As discussed with the community at #SuriCon2023, we have started requesting CVE IDs for security issues in #Suricata. Security releases will list CVE IDs of issues fixed.
For more info: https://forum.suricata.io/t/security-new-cve-policy/
Security: new CVE policy
As discussed with the community at Suricon 2023, we have started requesting CVE IDs for security issues in Suricata. There was already a “security” ticket class in our ticketing system, so generally we’ll get a CVE ID assigned to these. After consulting Mitre, we’ve started using Github as our CNA, through the Github Security Advisories facility. Previously, CVE IDs were requested by reporters of security issues, at their digression. This caused most “security” releases, to not have CVE IDs ass...
