branded products and technologies only.",
27392+
"contact": [
27393+
{
27394+
"email": [
27395+
{
27396+
"label": "Email",
27397+
"emailAddr": "[email protected]"
27398+
}
27399+
],
27400+
"contact": [],
27401+
"form": []
27402+
}
27403+
],
27404+
"disclosurePolicy": [
27405+
{
27406+
"label": "Policy",
27407+
"language": "",
27408+
"url": "https://hackerone.com/bcny"
27409+
}
27410+
],
27411+
"securityAdvisories": {
27412+
"alerts": [],
27413+
"advisories": [
27414+
{
27415+
"label": "Advisories",
27416+
"url": "https://arc.net/security/bulletins"
27417+
}
27418+
]
27419+
},
27420+
"resources": [],
27421+
"CNA": {
27422+
"isRoot": false,
27423+
"root": {
27424+
"shortName": "n/a",
27425+
"organizationName": "n/a"
27426+
},
27427+
"roles": [
27428+
{
27429+
"helpText": "",
27430+
"role": "CNA"
27431+
}
27432+
],
27433+
"TLR": {
27434+
"shortName": "mitre",
27435+
"organizationName": "MITRE Corporation"
27436+
},
27437+
"type": [
27438+
"Vendor",
27439+
"Bug Bounty Provider"
27440+
]
27441+
},
27442+
"country": "USA"
27443+
},
27444+
{
27445+
"shortName": "Foxit",
27446+
"cnaID": "CNA-2025-0055",
27447+
"organizationName": "Foxit Software Incorporated",
27448+
"scope": "Foxit issues only.",
27449+
"contact": [
27450+
{
27451+
"email": [
27452+
{
27453+
"label": "Email",
27454+
"emailAddr": "[email protected]"
27455+
}
27456+
],
27457+
"contact": [],
27458+
"form": []
27459+
}
27460+
],
27461+
"disclosurePolicy": [
27462+
{
27463+
"label": "Policy",
27464+
"language": "",
27465+
"url": "https://www.foxit.com/support/responsible-disclosure-policy.html"
27466+
}
27467+
],
27468+
"securityAdvisories": {
27469+
"alerts": [],
27470+
"advisories": [
27471+
{
27472+
"label": "Advisories",
27473+
"url": "https://www.foxit.com/support/security.html"
27474+
}
27475+
]
27476+
},
27477+
"resources": [],
27478+
"CNA": {
27479+
"isRoot": false,
27480+
"root": {
27481+
"shortName": "n/a",
27482+
"organizationName": "n/a"
27483+
},
27484+
"roles": [
27485+
{
27486+
"helpText": "",
27487+
"role": "CNA"
27488+
}
27489+
],
27490+
"TLR": {
27491+
"shortName": "mitre",
27492+
"organizationName": "MITRE Corporation"
27493+
},
27494+
"type": [
27495+
"Vendor"
27496+
]
27497+
},
27498+
"country": "USA"
2738627499
}
2738727500
]

src/assets/data/boardMeetings.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,9 @@
11
{
22
"2025": [
3+
{
4+
"name": "September 17, 2025 - teleconference",
5+
"path": "m=175993870004852&w=2"
6+
},
37
{
48
"name": "September 3, 2025 - teleconference",
59
"path": "m=175890383805223&w=2"

src/assets/data/events.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,9 @@
55
"displayOnHomepageOrder": 0,
66
"title": "CVE Program Technical Workshop – Autumn 2025",
77
"location": "Virtual",
8-
"description": "A collaborative virtual community event of CVE Partners focused on improving CVE.<br/><br/>Event Time: 10:00 AM to 2:00 PM EDT both days.<br/><br/>Please refer to the CNA partners email announcements for agenda topics and other workshop details.",
8+
"description": "A collaborative virtual community event of CVE Partners focused on improving CVE.<br/><br/>Event Time: 10:00 AM to 2:00 PM EDT (UTC-4) both days.<br/><br/>This workshop for <a href='/ProgramOrganization/CNAs'>CVE Numbering Authorities (CNAs)</a> is free, but registration is required. The registration deadline is 11:59 p.m. EDT (UTC-4) on October 22, 2025.<br/><br/>Please refer to the CNA partners email announcement sent on October 9, 2025, for registration information and other workshop details. The final agenda will be sent directly to registered attendees.<br/><br/>All CNAs should attend this workshop. There is no limit on the number of attendees that can participate from your organization.",
99
"permission": "private",
10-
"url": "",
10+
"url": "/Media/News/item/news/2025/10/14/Register-Now-for-CVE-Technical-Workshop-2025",
1111
"date": {
1212
"start": "2025-10-22",
1313
"end": "2025-10-23",

src/assets/data/metrics.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1208,7 +1208,7 @@
12081208
},
12091209
{
12101210
"month": "October",
1211-
"value": "1"
1211+
"value": "3"
12121212
},
12131213
{
12141214
"month": "November",

src/assets/data/news.json

Lines changed: 144 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,115 @@
11
{
22
"currentNews": [
3+
{
4+
"id": 587,
5+
"newsType": "news",
6+
"title": "CNAs &mdash; Register Now for the “CVE Program Technical Workshop 2025” on October 22 &amp; 23, 2025",
7+
"urlKeywords": "Register Now for CVE Technical Workshop 2025",
8+
"date": "2025-10-14",
9+
"description": [
10+
{
11+
"contentnewsType": "paragraph",
12+
"content": "The CVE Program will host a virtual “CVE Program Technical Workshop – Autumn 2025” for <a href='/ProgramOrganization/CNAs'>CVE Numbering Authorities (CNAs)</a> on Wednesday, October 23, 2025, and Thursday, October 24, 2025, from 10:00 a.m. – 2:00 p.m. EDT (UTC-4) on both days.<br/><br/>This CNA workshop is free, but registration is required. Information on how to register was sent directly to CNAs on October 9, 2025. The registration deadline is 11:59 p.m. EDT (UTC-4) on October 22, 2025, so register today!"
13+
},
14+
{
15+
"contentnewsType": "paragraph",
16+
"content": "There will be a variety of session topics including:"
17+
},
18+
{
19+
"contentnewsType": "paragraph",
20+
"content": "<ul><li>CVE Record Format roadmap</li><li>Focus on quality</li><li>CPE, PURL, CVSS 3.1 vs. CVSS 4.0, SSVC, and more</li><li>False positives and CVE data</li><li>Reference archive experiment</li><li>Effectively mapping CVEs to CWEs</li><li>Consumer Working Group</li><li>Supplier ADP pilot</li><li>Guided community listening sessions</li></ul>"
21+
},
22+
{
23+
"contentnewsType": "paragraph",
24+
"content": "The final agenda will be sent directly to registered attendees."
25+
},
26+
{
27+
"contentnewsType": "paragraph",
28+
"content": "All CNAs should attend this workshop. There is no limit on the number of attendees that can participate from your organization."
29+
}
30+
]
31+
},
32+
{
33+
"id": 586,
34+
"newsType": "news",
35+
"title": "Foxit Added as CVE Numbering Authority (CNA)",
36+
"urlKeywords": "Foxit Added as CNA",
37+
"date": "2025-10-14",
38+
"description": [
39+
{
40+
"contentnewsType": "paragraph",
41+
"content": "<a href='/PartnerInformation/ListofPartners/partner/Foxit'>Foxit Software Incorporated</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for Foxit issues only."
42+
},
43+
{
44+
"contentnewsType": "paragraph",
45+
"content": "To date, <a href='/PartnerInformation/ListofPartners'>478 CNAs</a> (475 CNAs and 3 CNA-LRs) from <a href='/ProgramOrganization/CNAs'>40 countries</a> and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. Foxit is the 258th CNA from USA."
46+
},
47+
{
48+
"contentnewsType": "paragraph",
49+
"content": "Foxit’s Root is the <a href='/PartnerInformation/ListofPartners/partner/mitre'>MITRE TL-Root</a>."
50+
}
51+
]
52+
},
53+
{
54+
"id": 585,
55+
"newsType": "news",
56+
"title": "The Browser Company of New York Added as CVE Numbering Authority (CNA)",
57+
"urlKeywords": "Browser Company Added as CNA",
58+
"date": "2025-10-14",
59+
"description": [
60+
{
61+
"contentnewsType": "paragraph",
62+
"content": "<a href='/PartnerInformation/ListofPartners/partner/BCNY'>The Browser Company of New York</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for The Browser Company of New York branded products and technologies only."
63+
},
64+
{
65+
"contentnewsType": "paragraph",
66+
"content": "To date, <a href='/PartnerInformation/ListofPartners'>477 CNAs</a> (474 CNAs and 3 CNA-LRs) from <a href='/ProgramOrganization/CNAs'>40 countries</a> and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. The Browser Company of New York is the 257th CNA from USA."
67+
},
68+
{
69+
"contentnewsType": "paragraph",
70+
"content": "The Browser Company of New York’s Root is the <a href='/PartnerInformation/ListofPartners/partner/mitre'>MITRE TL-Root</a>."
71+
}
72+
]
73+
},
74+
{
75+
"id": 584,
76+
"newsType": "podcast",
77+
"title": "CVE Podcast &mdash; The CVE Consumer Working Group (CWG)",
78+
"urlKeywords": "CVE Consumer Working Group",
79+
"date": "2025-10-14",
80+
"description": [
81+
{
82+
"contentnewsType": "paragraph",
83+
"content": "“<a href='/Media/News/Podcasts'>We Speak CVE</a>” podcast host Shannon Sabens chats with <a href='/ProgramOrganization/WorkingGroups#CVEConsumerWorkingGroupCWG'>CVE Consumer Working Group (CWG)</a> co-chairs, Jay Jacobs and Bob Lord, and <a href='/'>CVE&trade;</a> Project Lead Alec Summers, about how the CWG was created to address the needs and perspectives of those who use CVE data &mdash; ranging from enterprise security teams to tool developers and managed security service providers &mdash; recognizing that their requirements and pain points often differ from those of upstream data providers."
84+
},
85+
{
86+
"contentnewsType": "paragraph",
87+
"content": "Topics include the CWG’s goals to systematically capture and organize consumer feedback, identify common and unique challenges across different user types, and inform improvements in the CVE Program; the diversity and international participation among sign-ups, including organizations outside the usual sphere, such as medical companies; and the concept of “patch smarter, not harder,” stressing the importance of prioritization and high-quality data to help defenders manage the overwhelming volume of vulnerabilities. In addition, listeners are encouraged to join the CWG for meetings scheduled to accommodate global involvement and help participate in shaping the future of CVE."
88+
},
89+
{
90+
"contentnewsType": "paragraph",
91+
"content": "“<a href='/Media/News/Podcasts'>We Speak CVE</a>” is a free podcast about cybersecurity, vulnerability management, and the CVE Program. Listen on the <a href='https://www.youtube.com/channel/UCUHd2XFDsKH8kjMZQaSKpDQ/' target='_blank'>CVE Program Channel on YouTube</a>, on <a href='https://wespeakcve.buzzsprout.com/' target='_blank'>We Speak CVE page on Buzzsprout</a>, and on major podcast directories such as Spotify, Stitcher, Apple Podcasts, iHeartRadio, Podcast Addict, Podchaser, Pocket Casts, Deezer, Listen Notes, Player FM, and Podcast Index, among others."
92+
}
93+
],
94+
"url": "https://www.youtube.com/embed/PetT7jdf7Pc"
95+
},
96+
{
97+
"id": 583,
98+
"newsType": "news",
99+
"title": "Minutes from CVE Board Teleconference Meeting on September 17 Now Available",
100+
"urlKeywords": "CVE Board Minutes from September 17",
101+
"date": "2025-10-14",
102+
"description": [
103+
{
104+
"contentnewsType": "paragraph",
105+
"content": "The <a href='/ProgramOrganization/Board'>CVE Board</a> held a teleconference meeting on September 17, 2025. Read the <a href='https://marc.info/?l=cve-editorial-board&m=175993870004852&w=2' target='_blank'>meeting minutes summary</a>."
