The bogus CVE problem
The bogus CVE problem
Posted Sep 22, 2023 6:46 UTC (Fri) by kunitz (subscriber, #3965)In reply to: The bogus CVE problem by florianfainelli
Parent article: The bogus CVE problem
Since there are so many software packages, nobody has the time to look at the detail of a CVE. If there is a CVE which is high or critical you have to make it disappear, regardless whether you actually use the functionality or expose the service in any way. The financial industry has the audit and governance structures to enforce such rules.
For me it looks like that dependency reduction will become very important in the industry. How open-source will deal with the requirements of the CRA will be interesting to see.
