Skip to content

Microsoft MotW under-assignment #2

@zmanion

Description

@zmanion

Microsoft assigned two quite-different vulnerabilities to CVE-2022-41049. CNA rules state:

7.2.1 CNAs MUST NOT assign the same CVE ID to more than one independently fixable vulnerability.

CVE IDs are meant to track vulnerabilities not fixes.

CC @wdormann

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions