Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add optional CAPEC to vulnerabilities #766

Open
CERT-VDE opened this issue Aug 9, 2024 · 2 comments
Open

Add optional CAPEC to vulnerabilities #766

CERT-VDE opened this issue Aug 9, 2024 · 2 comments
Assignees
Labels
csaf 2.x Maybe future

Comments

@CERT-VDE
Copy link

CERT-VDE commented Aug 9, 2024

It should be possible to add MITREs Common Attack Pattern Enumerations and Classifications (CAPEC) to a vulnerability in CSAF. This field should be optional like it is in CVE entries and may be an array of multiple CAPECs.
This may add information to CSAF advisories that help to asses risks of a vulnerability.

@tschmidtb51
Copy link
Contributor

@CERT-VDE The comments mailing list is now back online. Please formally announce your suggestion there, e.g. through "Please see our suggest in Github Issue XYZ (https://github.com/oasis-tcs/csaf/issues/XYZ)."

Thank you!

@tschmidtb51 tschmidtb51 added csaf 2.x Maybe future and removed tc-discussion-needed labels Sep 25, 2024
@santosomar
Copy link
Contributor

During the TC meeting on September 25, 2024, we discussed the prioritization of including CAPEC in CSAF 2.1. The consensus was to consider this for a future release rather than for 2.1. Please share any additional use cases or suggestions for reprioritization in the comments section of this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
csaf 2.x Maybe future
Projects
None yet
Development

No branches or pull requests

4 participants
@santosomar @CERT-VDE @tschmidtb51 and others