podcast icon indicating copy to clipboard operation
podcast copied to clipboard

CVE, CVSS, CPE, CWE: Sharing the love of vulnerability handling

Open oej opened this issue 2 years ago • 0 comments

There is a lot of focus now on "Dependency chain security" - using automated systems to track down known (and possibly exploited) vulnerabilities. In the heart of these systems is an old and somewhat messy system of identifiers, reports and actors that I personally have no full control over who they are and what their agenda really is.

@bagder has a lot to say about CVSS...

I think it would be interesting to focus on this pot of abbreviations and highlight the good, the bad and the ugly. What's stinking and what's shimmering like gold?

And what's the way forward?

oej avatar Apr 20 '23 13:04 oej