Skip to content

ES2511-3c1f9635 (Modification) - Add observed examples for AI products #171

@stevechristeycoley

Description

@stevechristeycoley

Submission File: ES2511-3c1f9635-AI-ML-observed-examples.txt

DESCRIPTION:

This submission will be used to focus the identification, review, and
addition of observed examples based on a report of recent CVEs in
AI/ML-related products. Contributors may make suggestions using comments in
the CDR issue itself.

The task is roughly:

  • for each CWE, review the list and identify one to three observed examples
    that could be most suitable to include in the CWE entry

The best examples satisfy the following criteria:

  • the vulnerability is not unnecessarily complex

  • the CVE has useful technical details that explain the weakness, whether
    in the CVE description itself or in its references (many CVEs do not have
    such details)

  • the relevant CWE mapping needs to be verified (in case of errors); a
    better CWE can be used if found.

  • ideally, the collected set of CVEs for a particular CWE should reflect
    a variety of products, technologies, and/or errors.

Metadata

Metadata

Labels

External-SubmissionPhase03-Init-ReviewThe external submission has been assigned to a CWE analyst to review the initial submission

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions