Skip to content

VEX-like status and justification options #7

@zmanion

Description

@zmanion

Support VEX status and justifications as optional?

See also CVEProject/cve-schema#478.

Status

VEX CVE
not_affected unaffected
affected affected
fixed unaffected
under_investigation unknown
? unknown

Justification

VEX requires justification (or an impact statement) for "not_affected" status.

For [status] “not_affected”, a VEX statement SHOULD provide [justification].
If [justification] is not provided then [impact_statement] MUST be provided.

"component_not_present"
"vulnerable_code_not_present"
"vulnerable_code_not_in_execute_path"
"vulnerable_code_cannot_be_controlled_by_adversary"
“inline_mitigations_already_exist"

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions