CVE - CVE Assignment Information Format (2024)

The information on this page is excerpted from “Appendix B: CVE Information Format” of the “CVE Numbering Authorities (CNA) Rules” document, and provides the required Format, a Correctly Formatted Example, and information about the JSON Submission and Storage Format.

Format

CVE Numbering Authorities (CNAs) must provide CVE assignment information to the CNA level above them using the following format. The use of this format facilitates the automation of CVE assignment.

  1. The preferred format for submitting CVE assignment information is using the JSON schema.
  2. In a flat file, use this format:
    [CVEID]:
    [PRODUCT]:
    [VERSION]:
    [PROBLEMTYPE]:
    [REFERENCES]:
    [DESCRIPTION]:
    [ASSIGNINGCNA]:
  3. In a Comma Separated Values (CSV) file, each row should include each of these columns with CVE ID as a primary key.

There are no format limitations on the actual data, which allows for flexibility across products that may have unusual versioning or differing definitions, such as what a “problem type” means. The only exception to this is that references must be URLs. With or without this technical standard, the information referenced by each field is required for assigning a CVE ID. In all cases, the content included in CVE Entry submission must be germane to the vulnerability. The Primary CNA reserves the right to modify or reject content included in CVE assignment if it is deemed inappropriate by the Primary CNA. Any information submitted as part of a CVE Entry must be submitted in English, though CVE Entries may reference content in any language.

Where applicable, make use of industry standards when describing vulnerabilities.

[PRODUCT]

As a general guideline, [PRODUCT] should include the vendor, developer, or project name as well as the name of the actual software or hardware in which the vulnerability exists.

[VERSION]

[VERSION] should include the version, date of release, or whatever indicator that is used by vendors, developers, or projects to differentiate between releases. [VERSION] can be described with specific version numbers, ranges of versions, or “all versions before/after” a version number or date.

[PROBLEMTYPE]

As mentioned above, [PROBLEMTYPE] can include an arbitrary summary of the problem, though Common Weakness Enumerations (CWEs) are an excellent standard to use in this field.

[REFERENCES]

[REFERENCES] should be URLs pointing to a world-wide-web-based resource. For CSV and flat-file formats, they should be separated by a space. References should point to content that is relevant to the vulnerability and include at least all the details included in the CVE entry. Ideally, references should point to content that includes the CVE ID itself whenever possible. References must also be publicly available, as described in Section 2.1.1 of the CVE Numbering Authorities (CNA) Rules.

[DESCRIPTION]

The [DESCRIPTION] field is a plain language field that should describe the vulnerability with sufficient detail as to demonstrate that the vulnerability is unique. The required information listed above should be included in the [DESCRIPTION], as well as other details the author feels are relevant or necessary to show uniqueness.

Specifically, the [DESCRIPTION] field could also include:

  • An explanation of an attack type using the vulnerability;
  • The impact of the vulnerability;
  • The software components within a software product that are affected by the vulnerability; and
  • Any attack vectors that can make use of the vulnerability.

Descriptions often follow this template:

[PROBLEM TYPE] in [PRODUCT/VERSION] causes [IMPACT] when [ATTACK]

where impact and attack are arbitrary terms that should be relevant to the nature of the vulnerability.

[ASSIGNINGCNA]

The [ASSIGNINGCNA] field should include the name of the assigning CNA. CNAs should use a consistent name to facilitate searches for CVE IDs that originate from them.

Back to top

Correctly Formatted Example

Following is an example of the reporting format in use. In this case, the Sub-CNA “BigCompanySoft” is assigning a CVE ID to versions of their product.

[CVEID]: CVE-2016-123455
[PRODUCT]: BIGCOMPANYSOFT SOFTWARE PRODUCT
[VERSION]: All versions prior to version 2.5
[PROBLEMTYPE]: Arbitrary Code Execution
[REFERENCES]: http://bigcompanysoft.com/vuln/v1232.html
[DESCRIPTION]: CoreGraphics in BIGCOMPANYSOFT SOFTWARE PRODUCT before 2.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted BMP image.
[ASSIGNINGCNA]: BigCompanySoft

Back to top

JSON Submission and Storage Format

The JSON schema will be reviewed periodically. The review cycle will follow a schedule similar to this example:

First 30 days (September)

  • Open comment period including CVE Board and CNAs.
  • One or two Automation WG calls specifically set aside for discussion of proposed changes.
  • At the end of this period, no additional suggestions will be included in the revision cycle.

Next 30 days (October)

  • The community will work in one-week sprints (WG meetings and mailing list discussions) with a subset of the proposed revisions discussed during each sprint. Each subset is only to be discussed during that sprint.
  • There will be four total sprints (making this part a four-week process).
  • At the end of a sprint, if something was not resolved or discussed, it will not be included in the revision.
  • When something is resolved, any changes based on it are included within the development branch at that time.
  • At the end of all sprints, the JSON format will be finalized and sent to the Board for approval.

Next 60 days (November and December)

  • CNAs can use the development branch for testing new features and changes.

New JSON Format in Effect (January)

  • The new JSON format would take effect on January 1 of the next year. This would give CNAs two months to implement any changes to their processes that become needed after the JSON format revised.

Back to top

CVE -

CVE Assignment Information Format (2024)
Top Articles
Mortgage Rates Drop Again, Falling to Lowest Level in Almost 3 Weeks
10 Things You Had No Idea Home Insurance Actually Covers
Netronline Taxes
What Are Romance Scams and How to Avoid Them
Ups Dropoff Location Near Me
Kaydengodly
Is pickleball Betts' next conquest? 'That's my jam'
Atvs For Sale By Owner Craigslist
Fort Carson Cif Phone Number
5 Bijwerkingen van zwemmen in een zwembad met te veel chloor - Bereik uw gezondheidsdoelen met praktische hulpmiddelen voor eten en fitness, deskundige bronnen en een betrokken gemeenschap.
craigslist: south coast jobs, apartments, for sale, services, community, and events
Simple Steamed Purple Sweet Potatoes
Thotsbook Com
Drago Funeral Home & Cremation Services Obituaries
Scenes from Paradise: Where to Visit Filming Locations Around the World - Paradise
Wal-Mart 140 Supercenter Products
Tamilyogi Proxy
Sprinkler Lv2
Drift Boss 911
Juicy Deal D-Art
Noaa Duluth Mn
Mybiglots Net Associates
Jordan Poyer Wiki
Foodsmart Jonesboro Ar Weekly Ad
1979 Ford F350 For Sale Craigslist
Craigslist Rentals Coquille Oregon
New Stores Coming To Canton Ohio 2022
Pokémon Unbound Starters
Dell 22 FHD-Computermonitor – E2222H | Dell Deutschland
Ncal Kaiser Online Pay
Schooology Fcps
Motor Mounts
Fastpitch Softball Pitching Tips for Beginners Part 1 | STACK
Puerto Rico Pictures and Facts
One Credit Songs On Touchtunes 2022
Selfservice Bright Lending
Heavenly Delusion Gif
Hisense Ht5021Kp Manual
Admissions - New York Conservatory for Dramatic Arts
Main Street Station Coshocton Menu
Oriellys Tooele
Jack In The Box Menu 2022
“To be able to” and “to be allowed to” – Ersatzformen von “can” | sofatutor.com
Pain Out Maxx Kratom
Ronnie Mcnu*t Uncensored
El Patron Menu Bardstown Ky
Cryptoquote Solver For Today
Black Adam Showtimes Near Kerasotes Showplace 14
2487872771
Overstock Comenity Login
E. 81 St. Deli Menu
Latest Posts
Article information

Author: Horacio Brakus JD

Last Updated:

Views: 6046

Rating: 4 / 5 (71 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Horacio Brakus JD

Birthday: 1999-08-21

Address: Apt. 524 43384 Minnie Prairie, South Edda, MA 62804

Phone: +5931039998219

Job: Sales Strategist

Hobby: Sculling, Kitesurfing, Orienteering, Painting, Computer programming, Creative writing, Scuba diving

Introduction: My name is Horacio Brakus JD, I am a lively, splendid, jolly, vivacious, vast, cheerful, agreeable person who loves writing and wants to share my knowledge and understanding with you.