Repository navigation
Creating security advisory and requesting CVE through fork? (or alternatives) #970
BackgroundAt the beginning of the year I reported a vulnerability to a maintainer and contributed a fix. The maintainer published a new release containing the fix soon after. The problem is since then how to create a security advisory and to request a CVE. So to me and the maintainer it looked like MITRE was the right CNA to approach. I submitted the CVE request on February 1st but never got a response since then1. In my last mail to MITRE in July I mentioned to them that I might try another CNA, but also did not get a response there. Therefore I went looking for other CNAs which accept reports for open source projects and found Snyk. However, I did not get any response from them either and in the meantime they changed their policy to not accept reports for open source projects anymore, see https://snyk.io/report-a-vulnerability/. So now I am still in the situation that the vulnerability has been fixed about 10 months ago but there is still no advisory nor CVE for it. Caution Please don't try to guess which project this is about and especially don't mention the project here or anywhere else publicly. It would just be a waste of your and my time, since the whole point of this here is to disclose it, but properly. QuestionSo my question is now, can I just create a fork of the repository, enable private vulnerability reporting there, create the advisory, invite the maintainer and then finally publish the advisory (to make it appear in the global GitHub advisory database eventually) and request a CVE? Also, what will happen if I then delete my fork; will that break things for the advisory? I know that this is not the 'proper' way, but everything else failed so far (as mentioned above), and I am also not that keen on continuing to wait any further for MITRE to respond maybe1. Or what alternatives exist? Given the large increase in advisories and CVEs I doubt that there still is any other CNA which accepts CVE requests for open source projects. The last resort would of course be to just publish a repository advisory in my fork (or create some kind of write-up), and then hope that some CNA somehow through social media or some other means becomes aware of it and publishes the CVE. Footnotes
|
Replies: 1 comment 2 replies
|
Hi @Marcono1234, GitHub doesn't issue CVEs to forks that are created for security research purposes. The only time we consider issuing a CVE to a forked project is if the original project is unmaintained and the fork is being actively maintained, rather than just created for fixing a specific bug or conducting security research. There are a number of other CNAs that accept vulnerability reports from independent security researchers, including Vulncheck (which primarily operates in AMER time zones) and VulDB (which primarily operates in EMEA time zones). |
Hi @Marcono1234, GitHub doesn't issue CVEs to forks that are created for security research purposes. The only time we consider issuing a CVE to a forked project is if the original project is unmaintained and the fork is being actively maintained, rather than just created for fixing a specific bug or conducting security research.
There are a number of other CNAs that accept vulnerability reports from independent security researchers, including Vulncheck (which primarily operates in AMER time zones) and VulDB (which primarily operates in EMEA time zones).