Skip to content

Commit fafe41a

Browse files
committed
#3110 Add 3 new CNAs + Update 1 CNA's info
1 parent 3785ef5 commit fafe41a

File tree

3 files changed

+238
-7
lines changed

3 files changed

+238
-7
lines changed

src/assets/data/CNAsList.json

Lines changed: 174 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -8460,16 +8460,16 @@
84608460
"country": "Taiwan"
84618461
},
84628462
{
8463-
"shortName": "SNPS",
8463+
"shortName": "BlackDuck",
84648464
"cnaID": "CNA-2021-0013",
8465-
"organizationName": "Synopsys",
8466-
"scope": "All Synopsys SIG products, as well as vulnerabilities in third-party software discovered by Synopsys SIG that are not in another CNA’s scope",
8465+
"organizationName": "Black Duck Software, Inc.",
8466+
"scope": "All Black Duck (formerly Synopsys Software Integrity Group) products, as well as vulnerabilities in third-party software discovered by Black Duck that are not in another CNA’s scope",
84678467
"contact": [
84688468
{
84698469
"email": [
84708470
{
84718471
"label": "Email",
8472-
"emailAddr": "psirt@synopsys.com"
8472+
"emailAddr": "psirt@blackduck.com"
84738473
}
84748474
],
84758475
"contact": [],
@@ -8480,15 +8480,15 @@
84808480
{
84818481
"label": "Policy",
84828482
"language": "",
8483-
"url": "https://www.synopsys.com/company/legal/vulnerability-disclosure-policy.html"
8483+
"url": "https://www.blackduck.com/company/legal/vulnerability-disclosure-policy.html"
84848484
}
84858485
],
84868486
"securityAdvisories": {
84878487
"alerts": [],
84888488
"advisories": [
84898489
{
84908490
"label": "Advisories",
8491-
"url": "https://www.synopsys.com/blogs/software-security/"
8491+
"url": "https://www.blackduck.com/blog/category.cyrc.html#1"
84928492
}
84938493
]
84948494
},
@@ -23535,5 +23535,173 @@
2353523535
]
2353623536
},
2353723537
"country": "USA"
23538+
},
23539+
{
23540+
"shortName": "MyMMT",
23541+
"cnaID": "CNA-2024-0066",
23542+
"organizationName": "Mammotome",
23543+
"scope": "All Mammotome products",
23544+
"contact": [
23545+
{
23546+
"email": [],
23547+
"contact": [
23548+
{
23549+
"label": "Mammotome Report a Vulnerability page",
23550+
"url": "https://www.mammotome.com/us/en/legal/product-security/report-a-security-vulnerability"
23551+
}
23552+
],
23553+
"form": []
23554+
}
23555+
],
23556+
"disclosurePolicy": [
23557+
{
23558+
"label": "Policy",
23559+
"language": "",
23560+
"url": "https://www.mammotome.com/us/en/legal/product-security/product-security-overview"
23561+
}
23562+
],
23563+
"securityAdvisories": {
23564+
"alerts": [],
23565+
"advisories": [
23566+
{
23567+
"label": "Advisories",
23568+
"url": "https://www.mammotome.com/us/en/legal/product-security/product-security-updates"
23569+
}
23570+
]
23571+
},
23572+
"resources": [],
23573+
"CNA": {
23574+
"isRoot": false,
23575+
"root": {
23576+
"shortName": "icscert",
23577+
"organizationName": "Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS)"
23578+
},
23579+
"roles": [
23580+
{
23581+
"helpText": "",
23582+
"role": "CNA"
23583+
}
23584+
],
23585+
"TLR": {
23586+
"shortName": "CISA",
23587+
"organizationName": "Cybersecurity and Infrastructure Security Agency (CISA)"
23588+
},
23589+
"type": [
23590+
"Vendor"
23591+
]
23592+
},
23593+
"country": "USA"
23594+
},
23595+
{
23596+
"shortName": "wikimedia-foundation",
23597+
"cnaID": "CNA-2024-0067",
