Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20161121202816.GA26926@tunkki>
Date: Mon, 21 Nov 2016 22:28:16 +0200
From: Henri Salo <henri@...v.fi>
To: Scott Gravelle <scottg@...rezzio.com>
Cc: oss-security@...ts.openwall.com
Subject: Re: Multiple XSS vulnerabilities affecting five
 WordPress Plugins

On Mon, Nov 21, 2016 at 04:56:13PM +0000, Scott Gravelle wrote:
> Any plans to get CVEs assigned to these vulnerabilities you guys found?  Our
> vulnerability scanner does not have a feature to filter off OVE

Maybe you should start handling OVE and other IDs too. Two reasons:

1) MITRE is not always assigning CVEs for WordPress plugin and theme
vulnerabilities for unknown reason. It's not like the CVEs are running out
2) MITRE is not assigning CVEs to all software that has previously received a
CVE, silently dropping the software to out-of-scope area. Example case:
http://www.openwall.com/lists/oss-security/2016/11/10/6

-- 
Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.