106+
},
107+
{
108+
"contentnewsType": "paragraph",
109+
"content": "The CVE Board is the organization responsible for the strategic direction, governance, operational structure, policies, and rules of the CVE Program. The Board includes members from numerous cybersecurity-related organizations including commercial security tool vendors, academia, research institutions, government departments and agencies, and other prominent security experts, as well as end-users of vulnerability information."
110+
}
111+
]
112+
},
3113
{
4114
"id": 582,
5115
"newsType": "news",
@@ -19071,40 +19181,6 @@
1907119181
}
1907219182
]
1907319183
},
19074-
{
19075-
"id": 4,
19076-
"newsType": "podcast",
19077-
"title": "Interview with Larry Cashdollar A Researcher’s Perspective",
19078-
"date": "2021-05-04",
19079-
"description": [
19080-
{
19081-
"contentnewsType": "paragraph",
19082-
"content": "Kelly Todd of the <a href='/'>CVE Program</a> interviews security researcher <a href='https://twitter.com/_larry0' target='_blank'>Larry Cashdollar</a> about how he got started researching vulnerabilities and his experiences over the years, how he became the CVE Program’s first-ever independent vulnerability researcher <a href='/ProgramOrganization/CNAs'>CVE Numbering Authority (CNA)</a>, best practices, and the benefits of being able to assign his own <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE IDs</a> to the vulnerabilities he discovers."
19083-
},
19084-
{
19085-
"contentnewsType": "paragraph",
19086-
"content": "“<a href='/Media/News/Podcasts'>We Speak CVE</a>” is a free podcast about cybersecurity, vulnerability management, and the CVE Program. Listen on the <a href='https://www.youtube.com/channel/UCUHd2XFDsKH8kjMZQaSKpDQ/' target='_blank'>CVE Program Channel on YouTube</a>, on <a href='https://wespeakcve.buzzsprout.com/' target='_blank'>We Speak CVE page on Buzzsprout</a>, and on major podcast directories such as Spotify, Stitcher, Google Podcasts, Apple Podcasts, iHeartRadio, Podcast Addict, Podchaser, Pocket Casts, Deezer, Listen Notes, Player FM, and Podcast Index, among others."
19087-
}
19088-
],
19089-
"url": "https://www.youtube.com/embed/-OQ9FNnYymI"
19090-
},
19091-
{
19092-
"id": 3,
19093-
"newsType": "podcast",
19094-
"title": "Partnering with the CVE Program",
19095-
"date": "2021-04-06",
19096-
"description": [
19097-
{
19098-
"contentnewsType": "paragraph",
19099-
"content": "In our third episode, Shannon Sabens of <a href='https://www.crowdstrike.com/' target='_blank'>CrowdStrike</a> speaks with Jo Bazar of the <a href='/'>CVE Program</a>, Erin Alexander of <a href='https://www.cisa.gov/' target='_blank'>CISA ICS</a>, and Tomo Itou of <a href='https://www.jpcert.or.jp/vh/index.html' target='_blank'>JPCERT/CC</a> about the structure and objectives of the <a href='/ProgramOrganization/CNAs'>CVE Numbering Authority (CNA)</a> program, what it means to be a Root and a CNA, the benefits of <a href='/PartnerInformation/Partner#HowToBecomeAPartner'>partnering with the CVE Program</a>, and recommendations for organizations considering becoming a Root or CNA."
19100-
},
19101-
{
19102-
"contentnewsType": "paragraph",
19103-
"content": "“<a href='/Media/News/Podcasts'>We Speak CVE</a>” is a free podcast about cybersecurity, vulnerability management, and the CVE Program. Listen on the <a href='https://www.youtube.com/channel/UCUHd2XFDsKH8kjMZQaSKpDQ/' target='_blank'>CVE Program Channel on YouTube</a>, on <a href='https://wespeakcve.buzzsprout.com/' target='_blank'>We Speak CVE page on Buzzsprout</a>, and on major podcast directories such as Spotify, Stitcher, Google Podcasts, Apple Podcasts, iHeartRadio, Podcast Addict, Podchaser, Pocket Casts, Deezer, Listen Notes, Player FM, and Podcast Index, among others."
