Skip to content

Conversation

@Kevin-CB
Copy link
Contributor

@Kevin-CB Kevin-CB commented Aug 14, 2023

We recently had a misunderstanding regarding the assignment of CVEs when there's a scope conflict with another CNA.
(see SECURITY-3141)

@daniel-beck
Copy link
Contributor

daniel-beck commented Aug 14, 2023

Disagree. We still handled it by coordinating with the other CNA, we just didn't assign it ourselves. This exists because we need maintainers not to go run off themselves and have CVEs assigned.

.. Work usually happens on a branch, and a corresponding pull request will be used for review.
. A *date and time of the release is coordinated* between the security team and maintainers.
The security team handles CVE ID assignment, advance notification of users, and creation of the security advisory.
The security team handles CVE ID assignment (in cases where there is no CNA scope conflict), advance notification of users, and creation of the security advisory.
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We still handled it by coordinating with the other CNA, we just didn't assign it ourselves.

Do you prefer an approach like this one ,or do you think it should not be mentioned?

Suggested change
The security team handles CVE ID assignment (in cases where there is no CNA scope conflict), advance notification of users, and creation of the security advisory.
The security team handles CVE ID assignment (assignment may require coordination with another CNA in case of a scope conflict), advance notification of users, and creation of the security advisory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants