Curated articles, resources, tips and trends from the DevOps World.
Summary: This is a summary of an article originally published by The New Stack. Read the full original article here →
Anyone who works in the software industry knows that stigma can be attached to CVEs, or “common vulnerabilities and exposures” assignments. This is driven by misconceptions that can make vendors and open source maintainers reluctant to request a CVE, which reduces transparency and ultimately puts software security at risk.
Is the issue bad enough to justify the effort of getting an assignment?
So why are vendors and open source maintainers hesitant to request CVEs, even if the vulnerability is minor?
Responsible vendors and maintainers, as a matter of practice, request CVEs and publish advisories, even for minor vulnerabilities.
Made with pure grit © 2024 Jetpack Labs Inc. All rights reserved. www.jetpacklabs.com