BrianKrebs on Nostr: It seems like there are a lot of unknowns at this point about what exactly will ...
It seems like there are a lot of unknowns at this point about what exactly will happen this week with CVE, but here's more of what I've gathered: CVEs will still be issued to CNAs, or CVE Numbering Authorities, i.e. vendors, researchers, open source, CERT, hosted service, bug bounty provider, and consortium organizations authorized by the CVE Program to assign CVE IDs to vulnerabilities and publish CVE records within their own specific scopes of coverage.
The CVE has an API for CNAs to obtain CVEs, and as long as that's still running there will be new CVEs. So, not a complete stop to CVEs being issued. But MITRE does have a more manual process for issuing CVEs to non-CNAs, and that may be impacted this week.
Published at
2025-04-15 21:54:34Event JSON
{
"id": "0475ff5532e95c2bd84383a6a285b785d832b3338273256eeb3388d277658fc4",
"pubkey": "1a5ac5b37984c5e37a11bc914029a81f025326ea7950c9475d9a3f21a494cb56",
"created_at": 1744754074,
"kind": 1,
"tags": [
[
"e",
"78254adb5e4697179337a064e047be59b04538a82632c517e46acd462ad83973",
"wss://relay.mostr.pub",
"reply"
],
[
"proxy",
"https://infosec.exchange/users/briankrebs/statuses/114344203019345999",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.mostr.pub"
]
],
"content": "It seems like there are a lot of unknowns at this point about what exactly will happen this week with CVE, but here's more of what I've gathered: CVEs will still be issued to CNAs, or CVE Numbering Authorities, i.e. vendors, researchers, open source, CERT, hosted service, bug bounty provider, and consortium organizations authorized by the CVE Program to assign CVE IDs to vulnerabilities and publish CVE records within their own specific scopes of coverage. \n\nThe CVE has an API for CNAs to obtain CVEs, and as long as that's still running there will be new CVEs. So, not a complete stop to CVEs being issued. But MITRE does have a more manual process for issuing CVEs to non-CNAs, and that may be impacted this week.",
"sig": "0689e82facac4839efada37547fd50545dd705d70c6af3955881c2e73bba0ed282d0c1152f10bf328527b8fea9afe8e7bb18c09763b402e4ede45005fa4d3aca"
}