Skip to content

Commit 6b5ef3b

Browse files
committed
Merge pull request #3134 from branch 'origin/main' into dev
2 parents b18c1fa + 9cb6c6b commit 6b5ef3b

10 files changed

Lines changed: 2085 additions & 1325 deletions

File tree

77.7 KB
Loading

src/assets/data/CNAsList.json

Lines changed: 231 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -8460,16 +8460,16 @@
84608460
"country": "Taiwan"
84618461
},
84628462
{
8463-
"shortName": "SNPS",
8463+
"shortName": "BlackDuck",
84648464
"cnaID": "CNA-2021-0013",
8465-
"organizationName": "Synopsys",
8466-
"scope": "All Synopsys SIG products, as well as vulnerabilities in third-party software discovered by Synopsys SIG that are not in another CNA’s scope",
8465+
"organizationName": "Black Duck Software, Inc.",
8466+
"scope": "All Black Duck (formerly Synopsys Software Integrity Group) products, as well as vulnerabilities in third-party software discovered by Black Duck that are not in another CNA’s scope",
84678467
"contact": [
84688468
{
84698469
"email": [
84708470
{
84718471
"label": "Email",
8472-
"emailAddr": "psirt@synopsys.com"
8472+
"emailAddr": "psirt@blackduck.com"
84738473
}
84748474
],
84758475
"contact": [],
@@ -8480,15 +8480,15 @@
84808480
{
84818481
"label": "Policy",
84828482
"language": "",
8483-
"url": "https://www.synopsys.com/company/legal/vulnerability-disclosure-policy.html"
8483+
"url": "https://www.blackduck.com/company/legal/vulnerability-disclosure-policy.html"
84848484
}
84858485
],
84868486
"securityAdvisories": {
84878487
"alerts": [],
84888488
"advisories": [
84898489
{
84908490
"label": "Advisories",
8491-
"url": "https://www.synopsys.com/blogs/software-security/"
8491+
"url": "https://www.blackduck.com/blog/category.cyrc.html#1"
84928492
}
84938493
]
84948494
},
@@ -21606,7 +21606,7 @@
2160621606
"country": "USA"
2160721607
},
2160821608
{
21609-
"shortName": "GitHub, Inc.",
21609+
"shortName": "OS-S",
2161021610
"cnaID": "CNA-2024-0031",
2161121611
"organizationName": "OpenSource Security GmbH",
2161221612
"scope": "Vulnerabilities discovered by or reported to OpenSource Security, unless covered by another CNA’s scope",
@@ -23479,5 +23479,229 @@
2347923479
]
2348023480
},
2348123481
"country": "Taiwan"
23482+
},
23483+
{
23484+
"shortName": "Pall",
23485+
"cnaID": "CNA-2024-0065",
23486+
"organizationName": "Pall Corporation",
23487+
"scope": "Pall branded products only",
23488+
"contact": [
23489+
{
23490+
"email": [
23491+
{
23492+
"label": "Email",
23493+
"emailAddr": "productsecurity@pall.com"
23494+
}
23495+
],
23496+
"contact": [],
23497+
"form": []
23498+
}
23499+
],
23500+
"disclosurePolicy": [
23501+
{
23502+
"label": "Policy",
23503+
"language": "",
23504+
"url": "https://www.pall.com/en/about-pall/product-security-cvd.html"
23505+
}
23506+
],
23507+
"securityAdvisories": {
23508+
"alerts": [],
23509+
"advisories": [
23510+
{
23511+
"label": "Advisories",
23512+
"url": "https://www.pall.com/en/about-pall/product-security-cvd/known-vulnerabilities.html"
23513+
}
23514+
]
23515+
},
23516+
"resources": [],
23517+
"CNA": {
23518+
"isRoot": false,
23519+
"root": {
23520+
"shortName": "icscert",
23521+
"organizationName": "Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS)"
23522+
},
23523+
"roles": [
23524+
{
23525+
"helpText": "",
23526+
"role": "CNA"
23527+
}
23528+
],
23529+
"TLR": {
23530+
"shortName": "CISA",
23531+
"organizationName": "Cybersecurity and Infrastructure Security Agency (CISA)"
23532+
},
23533+
"type": [
23534+
"Vendor"
23535+
]
23536+
},
23537+
"country": "USA"
23538+
},
23539+
{
23540+
"shortName": "MyMMT",
23541+
"cnaID": "CNA-2024-0066",
23542+
"organizationName": "Mammotome",
23543+
"scope": "All Mammotome products",
23544+
"contact": [
23545+
{
23546+
"email": [],
23547+
"contact": [
23548+
{
23549+
"label": "Mammotome Report a Vulnerability page",
23550+
"url": "https://www.mammotome.com/us/en/legal/product-security/report-a-security-vulnerability"
23551+
}
23552+
],
23553+
"form": []
23554+
}
23555+
],
23556+
"disclosurePolicy": [
23557+
{
23558+
"label": "Policy",
23559+
"language": "",
23560+
"url": "https://www.mammotome.com/us/en/legal/product-security/product-security-overview"
23561+
}
23562+
],
23563+
"securityAdvisories": {
23564+
"alerts": [],
23565+
"advisories": [
23566+
{
23567+
"label": "Advisories",
23568+
"url": "https://www.mammotome.com/us/en/legal/product-security/product-security-updates"
23569+
}
23570+
]
23571+
},
23572+
"resources": [],
23573+
"CNA": {
23574+
"isRoot": false,
23575+
"root": {
23576+
"shortName": "icscert",
23577+
"organizationName": "Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS)"
23578+
},
23579+
"roles": [
23580+
{
23581+
"helpText": "",
23582+
"role": "CNA"
23583+
}
23584+
],
23585+
"TLR": {
23586+
"shortName": "CISA",
23587+
"organizationName": "Cybersecurity and Infrastructure Security Agency (CISA)"
23588+
},
23589+
"type": [
23590+
"Vendor"
23591+
]
23592+
},
23593+
"country": "USA"
23594+
},
23595+
{
23596+
"shortName": "wikimedia-foundation",
23597+
"cnaID": "CNA-2024-0067",
23598+
"organizationName": "The Wikimedia Foundation",
23599+
"scope": "Any code repository hosted under <a href='https://gerrit.wikimedia.org' target='_blank'>gerrit.wikimedia.org</a>, <a href='https://gitlab.wikimedia.org' target='_blank'>gitlab.wikimedia.org</a>, or <a href='https://github.com/wikimedia' target='_blank'>github.com/wikimedia</a> that is not labeled as archived or marked as a fork of an upstream project. Please see our <a href='https://www.mediawiki.org/wiki/Reporting_security_bugs' target='_blank'>disclosure policy</a> for additional exclusions to scope",
23600+
"contact": [
23601+
{
23602+
"email": [
23603+
{
23604+
"label": "Email",
23605+
"emailAddr": "security@wikimedia.org"
23606+
}
23607+
],
23608+
"contact": [],
23609+
"form": []
23610+
}
23611+
],
23612+
"disclosurePolicy": [
23613+
{
23614+
"label": "Policy",
23615+
"language": "",
23616+
"url": "https://www.mediawiki.org/wiki/Reporting_security_bugs"
23617+
}
23618+
],
23619+
"securityAdvisories": {
23620+
"alerts": [],
23621+
"advisories": [
23622+
{
23623+
"label": "Advisories",
23624+
"url": "https://gitlab.wikimedia.org/repos/security/wikimedia-cve-assignments"
23625+
}
23626+
]
23627+
},
23628+
"resources": [],
23629+
"CNA": {
23630+
"isRoot": false,
23631+
"root": {
23632+
"shortName": "n/a",
23633+
"organizationName": "n/a"
23634+
},
23635+
"roles": [
23636+
{
23637+
"helpText": "",
23638+
"role": "CNA"
23639+
}
23640+
],
23641+
"TLR": {
23642+
"shortName": "mitre",
23643+
"organizationName": "MITRE Corporation"
23644+
},
23645+
"type": [
23646+
"Open Source"
23647+
]
23648+
},
23649+
"country": "USA"
23650+
},
23651+
{
23652+
"shortName": "RTI",
23653+
"cnaID": "CNA-2024-0068",
23654+
"organizationName": "Real-Time Innovations, Inc.",
23655+
"scope": "All RTI Connext products, including EOL products. See <a href='https://www.rti.com/products' target='_blank'>https://www.rti.com/products</a> for more information",
23656+
"contact": [
23657+
{
23658+
"email": [
23659+
{
23660+
"label": "Email",
23661+
"emailAddr": "security@rti.com"
23662+
}
23663+
],
23664+
"contact": [],
23665+
"form": []
23666+
}
23667+
],
23668+
"disclosurePolicy": [
23669+
{
23670+
"label": "Policy",
23671+
"language": "",
23672+
"url": "https://community.rti.com/static/documentation/connext-dds/current/doc/vulnerabilities/#rti-s-approach-to-vulnerability-detection-and-management"
23673+
}
23674+
],
23675+
"securityAdvisories": {
23676+
"alerts": [],
23677+
"advisories": [
23678+
{
23679+
"label": "Advisories",
23680+
"url": "https://community.rti.com/static/documentation/connext-dds/current/doc/vulnerabilities/#"
23681+
}
23682+
]
23683+
},
23684+
"resources": [],
23685+
"CNA": {
23686+
"isRoot": false,
23687+
"root": {
23688+
"shortName": "n/a",
23689+
"organizationName": "n/a"
23690+
},
23691+
"roles": [
23692+
{
23693+
"helpText": "",
23694+
"role": "CNA"
23695+
}
23696+
],
23697+
"TLR": {
23698+
"shortName": "mitre",
23699+
"organizationName": "MITRE Corporation"
23700+
},
23701+
"type": [
23702+
"Vendor"
23703+
]
23704+
},
23705+
"country": "USA"
2348223706
}
2348323707
]

src/assets/data/currentBoardMembersList.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -43,8 +43,8 @@
4343
"familyName": "Cox",
4444
"firstName": "William",
4545
"imageURL": "",
46-
"organization": "Synopsys, Inc.",
47-
"organizationURL": "https://www.synopsys.com/",
46+
"organization": "Black Duck Software, Inc.",
47+
"organizationURL": "https://www.blackduck.com/",
4848
"role": "Board"
4949
},
5050
{

src/assets/data/events.json

Lines changed: 15 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -2,23 +2,10 @@
22
"currentEvents": [
33
{
44
"id": 34,
5-
"title": "CVE/FIRST VulnCon 2025",
6-
"location": "Raleigh, North Carolina, USA & Virtual",
7-
"description": "VulnCon 2025 is co-sponsored by the <a href='/'>CVE Program</a> and <a href='https://www.first.org/' target='_blank'>FIRST</a> and is open to the public.<br/><br/><strong>SPECIAL MESSAGE FOR CVE NUMBERING AUTHORITIES (CNAs)</strong>:<br/><i>VulnCon 2025 takes the place of this year’s Spring CVE Global Summit.</i><br/><br/><strong>Program Overview</strong>:<br/>* Day 1: Monday, April 7 &mdash; TBA<br/>* Day 2: Tuesday, April 8 &mdash; TBA<br/>* Day 3: Wednesday, April 9 &mdash; TBA <br/>* Day 4: Thursday, April 10 &mdash; TBA<br/><br/><strong>Agenda</strong>:<br/> TBA<br/><br/> <strong>Call for Papers</strong>:<br/>TBA<br/><br/><strong>Registration</strong>:<br/><ul><li>Standard Admission (by March 9, 2025): US $300.00</li><li>Late Rate Admission (after March 9, 2025): US $375.00</li><li>Virtual Admission: US $100.00</li></ul>Registration fees include four days of coffee breaks and buffet lunches, one networking reception hosted at the McKimmon Center, and applicable meeting materials. Note that discounted rates are not being offered for this event regardless of membership or speaking status.<br/><br/>An After Party will be tentatively hosted off-site with tickets to be sold separately. More information to come. Tickets will cost US $25.00.<br/><br/>Registration will open in November 2024.<br/><br/><strong>Venue</strong>:<br/><a href='https://facilities.ofa.ncsu.edu/building/mck/' target='_blank'>McKimmon Center,<br/>North Carolina State University</a>,<br/>1101 Gorman St.,<br/> Raleigh, North Carolina 27606<br/>USA<br/><br/><strong>Purpose</strong>:<br/>The purpose of <a href='https://www.first.org/conference/vulncon2025/' target='_blank'>VulnCon</a> is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.<br/><br/>A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.",
8-
"permission": "public",
9-
"url": "https://www.first.org/conference/vulncon2025/",
10-
"date": {
11-
"start": "2025-04-07",
12-
"end": "2025-04-10",
13-
"repeat": false
14-
}
15-
},
16-
{
17-
"id": 33,
185
"displayOnHomepageOrder": 1,
196
"title": "CVE Program Workshop – Autumn 2024",
207
"location": "Virtual",
21-
"description": "A collaborative virtual community event of CVE Partners focused on improving CVE.<br/><br/>Event Time: 10:00 AM to 2:00 PM EDT both days. Additional Details: TBA<br/><br/>Workshop “save the date” sent September 5, 2024.",
8+
"description": "A collaborative virtual community event of CVE Partners focused on improving CVE.<br/><br/>Event Time: 10:00 AM to 2:00 PM EDT both days.<br/><br/>Workshop “save the date” announcement, with expected topics and other details, sent to partners on September 19, 2024.",
229
"permission": "private",
2310
"url": "",
2411
"date": {
@@ -27,6 +14,20 @@
2714
"repeat": false
2815
}
2916
},
17+
{
18+
"id": 33,
19+
"displayOnHomepageOrder": 2,
20+
"title": "CVE/FIRST VulnCon 2025",
21+
"location": "Raleigh, North Carolina, USA & Virtual",
22+
"description": "VulnCon 2025 is co-sponsored by the <a href='/'>CVE Program</a> and <a href='https://www.first.org/' target='_blank'>FIRST</a> and is open to the public.<br/><br/><strong>SPECIAL MESSAGE FOR CVE NUMBERING AUTHORITIES (CNAs)</strong>:<br/><i>VulnCon 2025 takes the place of this year’s Spring CVE Global Summit.</i><br/><br/><strong>Program Overview</strong>:<br/>* Day 1: Monday, April 7 &mdash; TBA<br/>* Day 2: Tuesday, April 8 &mdash; TBA<br/>* Day 3: Wednesday, April 9 &mdash; TBA <br/>* Day 4: Thursday, April 10 &mdash; TBA<br/><br/><strong>Agenda</strong>:<br/> TBA<br/><br/> <strong>Call for Papers</strong>:<br/>TBA<br/><br/><strong>Registration</strong>:<br/>Registration will open in November 2024.<br/><ul><li>Standard Admission (by March 9, 2025): US $300.00</li><li>Late Rate Admission (after March 9, 2025): US $375.00</li><li>Virtual Admission: US $100.00</li></ul>Registration fees include four days of coffee breaks and buffet lunches, one networking reception hosted at the McKimmon Center, and applicable meeting materials. Note that discounted rates are not being offered for this event regardless of membership or speaking status.<br/><br/>An After Party will be tentatively hosted off-site with tickets to be sold separately. More information to come. Tickets will cost US $25.00.<br/><br/><strong>Venue</strong>:<br/><a href='https://facilities.ofa.ncsu.edu/building/mck/' target='_blank'>McKimmon Center,<br/>North Carolina State University</a>,<br/>1101 Gorman St.,<br/> Raleigh, North Carolina 27606<br/>USA<br/><br/><strong>Purpose</strong>:<br/>The purpose of <a href='https://www.first.org/conference/vulncon2025/' target='_blank'>VulnCon</a> is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.<br/><br/>A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.",
23+
"permission": "public",
24+
"url": "https://www.first.org/conference/vulncon2025/",
25+
"date": {
26+
"start": "2025-04-07",
27+
"end": "2025-04-10",
28+
"repeat": false
29+
}
30+
},
3031
{
3132
"id": 32,
3233
"title": "Vulnerability Conference and Events Working Group (VCEWG)",

src/assets/data/faqs.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -104,7 +104,7 @@
104104
"questionId": "cve_nvd_relationship",
105105
"questionText": "What is the relationship between CVE and the NVD (U.S. National Vulnerability Database)",
106106
"questionResponseParagraphs": [
107-
"<a href='/'>CVE</a> and <a href='https://nvd.nist.gov/' target='_blank'>NVD</a> are two separate programs. The CVE List was launched by the MITRE Corporation as a community effort in 1999. The U.S. National Vulnerability Database (NVD) was launched by the National Institute of Standards and Technology (NIST) in 2005. While separate, output from both programs is available to the public and free to use."
107+
"<a href='/'>CVE</a> and <a href='https://nvd.nist.gov/' target='_blank'>NVD</a> are two separate programs. The CVE List was launched by the MITRE Corporation as a community effort in 1999. The U.S. National Vulnerability Database (NVD) was launched by the National Institute of Standards and Technology (NIST) in 2005. The CVE List feeds NVD, which historically has built upon the information included in CVE Records to provide enhanced information for each record in its database. While separate, output from both programs is available to the public and free to use."
108108
]
109109
}
110110
]

src/assets/data/metrics.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
},
1010
{
1111
"quarter": "2",
12-
"value": "TBA"
12+
"value": "11,716"
1313
},
1414
{
1515
"quarter": "3",
@@ -553,7 +553,7 @@
553553
"data": [
554554
{
555555
"quarter": "all",
556-
"value": "13,499"
556+
"value": "26,028"
557557
}
558558
]
559559
},
@@ -1161,11 +1161,11 @@
11611161
},
11621162
{
11631163
"month": "September",
1164-
"value": "7"
1164+
"value": "8"
11651165
},
11661166
{
11671167
"month": "October",
1168-
"value": "TBA"
1168+
"value": "3"
11691169
},
11701170
{
11711171
"month": "November",

0 commit comments

Comments
 (0)