Skip to content

Commit

Permalink
require CNAs to publish advisories that reference CVE IDs
Browse files Browse the repository at this point in the history
Signed-off-by: Art Manion <zmanion@protonmail.com>
  • Loading branch information
zmanion committed Dec 30, 2024
1 parent cc84e63 commit f799532
Showing 1 changed file with 5 additions and 5 deletions.
10 changes: 5 additions & 5 deletions CNA_Rules.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@

| Status | Final |
| ---: | :--- |
| Version | 4.0.0 |
| Approved | 2024-04-25 |
| Effective | 2024-05-08 |
| Version | 4.0.1 |
| Approved | 2025-mm-dd |
| Effective | 2025-mm-dd |

## Table of Contents

Expand Down Expand Up @@ -486,9 +486,9 @@ This section specifies actions related to publishing and managing CVE Records.

4.5.2 Publishing Vulnerability Information

4.5.2.1 CNA SHOULD publish Vulnerability advisories or other information about Vulnerabilities for which the CNA has assigned CVE IDs and published CVE Records. Such information SHOULD meet the public references requirements in [5.3](#53-public-references) and MAY be used as a public reference (see 5.3.1.1).
4.5.2.1 CNA MUST publish Vulnerability advisories or other information about Vulnerabilities for which the CNA has assigned CVE IDs and published CVE Records. Such information SHOULD meet the public references requirements in [5.3](#53-public-references) and MAY be used as a public reference (see 5.3.1.1).

4.5.2.2 Supplier CNAs MUST have at least one distribution point, such as a web site, where the CNA publishes Vulnerability advisories or other information about Vulnerabilities for which the CNA has assigned CVE IDs and published CVE Records. This Vulnerability information SHOULD reference appropriate CVE IDs.
4.5.2.2 Supplier CNAs MUST have at least one distribution point, such as a web site, where the CNA publishes Vulnerability advisories or other information about Vulnerabilities for which the CNA has assigned CVE IDs and published CVE Records. This Vulnerability information MUST reference appropriate CVE IDs.

4.5.2.3 The Vulnerability information described in 4.5.2.1 MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records.

Expand Down

0 comments on commit f799532

Please sign in to comment.