|
1 | 1 | [ |
2 | | - { |
3 | | - "id": "glossaryADP", |
4 | | - "term": "Authorized Data Publisher (ADP)", |
5 | | - "definition": "An organization authorized within the <span class='cve-term-reference'>CVE Program</span> to enrich a <span class='cve-term-reference'>CVE Record</span> previously published by a CNA with additional, related information (e.g., risk scores, affected product lists, and versions [i.e., references, translations]) within a defined Scope." |
6 | | - }, |
| 2 | + |
7 | 3 | { |
8 | 4 | "id": "glossaryCVE", |
9 | 5 | "term": "CVE", |
|
16 | 12 | }, |
17 | 13 | { |
18 | 14 | "id": "glossaryCVEID", |
19 | | - "term": "CVE ID", |
| 15 | + "term": "CVE Identifier (CVE ID)", |
20 | 16 | "definition": "A unique, alphanumeric identifier assigned by the <span class='cve-term-reference'>CVE Program</span>. Each identifier references a specific vulnerability. A CVE ID enables automation and multiple parties to discuss, share, and correlate information about a specific vulnerability, knowing they are referring to the same thing." |
21 | 17 | }, |
22 | 18 | { |
|
37 | 33 | { |
38 | 34 | "id": "glossaryProgram", |
39 | 35 | "term": "CVE Program", |
40 | | - "definition": "An international, community-driven effort to catalog <span class='cve-term-reference'>Vulnerabilities</span> in accordance with the effort’s rules and guidelines." |
| 36 | + "definition": "An international, community-driven effort to catalog <span class='cve-term-reference'>vulnerabilities</span> in accordance with the effort’s rules and guidelines." |
41 | 37 | }, |
42 | 38 | { |
43 | 39 | "id": "glossaryRecord", |
44 | 40 | "term": "CVE Record", |
45 | | - "definition": "The descriptive data about a <span class='cve-term-reference'>Vulnerability</span> associated with a <span class='cve-term-reference'>CVE ID</span>, provided by a <span class='cve-term-reference'>CNA</span>, and enriched by <span class='cve-term-reference'>ADPs</span>. This data is provided in multiple human and machine-readable formats. <p>A CVE Record is associated with one of the following states:</p><ul class='cve-term-definition-list'><li><span class='cve-term-reference'>Reserved</span>: The initial state for a CVE Record; when the associated CVE ID is Reserved by a CNA.</li><li><span class='cve-term-reference'>Published</span>: When a CNA populates the data associated with a CVE ID as a CVE Record, the state of the CVE Record is Published. The associated data must contain an identification number (CVE ID), a prose description, and at least one public reference.</li><li><span class='cve-term-reference'>Rejected</span>: If the CVE ID and associated CVE Record should no longer be used, the CVE Record is placed in the Rejected state. A Rejected CVE Record remains on the CVE List so that users can know when it is invalid.</li></ul><p>See also:</p><ul class='cve-term-definition-list'><li>The full requirements for a CVE Record can be found in Section 8.1. CVE Entry Information Requirements of the CNA Rules document. Data elements within a CVE Record are defined in Section 7. Assignment Rules of the CNA Rules document.</li><li>See Section 8.3 Reference Requirements of the CNA Rules for the requirements for the <span class='cve-term-reference'>CVE Program</span> to consider a CVE ID public.</li></ul>" |
| 41 | + "definition": "The descriptive data about a <span class='cve-term-reference'>Vulnerability</span> associated with a <span class='cve-term-reference'>CVE ID</span>, provided by a <span class='cve-term-reference'>CNA</span>. This data is provided in multiple human and machine-readable formats. <p>A CVE Record is associated with one of the following states:</p><ul class='cve-term-definition-list'><li><span class='cve-term-reference'>Reserved</span>: The initial state for a CVE Record; when the associated CVE ID is Reserved by a CNA.</li><li><span class='cve-term-reference'>Published</span>: When a CNA populates the data associated with a CVE ID as a CVE Record, the state of the CVE Record is Published. The associated data must contain an identification number (CVE ID), a prose description, and at least one public reference.</li><li><span class='cve-term-reference'>Rejected</span>: If the CVE ID and associated CVE Record should no longer be used, the CVE Record is placed in the Rejected state. A Rejected CVE Record remains on the CVE List so that users can know when it is invalid.</li></ul><p>See also:</p><ul class='cve-term-definition-list'><li>The full requirements for a CVE Record can be found in <a href='/ResourcesSupport/AllResources/CNARules#section_8-1_cve_entry_information_requirements'> Section 8.1. CVE Record Information Requirements of the CNA Rules</a> document. Data elements within a CVE Record are defined in <a href ='/ResourcesSupport/AllResources/CNARules#section_7_assignment_rules'> Section 7. Assignment Rules </a> of the CNA Rules document.</li><li>See <a href ='/ResourcesSupport/AllResources/CNARules#section_8-3_cve_entry_reference_requirements'> Section 8.3 Reference Requirements</a> of the CNA Rules for the requirements for the <span class='cve-term-reference'>CVE Program</span> to consider a CVE ID public.</li></ul>" |
46 | 42 | }, |
47 | 43 | { |
48 | 44 | "id": "glossaryWG", |
|
56 | 52 | }, |
57 | 53 | { |
58 | 54 | "id": "glossaryRoot", |
59 | | - "term": "Root CNA", |
60 | | - "definition": "An organization authorized within the <span class='cve-term-reference'>CVE Program</span> that is responsible, within a specific Scope, for the recruitment, training, and governance of one or more entities that are a CVE <span class='cve-term-reference'>CNA</span>, <span class='cve-term-reference'>CNA-LR</span>, an <span class='cve-term-reference'>ADP</span>, or another Root CNA." |
| 55 | + "term": "Root", |
| 56 | + "definition": "An organization authorized within the <span class='cve-term-reference'>CVE Program</span> that is responsible, within a specific Scope, for the recruitment, training, and governance of one or more entities that are a <span class='cve-term-reference'>CNA</span>, <span class='cve-term-reference'>CNA-LR</span>, or another Root." |
61 | 57 | }, |
62 | 58 | { |
63 | 59 | "id": "glossaryScope", |
|
71 | 67 | }, |
72 | 68 | { |
73 | 69 | "id": "glossaryTLRCNA", |
74 | | - "term": "Top-Level Root CNA (TLR-CNA)", |
75 | | - "definition": "A <span class='cve-term-reference'>Root CNA</span> that does not report to another Root CNA, and is thus responsible to the <span class='cve-term-reference'>CVE Board</span>." |
| 70 | + "term": "Top-Level Root (TL-Root)", |
| 71 | + "definition": "A <span class='cve-term-reference'>Root</span> that does not report to another Root, and is thus responsible to the <span class='cve-term-reference'>CVE Board</span>." |
76 | 72 | }, |
77 | 73 | { |
78 | 74 | "id": "glossaryVulnerability", |
|
0 commit comments