You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CSAF producer methods currently do include the following information that is present in Vulnerability Advisories from VINCE https://kb.cert.org/vuls/ .
The proposed updates should include
Use vulnerability[]/release_date to provide date in the future for Embargoed/private CSAF documents via private authenticated API. Vulnerability release_date in CSAF format to be copied from "Expected Date Public"
Add TLP statements to CSAF document for private authenticated API Section 3.2.1.5.2 from CSAF guidance doc.
Add disclosure timeline and include vendors who have been notified and not responded to a vulnerability disclosure as per section 3.2.3.7.
CSAF producer methods currently do include the following information that is present in Vulnerability Advisories from VINCE https://kb.cert.org/vuls/ .
The proposed updates should include
vulnerability[]/release_date
to provide date in the future for Embargoed/private CSAF documents via private authenticated API. Vulnerability release_date in CSAF format to be copied from "Expected Date Public"See Issue in @oasis-tcs for discussion.
oasis-tcs/csaf#586
The text was updated successfully, but these errors were encountered: