Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

About/Process has confusing references to "CVE Program participant" #2920

Open
ElectricNroff opened this issue Jul 2, 2024 · 1 comment
Open
Assignees
Labels
content update Content update to the website needs-discussion Needs more discussion, either with TWG or internally

Comments

@ElectricNroff
Copy link

<p>CVE Program participant requests a CVE Identifier (CVE ID).</p>

<p>CVE Program participant submits the details.</p>

This is difficult to understand, especially with the upcoming clarification to the meaning of "CVE Program participant." Perhaps both the text and graphic will need to be updated.

Step 3 might be referring to a pre-2020 scenario in which a CNA requests a CVE ID from MITRE, who processes the request manually.

As mentioned on the https://www.cve.org/ReportRequest/ReportRequestForNonCNAs page, anyone can request. They do not need to be a CVE Program participant.

In Step 5, it is unclear what "submits the details" means. Is this discussing CVE Record submission through CVE Services (automation), or a pre-submission process that envisions that the details are held by someone who is not a CNA? In the latter case, it could be reworded as "A person or organization provides the details." possibly.

Step 6 introduces the concept of "the responsible CNA," which is not previously mentioned. Maybe the "responsible CNA" is often the same as the "CVE Program participant" in Step 2? Today, it would be unusual if an individual or organization, when following this process, would benefit from reporting a vulnerability to a CVE Program participant who is not a CNA.

@dmcyber
Copy link

dmcyber commented Jul 2, 2024

Suggest updating step 2 on Process page to point here for helpful info on determining to who to report (instead of pointing to Partners list directly).

@github-project-automation github-project-automation bot moved this to Needs Triage in CVE Website Backlog Aug 22, 2024
@athu-tran athu-tran added the content update Content update to the website label Aug 23, 2024
@athu-tran athu-tran assigned athu-tran and rroberge and unassigned athu-tran Aug 23, 2024
@jdaigneau5 jdaigneau5 added the needs-discussion Needs more discussion, either with TWG or internally label Oct 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
content update Content update to the website needs-discussion Needs more discussion, either with TWG or internally
Projects
Status: Needs Triage
Development

No branches or pull requests

5 participants