23598+
"organizationName": "The Wikimedia Foundation",
23599+
"scope": "Any code repository hosted under <a href='https://gerrit.wikimedia.org' target='_blank'>gerrit.wikimedia.org</a>, <a href='https://gitlab.wikimedia.org' target='_blank'>gitlab.wikimedia.org</a>, or <a href='https://github.com/wikimedia' target='_blank'>github.com/wikimedia</a> that is not labeled as archived or marked as a fork of an upstream project. Please see our <a href='https://www.mediawiki.org/wiki/Reporting_security_bugs' target='_blank'>disclosure policy</a> for additional exclusions to scope",
23600+
"contact": [
23601+
{
23602+
"email": [
23603+
{
23604+
"label": "Email",
23605+
"emailAddr": "[email protected]"
23606+
}
23607+
],
23608+
"contact": [],
23609+
"form": []
23610+
}
23611+
],
23612+
"disclosurePolicy": [
23613+
{
23614+
"label": "Policy",
23615+
"language": "",
23616+
"url": "https://www.mediawiki.org/wiki/Reporting_security_bugs"
23617+
}
23618+
],
23619+
"securityAdvisories": {
23620+
"alerts": [],
23621+
"advisories": [
23622+
{
23623+
"label": "Advisories",
23624+
"url": "https://gitlab.wikimedia.org/repos/security/wikimedia-cve-assignments"
23625+
}
23626+
]
23627+
},
23628+
"resources": [],
23629+
"CNA": {
23630+
"isRoot": false,
23631+
"root": {
23632+
"shortName": "n/a",
23633+
"organizationName": "n/a"
23634+
},
23635+
"roles": [
23636+
{
23637+
"helpText": "",
23638+
"role": "CNA"
23639+
}
23640+
],
23641+
"TLR": {
23642+
"shortName": "mitre",
23643+
"organizationName": "MITRE Corporation"
23644+
},
23645+
"type": [
23646+
"Open Source"
23647+
]
23648+
},
23649+
"country": "USA"
23650+
},
23651+
{
23652+
"shortName": "RTI",
23653+
"cnaID": "CNA-2024-0068",
23654+
"organizationName": "Real-Time Innovations, Inc.",
23655+
"scope": "All RTI Connext products, including EOL products. See <a href='https://www.rti.com/products' target='_blank'>https://www.rti.com/products</a> for more information",
23656+
"contact": [
23657+
{
23658+
"email": [
23659+
{
23660+
"label": "Email",
23661+
"emailAddr": "[email protected]"
23662+
}
23663+
],
23664+
"contact": [],
23665+
"form": []
23666+
}
23667+
],
23668+
"disclosurePolicy": [
23669+
{
23670+
"label": "Policy",
23671+
"language": "",
23672+
"url": "https://community.rti.com/static/documentation/connext-dds/current/doc/vulnerabilities/#rti-s-approach-to-vulnerability-detection-and-management"
23673+
}
23674+
],
23675+
"securityAdvisories": {
23676+
"alerts": [],
23677+
"advisories": [
23678+
{
23679+
"label": "Advisories",
23680+
"url": "https://community.rti.com/static/documentation/connext-dds/current/doc/vulnerabilities/#"
23681+
}
23682+
]
23683+
},
23684+
"resources": [],
23685+
"CNA": {
23686+
"isRoot": false,
23687+
"root": {
23688+
"shortName": "n/a",
23689+
"organizationName": "n/a"
23690+
},
23691+
"roles": [
23692+
{
23693+
"helpText": "",
23694+
"role": "CNA"
23695+
}
23696+
],
23697+
"TLR": {
23698+
"shortName": "mitre",
23699+
"organizationName": "MITRE Corporation"
23700+
},
23701+
"type": [
23702+
"Vendor"
23703+
]
23704+
},
23705+
"country": "USA"
2353823706
}
2353923707
]

src/assets/data/metrics.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1165,7 +1165,7 @@
11651165
},
11661166
{
11671167
"month": "October",
1168-
"value": "TBA"
1168+
"value": "3"
11691169
},
11701170
{
11711171
"month": "November",

