|
|
|
|
|
by littlestymaar
209 days ago
|
|
> However, things get annoying once something ends up on some priority list (like the Known Exploited Vulnerabilities list from CISA), you ship the software in a much older version, and there is no reproducer There are known exploited vulnerabilities without PoC? TIL and that doesn't sound fun at all indeed. |
|
And access to the reproducer is merely a replacement for lack of public vulnerability-to-commit mapping for software that has a public version control repository.