Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Did I miss that CVEs are allocated for supply chain compromises nowadays?

Did I miss that CVEs are allocated for supply chain compromises nowadays?

Scheduled Pinned Locked Moved Uncategorized
18 Posts 13 Posters 71 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

    RE: https://mastodon.social/@cisakevtracker/116647846381979235

    Did I miss that CVEs are allocated for supply chain compromises nowadays?

    caspicat@infosec.exchangeC This user is from outside of this forum
    caspicat@infosec.exchangeC This user is from outside of this forum
    caspicat@infosec.exchange
    wrote last edited by
    #6

    @GossiTheDog Yes, since 2017ish, for example

    Link Preview Image
    NVD - CVE-2021-4229

    favicon

    (nvd.nist.gov)

    Link Preview Image
    NVD - CVE-2017-16054

    favicon

    (nvd.nist.gov)

    1 Reply Last reply
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      RE: https://mastodon.social/@cisakevtracker/116647845255291135

      It's not isolated, e.g.

      There's a whole bunch of these now, it looks like companies are just yolo'ing out CVEs for other companies products.

      pauliehedron@infosec.exchangeP This user is from outside of this forum
      pauliehedron@infosec.exchangeP This user is from outside of this forum
      pauliehedron@infosec.exchange
      wrote last edited by
      #7

      @GossiTheDog They found a way to justify AI costs?

      1 Reply Last reply
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        RE: https://mastodon.social/@cisakevtracker/116647845255291135

        It's not isolated, e.g.

        There's a whole bunch of these now, it looks like companies are just yolo'ing out CVEs for other companies products.

        vathpela@infosec.exchangeV This user is from outside of this forum
        vathpela@infosec.exchangeV This user is from outside of this forum
        vathpela@infosec.exchange
        wrote last edited by
        #8

        @GossiTheDog yeah, and a whole bunch of Open Source projects have had to become CNAs to keep others from issuing bullshit CVEs. Hence https://daniel.haxx.se/blog/2024/01/16/curl-is-a-cna/ and http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/ . Between that and NVD issuing CVSS scores that don't match what SMEs evaluate the same bugs as, and for that matter CVSS just being kind of bad in several ways, the whole scheme is starting to reek.

        1 Reply Last reply
        1
        0
        • R relay@relay.infosec.exchange shared this topic
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          RE: https://mastodon.social/@cisakevtracker/116647845255291135

          It's not isolated, e.g.

          There's a whole bunch of these now, it looks like companies are just yolo'ing out CVEs for other companies products.

          wdormann@infosec.exchangeW This user is from outside of this forum
          wdormann@infosec.exchangeW This user is from outside of this forum
          wdormann@infosec.exchange
          wrote last edited by
          #9

          @GossiTheDog
          A CNA that is of organization type "Researcher" can issue CVEs for anything not explicitly in another CNA's scope.
          Kaspersky is one such CNA.

          Link Preview ImageLink Preview Image
          1 Reply Last reply
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            RE: https://mastodon.social/@cisakevtracker/116647846381979235

            Did I miss that CVEs are allocated for supply chain compromises nowadays?

            merospit@infosec.exchangeM This user is from outside of this forum
            merospit@infosec.exchangeM This user is from outside of this forum
            merospit@infosec.exchange
            wrote last edited by
            #10

            @GossiTheDog Makes sense to me.

            CVE are regularly used to actually block deployment pipelines, which is a useful function for mitigating supply chain vulnerabilities.

            More generally, I wouldn't want to be forced to distinguish between active and passive threats and then not be able to label the active threats in a standard way.

            1 Reply Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              RE: https://mastodon.social/@cisakevtracker/116647846381979235

              Did I miss that CVEs are allocated for supply chain compromises nowadays?

              thepwnicorn@infosec.exchangeT This user is from outside of this forum
              thepwnicorn@infosec.exchangeT This user is from outside of this forum
              thepwnicorn@infosec.exchange
              wrote last edited by
              #11

              @GossiTheDog makes sense though if the package/software version is compromised? Whether the vulnerability stems from a bug or deliberately placed malware or backdoor, they are all vulnerabilities of some sort.

              thepwnicorn@infosec.exchangeT 1 Reply Last reply
              0
              • thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

