Re: CVE reporting discrepencies

2020-08-13 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Nic, On 8/13/20 15:52, Nic P wrote: > Hi > > Can anyone help me understand why some CVE's show in the changelog > but not on the security report? > > Example is CVE-2016-5388 which shows as fixed in 8.0.37 changelog > but missing on the security

CVE reporting discrepencies

2020-08-13 Thread Nic P
Hi Can anyone help me understand why some CVE's show in the changelog but not on the security report? Example is CVE-2016-5388 which shows as fixed in 8.0.37 changelog but missing on the security report. This has come up in a audit and hard to explain which is the System of Record information