Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

List of Partners sometimes does not have correct CNA name #3354

Open
ElectricNroff opened this issue Dec 15, 2024 · 0 comments
Open

List of Partners sometimes does not have correct CNA name #3354

ElectricNroff opened this issue Dec 15, 2024 · 0 comments

Comments

@ElectricNroff
Copy link

I used the cve.org CVE Record search to search for CVE-2024-52600. Because there is an obvious mistake in the product name (it is shown as both "Statmatic" and "statamic"), I decided to look for the contact information for the CNA. Both the search results and the CVE Record detail page have the correct CNA name, which is "GitHub (Maintainer Security Advisories)"

Then I went to the https://www.cve.org/PartnerInformation/ListofPartners page, which has its own Search field. There are many partners that match the search term GitHub, so I chose the search term "maintainer" (without the quotes) instead, and the outcome was

No results found for maintainer

This seems to be caused by:

"organizationName": "GitHub, Inc.",
"scope": "CVEs requested by code owners using the GitHub Security Advisories feature and vulnerabilities affecting open source projects discovered by security researchers at GitHub or Microsoft not covered by another CNA’s scope",

I feel that it would be better if there were a direct correspondence between the CNA names shown for CVE Records (in search results and on CVE Record detail pages) and the CNA names shown in organizationName fields.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Needs Triage
Development

No branches or pull requests

1 participant