|
1 | 1 | { |
2 | 2 | "currentNews": [ |
| 3 | + { |
| 4 | + "id": 519, |
| 5 | + "newsType": "news", |
| 6 | + "title": "CNA Operational Rules Updated to Version 4.1.0", |
| 7 | + "urlKeywords": "CNA Rules Updated to Version 4 1 0", |
| 8 | + "date": "2025-05-13", |
| 9 | + "description": [ |
| 10 | + { |
| 11 | + "contentnewsType": "paragraph", |
| 12 | + "content": "“<a href='/Resources/Roles/Cnas/CNA_Rules_v4.1.0.pdf' target='_blank'>CNA Operational Rules Version 4.1.0</a>” was approved by the <a href='/ProgramOrganization/Board'>CVE Board</a> on May 14, 2025, and is effective as of May 14, 2025. <a href='/Resources/Roles/Cnas/CNA_Rules_v4.1.0.pdf' target='_blank'>CNA Rules v4.1.0</a>, which has no breaking changes and was updated to improve the clarity of requirements throughout the document, is available now as a <a href='/Resources/Roles/Cnas/CNA_Rules_v4.1.0.pdf' target='_blank'>PDF</a> (0.2MB)." |
| 13 | + }, |
| 14 | + { |
| 15 | + "contentnewsType": "paragraph", |
| 16 | + "content": "Non-breaking changes for CNA Rules v4.1.0 include: <ul><li>Improved clarity regarding end-of-life (EOL) assignments</li><li>Enhanced information about the year portion of the CVE ID</li><li>Updated requirements for references</li><li>Grammar fixes and other improvements throughout the document</li></ul>" |
| 17 | + }, |
| 18 | + { |
| 19 | + "contentnewsType": "paragraph", |
| 20 | + "content": "The <a href='/ResourcesSupport/AllResources/CNARules'>CNA Rules web page</a> on the CVE website will be updated to the new version soon." |
| 21 | + } |
| 22 | + ] |
| 23 | + }, |
| 24 | + { |
| 25 | + "id": 518, |
| 26 | + "newsType": "news", |
| 27 | + "title": "Stackable Added as CVE Numbering Authority (CNA)", |
| 28 | + "urlKeywords": "Stackable Added as CNA", |
| 29 | + "date": "2025-05-13", |
| 30 | + "description": [ |
| 31 | + { |
| 32 | + "contentnewsType": "paragraph", |
| 33 | + "content": "<a href='/PartnerInformation/ListofPartners/partner/Stackable'>Stackable GmbH</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for vulnerabilities in Stackable products including end-of-life or unsupported Stackable software, as well as open source projects that are not in another CNA’s scope." |
| 34 | + }, |
| 35 | + { |
| 36 | + "contentnewsType": "paragraph", |
| 37 | + "content": "To date, <a href='/PartnerInformation/ListofPartners'>456 CNAs</a> (453 CNAs and 3 CNA-LRs) from <a href='/ProgramOrganization/CNAs'>40 countries</a> and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. Stackable is the 23rd CNA from Germany." |
| 38 | + }, |
| 39 | + { |
| 40 | + "contentnewsType": "paragraph", |
| 41 | + "content": "Stackable’s Root is the <a href='/PartnerInformation/ListofPartners/partner/mitre'>MITRE Top-Level Root</a>." |
| 42 | + } |
| 43 | + ] |
| 44 | + }, |
| 45 | + { |
| 46 | + "id": 517, |
| 47 | + "newsType": "news", |
| 48 | + "title": "SCHUTZWERK Added as CVE Numbering Authority (CNA)", |
| 49 | + "urlKeywords": "SCHUTZWERK Added as CNA", |
| 50 | + "date": "2025-05-13", |
| 51 | + "description": [ |
| 52 | + { |
| 53 | + "contentnewsType": "paragraph", |
| 54 | + "content": "<a href='/PartnerInformation/ListofPartners/partner/SCHUTZWERK'>SCHUTZWERK GmbH</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for vulnerabilities discovered by, reported to, or coordinated by, SCHUTZWERK unless covered by another CNA." |
| 55 | + }, |
| 56 | + { |
| 57 | + "contentnewsType": "paragraph", |
| 58 | + "content": "To date, <a href='/PartnerInformation/ListofPartners'>455 CNAs</a> (452 CNAs and 3 CNA-LRs) from <a href='/ProgramOrganization/CNAs'>40 countries</a> and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. SCHUTZWERK is the 22nd CNA from Germany." |
| 59 | + }, |
| 60 | + { |
| 61 | + "contentnewsType": "paragraph", |
| 62 | + "content": "SCHUTZWERK’s Root is the <a href='/PartnerInformation/ListofPartners/partner/mitre'>MITRE Top-Level Root</a>." |
| 63 | + } |
| 64 | + ] |
| 65 | + }, |
| 66 | + { |
| 67 | + "id": 516, |
| 68 | + "newsType": "news", |
| 69 | + "title": "Erlang Ecosystem Foundation Added as CVE Numbering Authority (CNA)", |
| 70 | + "urlKeywords": "Erlang Ecosystem Foundation Added as CNA", |
| 71 | + "date": "2025-05-13", |
| 72 | + "description": [ |
| 73 | + { |
| 74 | + "contentnewsType": "paragraph", |
| 75 | + "content": "<a href='/PartnerInformation/ListofPartners/partner/EEF'>Erlang Ecosystem Foundation</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for vulnerabilities in active packages hosted on <a href='https://hex.pm/' target='_blank'>Hex.pm</a>, and in active projects hosted under the GitHub organizations <a href='https://github.com/elixir-lang' target='_blank'>@elixir-lang</a>, <a href='https://github.com/erlang' target='_blank'>@erlang</a>, <a href='https://github.com/erlef-cna' target='_blank'>@erlef-cna</a>, <a href='https://github.com/erlef' target='_blank'>@erlef</a>, <a href='https://github.com/gleam-lang' target='_blank'>@gleam-lang</a>, and <a href='https://github.com/hexpm' target='_blank'>@hexpm</a>, unless covered by the scope of another CNA." |
| 76 | + }, |
| 77 | + { |
| 78 | + "contentnewsType": "paragraph", |
| 79 | + "content": "To date, <a href='/PartnerInformation/ListofPartners'>454 CNAs</a> (451 CNAs and 3 CNA-LRs) from <a href='/ProgramOrganization/CNAs'>40 countries</a> and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. Erlang Ecosystem Foundation is the 245th CNA from USA." |
| 80 | + }, |
| 81 | + { |
| 82 | + "contentnewsType": "paragraph", |
| 83 | + "content": "Erlang Ecosystem Foundation’s Root is the <a href='/PartnerInformation/ListofPartners/partner/mitre'>MITRE Top-Level Root</a>." |
| 84 | + } |
| 85 | + ] |
| 86 | + }, |
3 | 87 | { |
4 | 88 | "id": 515, |
5 | 89 | "newsType": "blog", |
|
0 commit comments