[HN Gopher] Bogus CVE Follow-Ups
___________________________________________________________________
Bogus CVE Follow-Ups
Author : HieronymusBosch
Score : 41 points
Date : 2023-09-05 17:19 UTC (5 hours ago)
(HTM) web link (daniel.haxx.se)
(TXT) w3m dump (daniel.haxx.se)
| orf wrote:
| CVEs are not what they once (ever?) where. With the proliferation
| of automated systems involved with vulnerability management and
| dependency updates, it's possible for a single GitHub PR close
| event to create a CVE for an issue that verifiably, 100% does not
| actually exist[1].
|
| Interesting times ahead.
|
| 1. https://tomforb.es/cve-2022-0329-and-the-problems-with-
| autom...
| tedunangst wrote:
| Related: https://opensourcewatch.beehiiv.com/p/now-postgresqls-
| turn-b...
| voakbasda wrote:
| This situation exposes some arbitrary and capricious aspects of
| the CVE process, which in turn devalues the entire system. It
| makes me personally less likely to take any of their assessments
| at face value, and I imagine others will feel the same. That is a
| net loss for security.
| delfinom wrote:
| CVEs have been questionable for awhile as I have seen quite a
| few over the years that amount to "the attacker already has
| root on the machine".
|
| The problem now, is we are entering a phase of the general IT
| market due to government mandates and insurers for all kinds of
| cybersecurity junkware. Following a CVE database and pushing
| scary CVEs are basically the end result and the overreaction
| will still be the same as many of the cybersecurity positions
| are no different than checklist readers since companies don't
| want to pay for actual engineers or skilled sysadmins.
| donutshop wrote:
| Been seeing an uptick of researchers using CVEs to get street
| cred. There definitely should be better governance with how
| things are done.
___________________________________________________________________
(page generated 2023-09-05 23:02 UTC)