                @GossiTheDog makes sense though if the package/software version is compromised? Whether the vulnerability stems from a bug or deliberately placed malware or backdoor, they are all vulnerabilities of some sort.

                thepwnicorn@infosec.exchangeT This user is from outside of this forum
                thepwnicorn@infosec.exchangeT This user is from outside of this forum
                thepwnicorn@infosec.exchange
                wrote last edited by
                #12

                @GossiTheDog they could of course also contribute to OSSF's malicious package DB instead. If it is a package like tanstack.

                thepwnicorn@infosec.exchangeT 1 Reply Last reply
                0
                • thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

                  @GossiTheDog they could of course also contribute to OSSF's malicious package DB instead. If it is a package like tanstack.

                  thepwnicorn@infosec.exchangeT This user is from outside of this forum
                  thepwnicorn@infosec.exchangeT This user is from outside of this forum
                  thepwnicorn@infosec.exchange
                  wrote last edited by
                  #13

                  @GossiTheDog the XZ backdoor for instance also got a CVE (CVE-2024-3094).

                  1 Reply Last reply
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    RE: https://mastodon.social/@cisakevtracker/116647845255291135

                    It's not isolated, e.g.

                    There's a whole bunch of these now, it looks like companies are just yolo'ing out CVEs for other companies products.

                    res260@infosec.exchangeR This user is from outside of this forum
                    res260@infosec.exchangeR This user is from outside of this forum
                    res260@infosec.exchange
                    wrote last edited by
                    #14

                    @GossiTheDog Yeah its weird but it started last year from what I can tell.

                    Guess malware is a vulnerability now 💀

                    1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      RE: https://mastodon.social/@cisakevtracker/116647845255291135

                      It's not isolated, e.g.

                      There's a whole bunch of these now, it looks like companies are just yolo'ing out CVEs for other companies products.

                      bontchev@infosec.exchangeB This user is from outside of this forum
                      bontchev@infosec.exchangeB This user is from outside of this forum
                      bontchev@infosec.exchange
                      wrote last edited by
                      #15

                      @GossiTheDog Weelll... If a particular version of a product has been Trojanized due to a supply-chain attack, it could be argued that this version contains a vulnerability now, no? And vulnerabilities are assigned CVEs.

                      1 Reply Last reply
                      1
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        RE: https://mastodon.social/@cisakevtracker/116647845255291135

                        It's not isolated, e.g.

                        There's a whole bunch of these now, it looks like companies are just yolo'ing out CVEs for other companies products.

                        campuscodi@mastodon.socialC This user is from outside of this forum
                        campuscodi@mastodon.socialC This user is from outside of this forum
                        campuscodi@mastodon.social
                        wrote last edited by
                        #16

                        @GossiTheDog It's because of this, prolly. They've been added to the KEV so CISA can force agencies to clean out artifacts/compromised systems

                        https://mastodon.social/@campuscodi/116648324167478081

                        gossithedog@cyberplace.socialG 1 Reply Last reply
                        0
                        • campuscodi@mastodon.socialC campuscodi@mastodon.social

                          @GossiTheDog It's because of this, prolly. They've been added to the KEV so CISA can force agencies to clean out artifacts/compromised systems

                          https://mastodon.social/@campuscodi/116648324167478081

                          gossithedog@cyberplace.socialG This user is from outside of this forum
                          gossithedog@cyberplace.socialG This user is from outside of this forum
                          gossithedog@cyberplace.social
                          wrote last edited by
                          #17

                          @campuscodi it's pretty odd. They're not vulnerabilities... if you were affected, it'd be an incident - not an upgrade. CISA need to build a better system and process.

                          thepwnicorn@infosec.exchangeT 1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            @campuscodi it's pretty odd. They're not vulnerabilities... if you were affected, it'd be an incident - not an upgrade. CISA need to build a better system and process.

                            thepwnicorn@infosec.exchangeT This user is from outside of this forum
                            thepwnicorn@infosec.exchangeT This user is from outside of this forum
                            thepwnicorn@infosec.exchange
                            wrote last edited by
                            #18

                            @GossiTheDog @campuscodi you're not wrong, but it seems CVEs are the go to mechanism for any security issue of software dependencies.

                            1 Reply Last reply
                            0
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                            • Login

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • World
                            • Users
                            • Groups