You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Lets consider a CVE c that impacts a product with version x. This CVE is fixed in product version y.
According to OpenVEX Specs, field 'Action_Statement' under 'Statement' can contain data for fixes/mitigations.
When constructing VEX report for x, would it be right to show c with status 'Affected' and put both x & y under 'Action_Statement' ?
P.S. I'm not sure of the correct forum to ask this, but found this repo active.
Please redirect me if this is not the right place.
The text was updated successfully, but these errors were encountered:
shanu-26
changed the title
Use of Action_Statement for "Affected" CVEs
Use of "Action_Statement" for "Affected" CVEs
Mar 28, 2024
Lets consider a CVE c that impacts a product with version x. This CVE is fixed in product version y.
According to OpenVEX Specs, field 'Action_Statement' under 'Statement' can contain data for fixes/mitigations.
When constructing VEX report for x, would it be right to show c with status 'Affected' and put both x & y under 'Action_Statement' ?
P.S. I'm not sure of the correct forum to ask this, but found this repo active.
Please redirect me if this is not the right place.
The text was updated successfully, but these errors were encountered: