Skip to content

Content of CVE text, and propagation of updates #136182

Answered by anargam
anargam asked this question in Code Security
Discussion options

You must be logged in to vote

According the Github copilot help

Remember, once a CVE is published, any changes or updates to the CVE text need to be made through MITRE directly, as GitHub does not have control over the content of the CVE database.

When prompted with this information that the CNA should do this (according to MITRE) it says

If you're not the repository owner or don't have the necessary permissions, you should ask the repository owner to contact GitHub Support for further assistance. They can provide the updated information for the CVE, and GitHub Support will handle the update process with MITRE.

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by anargam
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Code Security Build security into your GitHub workflow with features to keep your codebase secure Question inactive This discussion has been automatically marked as inactive. This was formerly labeled stale.
1 participant