|
|
|
|
|
by philipwhiuk
862 days ago
|
|
> noone should ever be able to file a CVE without the product owner having a say in this. That's a really stupid idea. CVEs track security vulnerabilities, not 'security vulnerabilities the product owner is prepared to admit to'. Imagine if Cisco decided they were going to be the CNA for Cisco devices just weren't going to issue any CVEs for any vulnerabilities in any Cisco devices, regardless of whether they're exploited or not. |
|