-
-
Notifications
You must be signed in to change notification settings - Fork 131
Description
The Node.js Security Team has been informed that the three CVEs we emitted for EOL release lines were removed by the MITRE team. Their justification is as follows:
This decision by the Board is in accordance with existing program rules. However, it is worth noting that the Board stated this vote does "not determine the CVE Program’s long-term position" regarding EOL. In fact, the Board plans to continue to discuss potential solutions for EOL support. You are encouraged to continue participating in CVE Working Groups to ensure your perspective is represented.
To address this, we participated in the OpenSSF Vulnerability Disclosure Working Group (WG) to discuss the implications of this decision. We believe we have clearly expressed our perspective on the importance of including EOL release lines in CVEs to ensure proper security disclosure.
Given MITRE's current stance, the only viable option we have is to update all CVEs to explicitly include EOL release lines. To implement this, we propose the following workflow:
- Open this issue to track the update process.
- Publish a blog post informing users about the situation and our planned actions. doc: add Updates on CVE to EOL blog post nodejs.org#7537
- Update the CVEs to include EOL release lines.
- Update the blog post once the changes have been applied.
This issue will serve as the central discussion point for tracking progress. Feedback and suggestions are welcome.
cc: @nodejs/security @nodejs/tsc