[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: Affected Product Information in the CSAF 2.0 Draft Schema
|
Hi folks,
One of the action items from the Oct 31st meeting was to resurrect the discussion about the product information in the CSAF 2.0 draft schema and also to do a comparison with MITREâs CVE schema.
The following is the current MITRE CVE schema:
This is how the product element is structured in the MITRE CVE schema:
It is very simple and elegant; less complicated that CSAF/CVRF. However, this is mostly because a CSAF/CVRF document can have multiple CVEs (vulnerabilities) and it can also list affected, not affected, patch levels, and other elements.
The following is our current CSAF 2.0 draft schema:
A vulnerability can have âproduct statusâ
Then under product_status:
Which in my opinion, the values still relevant and we should not change them. My question is more around the branch_product and the product_tree elements (below): is there an opportunity to simplify them?
and
As you can see, the full_product_name has the CPE element/property. As we discussed in the previous meetings, a generic product identification element is more appropriate (which can support any identifier or reference to SWID, SPDX, etc.) I will
start that conversation on a separate thread to not mix the two here.
Your thoughts here and during the meeting would be greatly appreciated.
|
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]