[
Date Prev][
Date Next][
Thread Prev][
Thread Next][
Date Index][
Thread Index]
RE: CVE for hosted services
How do I use a CVE for a service vuln to check if my environment was affected and if so, that my ops have applied the proper remedies?
Tom Millar, US-CERT
Sent from +1-202-631-1915
https://www.us-cert.gov
From: owner-cve-editorial-board-list@lists.mitre.org on behalf of Kurt Seifried
Sent: Friday, February 24, 2017 3:44:39 PM
To: Art Manion
Cc: jericho; Booth, Harold (Fed); cve-editorial-board-list
Subject: Re: CVE for hosted services
So uhh I'll just leave this example here:
I know for example on the CloudSecurityAlliance side I now need to forcibly reset every password for all our websites, and look at the third parties we do auth from (e.g. FaceBook/Linkedin) to see if they are affected (not that there is much we can do
other than notify people).