| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
![]() |
原始链接: https://news.ycombinator.com/item?id=43700607
合同续签失败威胁着CVE项目,这是一个至关重要的网络安全资源。美国国家标准与技术研究院(NIST)维护的国家漏洞数据库(NVD)的资金削减已经持续了一年多,导致漏洞积压日益严重。虽然CVE项目由MITRE管理,但NIST的NVD通过评分和分析丰富了CVE数据,使其成为广泛依赖的资源。 安全界担心可能会有越来越多的漏洞得不到解决,一些漏洞已经在野外被利用。美国网络安全与基础设施安全局(CISA)正在启动“Vulnrichment”项目,为CVE添加更多信息。NVD和CVE项目几年来一直面临着积压和资金问题,大多数安全厂商要么对及时提供漏洞信息守口如瓶(因为这可能会降低他们自身的竞争优势),要么试图推销他们自己的替代风险优先级评分。 诸如合作联盟之类的替代方案正在考虑中,但尚未实现。这种中断引发了人们对美国失去其技术和科学领导地位以及潜在的安全风险增加的担忧。
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
![]() |
April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann...
Sep 2024, Yocto Project, "An open letter to the CVE Project and CNAs", https://github.com/yoctoproject/cve-cna-open-letter/blob/mai...> Security and vulnerability handling in software is of ever increasing importance. Recent events have adversely affected many project's ability to identify and ensure these issues are addressed in a timely manner. This is extremely worrying.. Until recently many of us were relying not on the CVE project's data but on the NVD data that added that information.
Five years ago (2019), I helped to organize a presentation by CERT Director which covered the CVE backlog and lack of resources, e.g. many vulnerabilities reported never even receive a CVE number. It has since averaged less than a hundred views per year, even as the queue increased and funding decreased, https://www.youtube.com/watch?v=WmC65VrnBPI
reply