A good way to make developers not care about CVEs, and therefore allow attackers to introduce real vulnerabilities, is to post lots of fake CVEs so nobody pays attention.
A good way to make developers not care about CVEs, and therefore allow attackers to introduce real vulnerabilities, is to post lots of fake CVEs so nobody pays attention.
> a recently growing pattern involves newbie security enthusiasts and bug bounty hunters ostensibly "collecting" CVEs to enrich their resume
Naturally, such a reporter would value higher severity reports.
I haven't really thought that much about the CVE process. It's kind of strange to me that Github, Snyk, and the NVD may all have different evaluations of a report. I guess decentralization is a feature, but one not without bugs.
However, the severity score of 9.8 [1]
Whereas a remotely exploitable remote code execution bug in a windows wifi driver only scores 8.8 [2]
So the score seems very inflated to me.
[1] https://nvd.nist.gov/vuln/detail/CVE-2023-42282 [2] https://msrc.microsoft.com/update-guide/vulnerability/CVE-20...
don't get me wrong, it is an issue, but not critical, making everything critical, for frontend libs on npm creates fatigue and nobody takes these scores seriously anymore. in case of real issue, nobody will care enough to patch it, as everything is critical.
the difference: you can find affected openssh servers, with the node-ip issue you have to find very rare instance that would allow for SSRF and create exploit for the exact use case. with openssh you can make it really broad.
so the 9.8 score for node-ip is crazy high, and nobody should question it, it should be ~6 max
I would agree that the CVSS is not, in this instance, measuring something particularly related to the practical importance of the vulnerability. I agree nobody can really dispute that. But does that mean that the next version of CVSS should include "I bet not many systems are exposed" or "I subjectively think this isn't that bad" dimensions? I'm skeptical - that seems like it would create more problems than it solves.
because i'm checking dependabot [0][1] regularly, there is a lot of issues with very high scores for frontend libraries, that have really low impact, because it "checks" some features. eg some plugin for jquery (frontend lib) [2] that has the same score as heartbleed, which is insane and shows how useless the score is in current form.
- https://docs.github.com/en/code-security/dependabot/dependab...