src/assets/data/news.json

Lines changed: 63 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,68 @@
11
{
22
"currentNews": [
3+
{
4+
"id": 417,
5+
"newsType": "news",
6+
"title": "RTI Added as CVE Numbering Authority (CNA)",
7+
"urlKeywords": "RTI Added as CNA",
8+
"date": "2024-10-01",
9+
"description": [
10+
{
11+
"contentnewsType": "paragraph",
12+
"content": "<a href='/PartnerInformation/ListofPartners/partner/RTI'>Real-Time Innovations, Inc.</a> (RTI) is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for all RTI Connext products, including EOL products. See <a href='https://www.rti.com/products' target='_blank'>https://www.rti.com/products</a> for more information."
13+
},
14+
{
15+
"contentnewsType": "paragraph",
16+
"content": "To date, <a href='/PartnerInformation/ListofPartners'>411 CNAs</a> (409 CNAs and 2 CNA-LRs) from <a href='/ProgramOrganization/CNAs'>40 countries</a> and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. RTI is the 223rd CNA from USA."
17+
},
18+
{
19+
"contentnewsType": "paragraph",
20+
"content": "RTI’s Root is the <a href='/PartnerInformation/ListofPartners/partner/mitre'>MITRE Top-Level Root</a>."
21+
}
22+
]
23+
},
24+
{
25+
"id": 416,
26+
"newsType": "news",
27+
"title": "Wikimedia Foundation Added as CVE Numbering Authority (CNA)",
28+
"urlKeywords": "Wikimedia Foundation Added as CNA",
29+
"date": "2024-10-01",
30+
"description": [
31+
{
32+
"contentnewsType": "paragraph",
33+
"content": "<a href='/PartnerInformation/ListofPartners/partner/wikimedia-foundation'>The Wikimedia Foundation</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for any code repository hosted under <a href='https://gerrit.wikimedia.org' target='_blank'>gerrit.wikimedia.org</a>, <a href='https://gitlab.wikimedia.org' target='_blank'>gitlab.wikimedia.org</a>, or <a href='https://github.com/wikimedia' target='_blank'>github.com/wikimedia</a> that is not labeled as archived or marked as a fork of an upstream project. Please see our <a href='https://www.mediawiki.org/wiki/Reporting_security_bugs' target='_blank'>disclosure policy</a> for additional exclusions to scope."
34+
},
35+
{
36+
"contentnewsType": "paragraph",
37+
"content": "To date, <a href='/PartnerInformation/ListofPartners'>410 CNAs</a> (408 CNAs and 2 CNA-LRs) from <a href='/ProgramOrganization/CNAs'>40 countries</a> and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. Wikimedia Foundation is the 222nd CNA from USA."
38+
},
39+
{
40+
"contentnewsType": "paragraph",
41+
"content": "Wikimedia Foundation’s Root is the <a href='/PartnerInformation/ListofPartners/partner/mitre'>MITRE Top-Level Root</a>."
42+
}
43+
]
44+
},
45+
{
46+
"id": 415,
47+
"newsType": "news",
48+
"title": "Mammotome Added as CVE Numbering Authority (CNA)",
49+
"urlKeywords": "Mammotome Added as CNA",
50+
"date": "2024-10-01",
51+
"description": [
52+
{
53+
"contentnewsType": "paragraph",
54+
"content": "<a href='/PartnerInformation/ListofPartners/partner/MyMMT'>Mammotome</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for all Mammotome products."
55+
},
56+
{
57+
"contentnewsType": "paragraph",
58+
"content": "To date, <a href='/PartnerInformation/ListofPartners'>409 CNAs</a> (407 CNAs and 2 CNA-LRs) from <a href='/ProgramOrganization/CNAs'>40 countries</a> and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. Mammotome is the 221st CNA from USA."
59+
},
60+
{
61+
"contentnewsType": "paragraph",
62+
"content": "Mammotome’s Root is the <a href='/PartnerInformation/ListofPartners/partner/icscert'>CISA ICS Root</a>."
63+
}
64+
]
65+
},
366
{
467
"id": 412,
568
"newsType": "blog",

0 commit comments

Comments
 (0)