[
Date Prev][
Date Next][
Thread Prev][
Thread Next][
Date Index][
Thread Index]
Re: CVE Entry Quality Working Group
On Mon, Nov 26, 2018 at 8:32 AM Coffin, Chris <ccoffin@mitre.org> wrote:
>
> Board Members,
>
>
>
> The CVE team would like to judge your level of interest in
> establishing a CVE Entry Quality Working Group. The main focus of the
> group would be on improving the quality of CVE entry content. The
> output of the group would be best practices and guidelines on how to
> generate a CVE entry, and possibly propose changes to the CNA Rules.
>
>
>
> Example issues the group could cover include:
>
> Should the CVSS vector be allowed in a CVE Entry description?
> What is the best way to describe relationships between products (e.g.
> Product A bundles Product B)?
> If the only public data for two different vulnerabilities would
> result in an identical description, what should be done?
>
>
>
> Would the Board be interested in establishing the CVE Entry Quality
> Working Group, and are any Board members interested in stepping up to
> be the chair? Please respond by Friday Nov 30.
>
>
>
> The CVE Team
Great idea, and I'd like to participate in this.
--
Regards,
Ken Williams
Vulnerability Response Director, Product Vulnerability Response Team
CA Technologies, A Broadcom Company, 520 Madison Av, 22nd Floor, NY NY
10022
Office: +1 631 533 7151 | Mobile: +1 816 914 4225 |
Ken.Williams@broadcom.com