#curl has been a CNA for a year now daniel.haxx.se/blog/2024/01/16…
curl is a CNA
The curl project has been accepted as a CVE Numbering Authority (CNA) for vulnerabilities in all products directly made or managed by the project. If I'm counting correctly, we are the 351st CNA.daniel.haxx.se
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •The short summary of if it has been worth the hassle: yeah I think so. It is now easy and fast to get new CVE IDs. We have a seat at a table where I can complain loudly on the system and what I say actually might have a (small) impact.
We have yet to deny someone else's crazy CVE attempts against curl.
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •Martin Schröder
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Martin Schröder • • •curl - CVEs
curl.sedaniel:// stenberg://
Unknown parent • • •curl - Vulnerability Disclosure Policy
curl.se