-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
Support VEX status and justifications as optional?
See also CVEProject/cve-schema#478.
Status
| VEX | CVE |
|---|---|
| not_affected | unaffected |
| affected | affected |
| fixed | unaffected |
| under_investigation | unknown |
| ? | unknown |
Justification
VEX requires justification (or an impact statement) for "not_affected" status.
For [status] “not_affected”, a VEX statement SHOULD provide [justification].
If [justification] is not provided then [impact_statement] MUST be provided.
"component_not_present"
"vulnerable_code_not_present"
"vulnerable_code_not_in_execute_path"
"vulnerable_code_cannot_be_controlled_by_adversary"
“inline_mitigations_already_exist"
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels