Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Clearly state what not mentioning a product in product_status means #850

Open
tschmidtb51 opened this issue Dec 18, 2024 · 0 comments
Open

Comments

@tschmidtb51
Copy link
Contributor

We need to clearly state that the interpretation for products not given in the CSAF document is "there is no information in that CSAF document about this product".

Reasoning

There are multiple ways to structure a CSAF document, e.g.

  • 1 vulnerability, 1 product
  • n vulnerabilities, 1 product
  • 1 vulnerability, m products
  • n vulnerabilities, m products

Usually, the CSAF documents are assembled during a coordination case and contain the findings of the case which might be any of the combinations above. Sometimes, the issuing party decides to do multiple CSAF documents for one case (or one to combine multiple related cases).

If a CSAF document I lists "Product A version 17.4.3" as fixed, we can't assume anything about "Product A version 17.3.3" or "Product A version 16.8.4". This might be affected, it might be fixed as well. We just know from CSAF document I that "Product A version 17.4.3" is fixed.
There might be another CSAF document II that lists "Product A version 17.3.3" as fixed. Also from that CSAF document II, we don't know anything about "Product A version 16.8.4".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant