[MDEV-11207] Docs Request: Create Security Matrix for CVEs Created: 2016-11-01  Updated: 2018-11-29  Due: 2017-06-26  Resolved: 2018-11-29

Status: Closed
Project: MariaDB Server
Component/s: Documentation
Fix Version/s: N/A

Type: Task Priority: Major
Reporter: Chris Calender (Inactive) Assignee: Daniel Bartholomew
Resolution: Fixed Votes: 0
Labels: security


 Description   

I'd like to propose that we add a security matrix on our site for CVEs that exist and are fixed, like Oracle does for MySQL here:

http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html#AppendixMSQL

Note the CVSS Version 3 Metrics are [apparently] puled from here:

https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6304

Thank you for your consideration.



 Comments   
Comment by Daniel Black [ 2016-11-01 ]

https://mariadb.com/kb/en/mariadb/security/ is sufficient?

Comment by Chris Calender (Inactive) [ 2016-11-02 ]

This is great.

However, do you think we could add one more link, for each CVE, that goes to the web.nvd.nist.gov site (which contains the CVSS Version 3 Metrics/Scores)?

Here is an example link:

https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6304

This would make it a one-stop shop, so-to-speak, and then we could avoid the whole "matrix".

Comment by Rasmus Johansson (Inactive) [ 2018-07-31 ]

Check last comment from Chris. Could we add that link for each CVE?

Comment by Sergei Golubchik [ 2018-08-10 ]

It's normally available from the CVE page. Like our CVE-2012-5614 link points to http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5614. And at the top of that page there's a link Learn more at National Vulnerability Database (NVD)

Comment by Daniel Bartholomew [ 2018-10-09 ]

In the KB any CVE-XXXX-XXXX text is automatically turned into a link to cve.mitre.org using the built-in auto-link feature. This feature doesn't have a way to turn a single CVE ID into two separate links, not right now at least. Such a thing could be added, but it would require a rewrite of the auto-link feature to allow for a single bit of text to be transformed into multiple links. bryan would know more about how feasible this would be.

Generated at Thu Feb 08 07:48:08 UTC 2024 using Jira 8.20.16#820016-sha1:9d11dbea5f4be3d4cc21f03a88dd11d8c8687422.