19104-
}
19105-
],
19106-
"url": "https://www.youtube.com/embed/QTjoGiFmmF4"
19107-
},
1910819184
{
1910919185
"id": 2,
1911019186
"newsType": "podcast",
@@ -19290,6 +19366,40 @@
1929019366
}
1929119367
],
1929219368
"archivePodcast": [
19369+
{
19370+
"id": 4,
19371+
"newsType": "podcast",
19372+
"title": "Interview with Larry Cashdollar A Researcher’s Perspective (Archived)",
19373+
"date": "2021-05-04",
19374+
"description": [
19375+
{
19376+
"contentnewsType": "paragraph",
19377+
"content": "Kelly Todd of the <a href='/'>CVE Program</a> interviews security researcher <a href='https://twitter.com/_larry0' target='_blank'>Larry Cashdollar</a> about how he got started researching vulnerabilities and his experiences over the years, how he became the CVE Program’s first-ever independent vulnerability researcher <a href='/ProgramOrganization/CNAs'>CVE Numbering Authority (CNA)</a>, best practices, and the benefits of being able to assign his own <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE IDs</a> to the vulnerabilities he discovers."
19378+
},
19379+
{
19380+
"contentnewsType": "paragraph",
19381+
"content": "“<a href='/Media/News/Podcasts'>We Speak CVE</a>” is a free podcast about cybersecurity, vulnerability management, and the CVE Program. Listen on the <a href='https://www.youtube.com/channel/UCUHd2XFDsKH8kjMZQaSKpDQ/' target='_blank'>CVE Program Channel on YouTube</a>, on <a href='https://wespeakcve.buzzsprout.com/' target='_blank'>We Speak CVE page on Buzzsprout</a>, and on major podcast directories such as Spotify, Stitcher, Google Podcasts, Apple Podcasts, iHeartRadio, Podcast Addict, Podchaser, Pocket Casts, Deezer, Listen Notes, Player FM, and Podcast Index, among others."
19382+
}
19383+
],
19384+
"url": "https://www.youtube.com/embed/-OQ9FNnYymI"
19385+
},
19386+
{
19387+
"id": 3,
19388+
"newsType": "podcast",
19389+
"title": "Partnering with the CVE Program (Archived)",
19390+
"date": "2021-04-06",
19391+
"description": [
19392+
{
19393+
"contentnewsType": "paragraph",
19394+
"content": "In our third episode, Shannon Sabens of <a href='https://www.crowdstrike.com/' target='_blank'>CrowdStrike</a> speaks with Jo Bazar of the <a href='/'>CVE Program</a>, Erin Alexander of <a href='https://www.cisa.gov/' target='_blank'>CISA ICS</a>, and Tomo Itou of <a href='https://www.jpcert.or.jp/vh/index.html' target='_blank'>JPCERT/CC</a> about the structure and objectives of the <a href='/ProgramOrganization/CNAs'>CVE Numbering Authority (CNA)</a> program, what it means to be a Root and a CNA, the benefits of <a href='/PartnerInformation/Partner#HowToBecomeAPartner'>partnering with the CVE Program</a>, and recommendations for organizations considering becoming a Root or CNA."
19395+
},
19396+
{
19397+
"contentnewsType": "paragraph",
19398+
"content": "“<a href='/Media/News/Podcasts'>We Speak CVE</a>” is a free podcast about cybersecurity, vulnerability management, and the CVE Program. Listen on the <a href='https://www.youtube.com/channel/UCUHd2XFDsKH8kjMZQaSKpDQ/' target='_blank'>CVE Program Channel on YouTube</a>, on <a href='https://wespeakcve.buzzsprout.com/' target='_blank'>We Speak CVE page on Buzzsprout</a>, and on major podcast directories such as Spotify, Stitcher, Google Podcasts, Apple Podcasts, iHeartRadio, Podcast Addict, Podchaser, Pocket Casts, Deezer, Listen Notes, Player FM, and Podcast Index, among others."
19399+
}
19400+
],
19401+
"url": "https://www.youtube.com/embed/QTjoGiFmmF4"
19402+
},
1929319403
{
1929419404
"id": 130,
1929519405
"newsType": "podcast",

0 commit comments

Comments
 (0)