Hi,
I don’t know if this is the right E-mail to send my question but I hope you’ll be able to answer 😊
I use NIST website to search for a specific CPE : https://nvd.nist.gov/products/cpe/search and view the corresponding CVEs
For example, I tested with Grafana v8.3.4 having CPE name : cpe:2.3:a:grafana:grafana:8.3.4:*:*:*:*:*:*:* and I found it and was able to view its CVEs.
Unfortunately, I’m not able to find Grafana v9.5.2 with the Search button (I used following CPE name : cpe:2.3:a:grafana:grafana:9.5.2:*:*:*:*:*:*:*) but in CPE dictionary it doesn’t exist.
I tested with others products & versions like Kafka, OpenJDK, Tomcat and sometimes for some versions I’m able to see the CPE name with its CVEs and sometimes I can’ t
That’s why, I was wondering if it can be due to NIST database or CPE dictionary that are not up to date ?? and I just need to wait a couple of days/months
Can it be related to the product’s provider that has not given the new CPE name for a new released version (to be written into the CPE dictionary) ?
I don’t understand ☹
Hope you understand my question
Kind regards
Sounds like an NVD question. Try following up with [email protected].
--
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to
[email protected]
Visit this group at https://list.nist.gov/scap-dev
---
To unsubscribe from this group and stop receiving emails from it, send an email to
[email protected].
Maya,
You may want to consider this work around: We basically submit any new CPE with its official links to the NVD and then they add that data to the CPE dictionary after their review. Do you currently build a proprietary CVE/CPE library, you might consider doing so. Let’s us know if that helps, however, we do not currently support non-US operations.
Jonathan
US ProTech
ANAMO CDM
From: 'Maya & Arthur' via SCAP Discussion and Development <[email protected]>
Sent: Tuesday, August 1, 2023 7:35 AM
To: SCAP Discussion and Development <[email protected]>
Subject: [scap-dev] CPE name not found in CPE dictionary
Hi,
--
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [email protected]
Visit this group at https://list.nist.gov/scap-dev
---
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].