Replies: 1 comment
-
It seems there is generally no "sync" done in both ways (at least partly) because i have also seen the opposite: Within the Mire CVE entry more recent info was found in comparison to the GHSA advisory. One example: GHSA-r4wh-9cw3-v2jg which lists Adobe Premiere Pro as being affected while actually Adobe Bridge is the affected product (got changed later in the Mitre CVE entry) On a related note: I also wonder how the "Reject" state is handled / synced, e.g. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
That happened in the past:
CVE-2023-30451
via Mitre and published their findings directlyCVE-2023-30451
This is the scenario today:
GHSA-w6x2-jg8h-p6mp
(e.g. version ranges, fixes, assessment & description)Thanks in advance for any guidance on this topic 🙏
Beta Was this translation helpful? Give feedback.
All reactions