Skip to content

Commit 2400318

Browse files
committed
Merge branch 'int-main' of https://github.com/CVEProject/cve-website into tat-3180-logo
2 parents 6caea3b + 2b763e5 commit 2400318

9 files changed

Lines changed: 406 additions & 19 deletions

File tree

src/assets/data/CNAsList.json

Lines changed: 170 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23720,5 +23720,175 @@
2372023720
]
2372123721
},
2372223722
"country": "USA"
23723+
},
23724+
{
23725+
"shortName": "PingCAP",
23726+
"cnaID": "CNA-2024-0069",
23727+
"organizationName": "PingCAP (US), Inc.",
23728+
"scope": "Vulnerabilities in the following PingCAP maintained products and components: TiDB (code available at <a href='https://github.com/pingcap/tidb' target='_blank'>https://github.com/pingcap/tidb</a>); TiKV (code available at <a href='https://github.com/tikv/tikv' target='_blank'>https://github.com/tikv/tikv</a>); PD (Placement Driver, code available at <a href='https://github.com/tikv/pd' target='_blank'>https://github.com/tikv/pd</a>); TiFlash (code available at <a href='https://github.com/pingcap/tiflash' target='_blank'>https://github.com/pingcap/tiflash</a>); and tidbcloud (PingCAP’s cloud database service). This scope includes vulnerabilities in all supported versions of these products. CVE IDs will not be assigned for vulnerabilities found in unsupported versions or for third-party dependencies not maintained by PingCAP",
23729+
"contact": [
23730+
{
23731+
"email": [
23732+
{
23733+
"label": "Email",
23734+
"emailAddr": "security@pingcap.com"
23735+
}
23736+
],
23737+
"contact": [],
23738+
"form": []
23739+
}
23740+
],
23741+
"disclosurePolicy": [
23742+
{
23743+
"label": "Policy",
23744+
"language": "",
23745+
"url": "https://www.pingcap.com/security/"
23746+
}
23747+
],
23748+
"securityAdvisories": {
23749+
"alerts": [],
23750+
"advisories": [
23751+
{
23752+
"label": "Advisories",
23753+
"url": "https://www.pingcap.com/security/"
23754+
}
23755+
]
23756+
},
23757+
"resources": [],
23758+
"CNA": {
23759+
"isRoot": false,
23760+
"root": {
23761+
"shortName": "n/a",
23762+
"organizationName": "n/a"
23763+
},
23764+
"roles": [
23765+
{
23766+
"helpText": "",
23767+
"role": "CNA"
23768+
}
23769+
],
23770+
"TLR": {
23771+
"shortName": "mitre",
23772+
"organizationName": "MITRE Corporation"
23773+
},
23774+
"type": [
23775+
"Vendor",
23776+
"Open Source",
23777+
"Hosted Service"
23778+
]
23779+
},
23780+
"country": "USA"
23781+
},
23782+
{
23783+
"shortName": "OMRON",
23784+
"cnaID": "CNA-2024-0070",
23785+
"organizationName": "OMRON Corporation",
23786+
"scope": "Omron Group companies’ Industrial Automation, Healthcare, Social Systems, Device &amp; Module Solutions issues only",
23787+
"contact": [
23788+
{
23789+
"email": [],
23790+
"contact": [
23791+
{
23792+
"label": "OMRON PSIRT Contact page",
23793+
"url": "https://www.omron.com/contact/ContactForm.do?FID=00282"
23794+
}
23795+
],
23796+
"form": []
23797+
}
23798+
],
23799+
"disclosurePolicy": [
23800+
{
23801+
"label": "Policy",
23802+
"language": "",
23803+
"url": "https://www.omron.com/contact/ContactForm.do?FID=00282"
23804+
}
23805+
],
23806+
"securityAdvisories": {
23807+
"alerts": [],
23808+
"advisories": [
23809+
{
23810+
"label": "Advisories",
23811+
"url": "https://www.omron.com/global/en/inquiry/vulnerability_information/"
23812+
}
23813+
]
23814+
},
23815+
"resources": [],
23816+
"CNA": {
23817+
"isRoot": false,
23818+
"root": {
23819+
"shortName": "jpcert",
23820+
"organizationName": "JPCERT/CC"
23821+
},
23822+
"type": [
23823+
"Vendor"
23824+
],
23825+
"TLR": {
23826+
"shortName": "mitre",
23827+
"organizationName": "MITRE Corporation"
23828+
},
23829+
"roles": [
23830+
{
23831+
"helpText": "",
23832+
"role": "CNA"
23833+
}
23834+
]
23835+
},
23836+
"country": "Japan"
23837+
},
23838+
{
23839+
"shortName": "CSA",
23840+
"cnaID": "CNA-2024-0071",
23841+
"organizationName": "Cyber Security Agency of Singapore",
23842+
"scope": "Vulnerabilities reported to CSA unless covered by the scope of another CNA",
23843+
"contact": [
23844+
{
23845+
"email": [
23846+
{
23847+
"label": "Email",
23848+
"emailAddr": "singcert@csa.gov.sg"
23849+
}
23850+
],
23851+
"contact": [],
23852+
"form": []
23853+
}
23854+
],
23855+
"disclosurePolicy": [
23856+
{
23857+
"label": "Policy",
23858+
"language": "",
23859+
"url": "https://www.csa.gov.sg/Tips-Resource/Resources/singcert/singcert-vulnerability-disclosure-policy"
23860+
}
23861+
],
23862+
"securityAdvisories": {
23863+
"alerts": [],
23864+
"advisories": [
23865+
{
23866+
"label": "Advisories",
23867+
"url": "https://www.csa.gov.sg/alerts-advisories"
23868+
}
23869+
]
23870+
},
23871+
"resources": [],
23872+
"CNA": {
23873+
"isRoot": false,
23874+
"root": {
23875+
"shortName": "n/a",
23876+
"organizationName": "n/a"
23877+
},
23878+
"roles": [
23879+
{
23880+
"helpText": "",
23881+
"role": "CNA"
23882+
}
23883+
],
23884+
"TLR": {
23885+
"shortName": "mitre",
23886+
"organizationName": "MITRE Corporation"
23887+
},
23888+
"type": [
23889+
"CERT"
23890+
]
23891+
},
23892+
"country": "Singapore"
2372323893
}
2372423894
]

src/assets/data/currentBoardMembersList.json

Lines changed: 0 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -31,14 +31,6 @@
3131
"organizationURL": "https://www.mitre.org/",
3232
"role": "MITRE At-Large"
3333
},
34-
{
35-
"familyName": "Cox",
36-
"firstName": "Mark",
37-
"imageURL": "",
38-
"organization": "",
39-
"organizationURL": "",
40-
"role": "Board"
41-
},
4234
{
4335
"familyName": "Cox",
4436
"firstName": "William",

src/assets/data/events.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@
3535
"displayOnHomepageOrder": 2,
3636
"title": "CVE/FIRST VulnCon 2025",
3737
"location": "Raleigh, North Carolina, USA & Virtual",
38-
"description": "VulnCon 2025 is co-sponsored by the <a href='/'>CVE Program</a> and <a href='https://www.first.org/' target='_blank'>FIRST</a> and is open to the public.<br/><br/><strong>SPECIAL MESSAGE FOR CVE NUMBERING AUTHORITIES (CNAs)</strong>:<br/><i>VulnCon 2025 takes the place of this year’s Spring CVE Global Summit.</i><br/><br/><strong>Program Overview</strong>:<br/>* Day 1: Monday, April 7 &mdash; TBA<br/>* Day 2: Tuesday, April 8 &mdash; TBA<br/>* Day 3: Wednesday, April 9 &mdash; TBA <br/>* Day 4: Thursday, April 10 &mdash; TBA<br/><br/><strong>Agenda</strong>:<br/> TBA<br/><br/> <strong>Call for Papers</strong>:<br/>TBA<br/><br/><strong>Registration</strong>:<br/>Registration will open in November 2024.<br/><ul><li>Standard Admission (by March 9, 2025): US $300.00</li><li>Late Rate Admission (after March 9, 2025): US $375.00</li><li>Virtual Admission: US $100.00</li></ul>Registration fees include four days of coffee breaks and buffet lunches, one networking reception hosted at the McKimmon Center, and applicable meeting materials. Note that discounted rates are not being offered for this event regardless of membership or speaking status.<br/><br/>An After Party will be tentatively hosted off-site with tickets to be sold separately. More information to come. Tickets will cost US $25.00.<br/><br/><strong>Venue</strong>:<br/><a href='https://facilities.ofa.ncsu.edu/building/mck/' target='_blank'>McKimmon Center,<br/>North Carolina State University</a>,<br/>1101 Gorman St.,<br/> Raleigh, North Carolina 27606<br/>USA<br/><br/><strong>Purpose</strong>:<br/>The purpose of <a href='https://www.first.org/conference/vulncon2025/' target='_blank'>VulnCon</a> is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.<br/><br/>A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.",
38+
"description": "VulnCon 2025 is co-sponsored by the <a href='/'>CVE Program</a> and <a href='https://www.first.org/' target='_blank'>FIRST</a> and is open to the public.<br/><br/><strong>SPECIAL MESSAGE FOR CVE NUMBERING AUTHORITIES (CNAs)</strong>:<br/><i>VulnCon 2025 takes the place of this year’s Spring CVE Global Summit.</i><br/><br/><strong>Call for Papers</strong>:<br/>Open until January 31, 2025. Details <a href='https://www.first.org/conference/vulncon2025/cfp' target='_blank'>here</a>.<br/><br/><strong>Program Overview</strong>:<br/>* Day 1: Monday, April 7 &mdash; TBA<br/>* Day 2: Tuesday, April 8 &mdash; TBA<br/>* Day 3: Wednesday, April 9 &mdash; TBA <br/>* Day 4: Thursday, April 10 &mdash; TBA<br/><br/><strong>Agenda</strong>:<br/> TBA<br/><br/> <strong>Call for Papers</strong>:<br/>TBA<br/><br/><strong>Registration</strong>:<br/>Registration will open in November 2024.<br/><ul><li>Standard Admission (by March 9, 2025): US $300.00</li><li>Late Rate Admission (after March 9, 2025): US $375.00</li><li>Virtual Admission: US $100.00</li></ul>Registration fees include four days of coffee breaks and buffet lunches, one networking reception hosted at the McKimmon Center, and applicable meeting materials. Note that discounted rates are not being offered for this event regardless of membership or speaking status.<br/><br/>An After Party will be tentatively hosted off-site with tickets to be sold separately. More information to come. Tickets will cost US $25.00.<br/><br/><strong>Venue</strong>:<br/><a href='https://facilities.ofa.ncsu.edu/building/mck/' target='_blank'>McKimmon Center,<br/>North Carolina State University</a>,<br/>1101 Gorman St.,<br/> Raleigh, North Carolina 27606<br/>USA<br/><br/><strong>Purpose</strong>:<br/>The purpose of <a href='https://www.first.org/conference/vulncon2025/' target='_blank'>VulnCon</a> is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.<br/><br/>A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.",
3939
"permission": "public",
4040
"url": "https://www.first.org/conference/vulncon2025/",
4141
"date": {

src/assets/data/faqs.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
"questionId": "what_is_cve",
88
"questionText": "What is CVE",
99
"questionResponseParagraphs": [
10-
"<i>The CVE Program is celebrating 25 years of impact in cybersecurity! Read the <a href='/Resources/Media/Cve25YearsAnniversaryReport.pdf'>CVE 25th Anniversary Report</a>.</i>",
10+
"<i>The Common Vulnerabilities and Exposures (CVE<sup>®</sup>) Program is celebrating 25 years of impact in cybersecurity! Read the <a href='/Resources/Media/Cve25YearsAnniversaryReport.pdf'>CVE 25th Anniversary Report</a>.</i>",
1111
"The mission of the Common Vulnerabilities and Exposures (CVE<sup>®</sup>) Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. See the <a href='/About/Overview'>Overview</a> page for additional information."
1212
]
1313
},
@@ -96,7 +96,7 @@
9696
"questionId": "working_groups",
9797
"questionText": "What are the CVE Working Groups (WGs) and how can I participate",
9898
"questionResponseParagraphs": [
99-
"<a href='/ResourcesSupport/Glossary?activeTerm=glossaryWG'>CVE WGs</a> actively focus on improving processes, workflows, and other aspects of the program as CVE continues to grow and expand. Current WGs focus on the following topics: Automation (AWG), CNA Organization of Peers (COOP), Outreach and Communications (OCWG), Quality (QWG), Strategic Planning (SPWG), Tactical (TWG), and Vulnerability Conference and Events (VCEWG).",
99+
"<a href='/ResourcesSupport/Glossary?activeTerm=glossaryWG'>CVE WGs</a> actively focus on improving processes, workflows, and other aspects of the program as CVE continues to grow and expand. Current WGs focus on the following topics: Automation (AWG), CNA Organization of Peers (COOP), CVE Artificial Intelligence (CVEAI), Outreach and Communications (OCWG), Quality (QWG), Strategic Planning (SPWG), Tactical (TWG), and Vulnerability Conference and Events (VCEWG).",
100100
"For additional information, see <a href='/ProgramOrganization/WorkingGroups#HowToJoin'>How to Join</a> and <a href='/ProgramOrganization/WorkingGroups#MeetingSchedule'>Meeting Schedule</a> on the Working Groups page."
101101
]
102102
},
@@ -478,4 +478,4 @@
478478
}
479479
]
480480
}
481-
]
481+
]

src/assets/data/metrics.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1165,7 +1165,7 @@
11651165
},
11661166
{
11671167
"month": "October",
1168-
"value": "3"
1168+
"value": "6"
11691169
},
11701170
{
11711171
"month": "November",

0 commit comments

Comments
 (0)