oss-sec mailing list archives

Re: Multiple XSS vulnerabilities affecting five WordPress Plugins


From: Henri Salo <henri () nerv fi>
Date: Mon, 21 Nov 2016 22:28:16 +0200

On Mon, Nov 21, 2016 at 04:56:13PM +0000, Scott Gravelle wrote:
Any plans to get CVEs assigned to these vulnerabilities you guys found?  Our
vulnerability scanner does not have a feature to filter off OVE

Maybe you should start handling OVE and other IDs too. Two reasons:

1) MITRE is not always assigning CVEs for WordPress plugin and theme
vulnerabilities for unknown reason. It's not like the CVEs are running out
2) MITRE is not assigning CVEs to all software that has previously received a
CVE, silently dropping the software to out-of-scope area. Example case:
http://www.openwall.com/lists/oss-security/2016/11/10/6

-- 
Henri Salo


Current thread: