You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Note: VINCE currently can generate CVE JSON, a future request will be to integrate CVE ID submission to whatever appropriate service, which may or may not be the IDR.
Probably use this, which currently supports some user/org management and CVE ID management and requests (but not yet submitting CVE IDs, which the services don't support yet either).
Request CVE IDs, probably in the vulnerability UI in a case
Track/report/manage requested and assigned CVE IDs
Publish/post/submit CVE IDs, probably in or near the vulnerability note UI, but independent of publishing the vulnerability note
4 will require collecting and verifying minimum required information for a valid CVE entry. Description can come from existing vulnerability description field.
VINCE should support CVE ID assignment, including pool management for a CNA, using the developing CVE Program services (e.g., authentication and IDR).
https://github.com/CVEProject/cve-services/wiki/Developer-Guide-to-CVE-Services-API
https://github.com/RedHatProductSecurity/cvelib
The text was updated successfully, but these errors were encountered: