CVE data quality problems



Looking at some CVE's and I'm seeing a lot of:



"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},






so 1/6 are "n/a", this seems like a lot of garbage data. Is this correct?
--
Ah crud, I forgot a CVE JSON can have multiple product_name entries, regardless that makes the data worse, I checked and there appears to be no overlap of data/"n/a" in 2020,


Looking at some CVE's and I'm seeing a lot of:

"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},


"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},



"value": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3."




--


--



Previous Email: CVE data quality problems

Next Email: New CNA - Samsung Mobile

January 2021 Email Index