Settings

Theme

The curl website now features text alerting about NVD “abuse”

twitter.com

2 points by samueloph 3 years ago · 2 comments

Reader

samuelophOP 3 years ago

"Alert: if you look up curl CVEs in public sources like NVD you will find they use inflated severity levels and CVSS scores. They think they know better and override our assessments. This is a systemic error that we unfortunately cannot fix. Feel free to complain to them - we keep doing it to no use - and consider using our material as the canonical sources for curl issues."

jruohonen 3 years ago

While it is well-documented that there are erroneous assignments, I think it is still better that a vendor-independent body does the scoring. Though, the presence of CNAs kind of admittedly downplays this line of argumentation.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection