Support VEX status and justifications as optional?
See also CVEProject/cve-schema#478.
Status
| VEX |
CVE |
| not_affected |
unaffected |
| affected |
affected |
| fixed |
unaffected |
| under_investigation |
unknown |
| ? |
unknown |
Justification
VEX requires justification (or an impact statement) for "not_affected" status.
For [status] “not_affected”, a VEX statement SHOULD provide [justification].
If [justification] is not provided then [impact_statement] MUST be provided.
"component_not_present"
"vulnerable_code_not_present"
"vulnerable_code_not_in_execute_path"
"vulnerable_code_cannot_be_controlled_by_adversary"
“inline_mitigations_already_exist"