Re: CWE submission form

2021-10-06 Thread Kurt Seifried
The authoritative URL is: https://csaurl.org/blockchain-vulnerabilities points to a google sheet right now, long term once it settles down it'll hopefully be something else like github. Some of these map to existing CWE and are flavours/maybe children, and some are completely new like "vote

Re: CWE submission form

2021-10-06 Thread Alec J Summers
Kurt, Apologies for the secondary note, but I wanted to follow up and clarify something. To your comment: “I have some more questions but I'm finally getting around to my list of 200 vulns about 1/4 to 1/2 of which should probably be added to CWE and trying to figure out how to do this

Re: CWE submission form

2021-10-06 Thread Alec J Summers
Kurt, Thanks for your note and patience in my reply. Yes, your message was received :-) This text form was our initial solution for standing up a solution to ingest entries during the rapid growth of CWE HW content. It was not meant to be a long-term solution, although it has worked fairly

Re: CWE submission form

2021-10-06 Thread Kurt Seifried
Did this email get received? Can we do anything about this? I'm thinking at a minimum of a simple JSON format instead of that txt file. On Fri, Oct 1, 2021 at 11:40 AM Kurt Seifried wrote: > Regarding the CWE submission form > > https://cwe.mitre.org/community/submissions/guidelines.html > >