wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
306 stars 61 forks source link

Use of tracking ID to identify cloud vulnerabilities #56

Open optionsit opened 2 years ago

optionsit commented 2 years ago

While some vulnerabilities like omigod would have CVE IDs referenced, others would not be suitable for a CVE (either because of a lack of patch/fixes or because it is fixed automatically by the vendor and no action is required from the customer's perspective).

is there a plan to have a specific tracking ID notation for the open-cvdb project, something like CVDB-2022-xxxx, in the same fashion as CVE IDs, the year would match the year of publication for retro-active assignments .

This would help when referencing and keeping track of specific vulnerabilities in advisories, articles, disclosures and so on.