Skip to content

Reporting Capability For CVE Records That Have Inaccurate Information on Affected Versions  #21

@PluginVulnerabilities

Description

@PluginVulnerabilities

Proposed New Idea/Feature (required)

You are providing information on which versions of software are vulnerable, which would be really useful if the information was accurate. But a number of your CNAs are known to not actually figure out which versions are vulnerable, but instead claim that all previous versions before the fixed version are vulnerable, despite not knowing that and it often not being true. For example, CVE-2023-6875 has gotten some press coverage. With the press coverage claiming all versions before 2.8.8 are vulnerable. That is in line with the information provided by the CVE record. The CVE’s description of the issue says “all versions up to, and including, 2.8.7.” The version section provides the same information. But the feature at issue has only been in the software since version 2.7.0, so that couldn’t be right. Similarly, we saw a hacker this week trying to exploit a vulnerability that may be identified by you with CVE-2023-6634. The record claims that “all versions up to, and including, 4.2.5.7” are vulnerable. But the code being exploited was added in version 4.2.5.7, so if that record is related, as it appears, the version information is wrong.

There are other issues. For example, with CVE-2023-52215, the description says that the versions impacted are “n/a through 1.5.1”. The version section says that it is "affected from n/a through 1.5.1." There is not a not applicable version of the plugin.

Currently, there isn’t a mechanism to report this situation with a CVE record and therefore a method to monitor for CNAs repeatedly providing inaccurate information. Adding a mechanism for that would help to address the problem. It is possible to contact a CNA about this, but as we mentioned earlier, the CNAs are known to provide inaccurate information, so contacting them wouldn't address this.

Additional Notes (Optional)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions