Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How security vulnerabilities for this package is tracked in NIST/NVD? #48

Open
vaibhav-rustagi opened this issue Nov 24, 2021 · 4 comments
Labels

Comments

@vaibhav-rustagi
Copy link

Hi,

I was trying to find cpe_uri associated with this package in NIST/NVD so that COS (https://cloud.google.com/container-optimized-os/docs) can track security vulnerabilities associated with it. However, based on the search there was no cpe_uri associated.

Could you help in providing information as what cpe_uri can be used by downstream users to track security vulnerability in this package from NIST/NVD?

@ThomasHabets
Copy link
Owner

What's cpe_uri?

@vaibhav-rustagi
Copy link
Author

cpe is a structured format which covers information about vendor and software provided by them. More information can be found at: https://nvd.nist.gov/products/cpe, https://csrc.nist.gov/Projects/Security-Content-Automation-Protocol/Specifications/cpe

For tracking security vulnerabilities in any software used, NVD is generally being tracked for finding vulnerabilities based on CPE associated with each vulnerability. Example: https://nvd.nist.gov/vuln/detail/CVE-2021-41617 where we can see cpe:2.3:a:openbsd:openssh: / cpe:2.3:o:fedoraproject:fedora:34 are the CPE's. Downstream users of the package tracks a cpe for vulnerability and if NVD has a vulnerability which matches with the cpe monitored by downstream, then downstream users can triage the vulnerability to see if they are affected or not.

@ThomasHabets
Copy link
Owner

I'm not aware of arping having a cpu_uri, either formally or informally.

I dunno, could cpe:2.3:a:thomashabets:arping:[…] make sense?

@vaibhav-rustagi
Copy link
Author

I think above make sense. But in order to add it to NVD, I think you need to contact: [email protected] (as per https://nvd.nist.gov/products/cpe).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants