Assigning a CVE doesn't mean generating panic, in case this is what is happening, stopping to assign CVE to less important security bugs is not the way to fix the world. Please keep in mind that many downstream distros and project relies on CVE ID in order to prepare package updates and/or assess compliance. Other things use CVE ID too, for instance, if we do not assign a CVE to a security bug then there won't be any security scanner to check for it... and this will get unnoticed for many organizations. base/env/temp CVSS are there to show the severity of a security bug. We as a security community should not hide potential security bugs. |