Skip to content
Discussion options

You must be logged in to vote

Please see CNA operational rules that govern the allocation of CVEs:

https://www.cve.org/resourcessupport/allresources/cnarules

4.1.12 The act of updating Product dependencies MUST NOT be determined to be a Vulnerability, regardless of whether the dependencies have Vulnerabilities. For example, updating a library to address a Vulnerability in that library MUST NOT be determined to be a new Vulnerability in a Product that uses the library, and a Vulnerability advisory for the Product SHOULD reference the CVE ID for the Vulnerability in the library.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jmion2s
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Help
Labels
None yet
2 participants