vulnerablecode
vulnerablecode copied to clipboard
Handle CPE data in Vulnerablecode
-
NVD provides too much details on CPEs https://nvd.nist.gov/vuln/detail/CVE-2011-4136 with fully enumerated CPE ranges, that put a lot of data under references.
-
We need to know which CPE references are interesting, this may require new models and structures
-
CPEs should be referred as a package alias rather than a vulnerability reference.
I think that point 3 is most important and addressing that may mitigate the other problems with too much CPE data.