IETF Disclosure Policies



I mentioned on the last board call that the IETF is working on disclosure policies, which could lead to some interest in working with the CVE program. I believe this is an opportunity for the board and the secretariat to engage more with the IETF community.

Here is some information on their current efforts:

For the infrastructure and services provided and operated by the IETF Adminsitration LLC:

For vulnerabilities in IETF protocols and specifications:

Regards,

Dave




Next Email: New CVE logo is now live

December 2020 Email Index