Skip to content

Draft "bundled" tag - #491

Open
zmanion wants to merge 4 commits into
CVEProject:mainfrom
zmanion:patch-1
Open

Draft "bundled" tag#491
zmanion wants to merge 4 commits into
CVEProject:mainfrom
zmanion:patch-1

Conversation

@zmanion

@zmanion zmanion commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Draft to add a "bundled" tag conveying that a CVE ID and Record identify multiple vulnerabilities.

Draft to add a "bundled" tag conveying that a CVE ID and Record identify multiple vulnerabilities.
Comment thread schema/tags/cna-tags.json

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was done in some haste to demonstrate that adding a tag is technically simple during a CVE Board meeting. Might choose a different word or definition. Add to adp-tags also. May also want a corresponding URL reference type tag. Either the CNA or the Program ADP can set these.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Slightly revised text, added "bundled" tag to ADP and reference tags. Also removed an outdated reference to a FIRST.org list of public VDBs.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should probably cause a non-breaking schema version bump, I don't see where to record this, probably the schema itself should contain it's version?

@darakian

Copy link
Copy Markdown
Contributor

Are bundled advisories counter to the stated goal of the cve program?

The mission of the CVE™ Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. There is one CVE Record for each vulnerability in the catalog. The vulnerabilities are discovered then assigned and published by organizations from around the world that have partnered with the CVE Program. Partners publish CVE Records to communicate consistent descriptions of vulnerabilities. Information technology and cybersecurity professionals use CVE Records to ensure they are discussing the same issue, and to coordinate their efforts to prioritize and address the vulnerabilities.

https://www.cve.org/About/Overview

The sentence There is one CVE Record for each vulnerability in the catalog. in particular pops out at me. What do you think?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants