Skip to content

2.5. Generalize CPE and CVE datasets to match user expectations #582

@MaryBak

Description

@MaryBak

Description
Our current processing excludes some CVEs (for example, those without an entry on the site). We also match certificates and CVEs to CPEs-only and not to CPE match criteria, so NIST’s NVD website may show more CPE-like entries than ours. This should be changed so that the datasets include everything (the records will also need to change to include the data that we filter on), and only our matching and other heuristics should filter them

Details for underlying issues and ideas for implementation:
Issues #468 and #483 explain the general idea. Our current processing leads to some CVEs being excluded (not having an entry on the site for example). We also match certificates and CVEs to CPEs-only and not to CPE match criteria, so NIST’s NVD website may show more CPE-like entries than ours. This should be changed so that the datasets include everything (the records will also need to change to include the data that we filter on) and only our matching and other heuristics should filter them.

Additional context
CCAT project

Metadata

Metadata

Assignees

No one assigned

    Labels

    cpeRelated to CPEscveRelated to CVEsenhancementNew feature or requestlibraryPull requests that update library/tool code

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions