Skip to content

Commit e6260f6

Browse files
committed
CNAs (plural) and address issue #7.
Signed-off-by: Art Manion <zmanion@protonmail.com>
1 parent f799532 commit e6260f6

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

CNA_Rules.md

+3-1
Original file line numberDiff line numberDiff line change
@@ -435,6 +435,8 @@ CNAs are constrained to assigning CVE IDs to Vulnerabilities within their Scope
435435

436436
4.2.20 To help minimize duplicate assignments, CNAs SHOULD consider coordinating with an appropriate Root or CNA-LR before assigning CVE IDs for Publicly Disclosed Vulnerabilities. See 4.2.1.2 for more specific guidance.
437437

438+
4.2.21 CNAs SHOULD assign the year portion of a CVE ID based on the calendar year in which the vulnerability was first publicly disclosed.
439+
438440
### 4.3 Notification
439441

440442
4.3.1 When a CNA becomes aware of a non-public Vulnerability report, CVE ID request, or CVE ID assignment that is only covered by the Scope Definition of a different CNA, the first CNA SHOULD either refer the reporter or requester to or attempt to notify the appropriate CNA.
@@ -486,7 +488,7 @@ This section specifies actions related to publishing and managing CVE Records.
486488

487489
4.5.2 Publishing Vulnerability Information
488490

489-
4.5.2.1 CNA MUST publish Vulnerability advisories or other information about Vulnerabilities for which the CNA has assigned CVE IDs and published CVE Records. Such information SHOULD meet the public references requirements in [5.3](#53-public-references) and MAY be used as a public reference (see 5.3.1.1).
491+
4.5.2.1 CNAs MUST publish Vulnerability advisories or other information about Vulnerabilities for which the CNA has assigned CVE IDs and published CVE Records. Such information SHOULD meet the public references requirements in [5.3](#53-public-references) and MAY be used as a public reference (see 5.3.1.1).
490492

491493
4.5.2.2 Supplier CNAs MUST have at least one distribution point, such as a web site, where the CNA publishes Vulnerability advisories or other information about Vulnerabilities for which the CNA has assigned CVE IDs and published CVE Records. This Vulnerability information MUST reference appropriate CVE IDs.
492494

0 commit comments

Comments
 (0)