CVE wonders:
Apache created CVE-2023-49070 to capture: "Our OFBiz product has Apache XML-RPC, which is vulnerable to CVE-2019-17570".
This seems... wrong?
If every vendor created a new CVE to capture "Hey, we use library <foo> that already has a CVE", how can this possibly scale?
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Will Dormann (wdormann@infosec.exchange)'s status on Wednesday, 17-Jan-2024 03:57:09 JSTWill Dormann