It does not take time to do CVSS scoring, and the CVSS scori...

semisol
npub12262qa4uhw7u8gdwlgmntqtv7aye8vdcmvszkqwgs0zchel6mz7s6cgrkj
hex
b403362a1e428e33711245d174fe55c9b8885baf918e4ca3cf02372929d49a00nevent
nevent1qqstgqek9g0y9r3nwyfyt5t5le2unwygtwherrjv508sydef982f5qqprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgs99d9qw67th0wr5xh05de4s9k0wjvnkxudkgptq8yg83vtulad30g2xhdhzKind-1 (TextNote)
↳ 回复 事件不存在
1dc28db27eb9cc0bc17259c4160a54763c72307117e12f12a9fb231b250e1da7...
It does not take time to do CVSS scoring, and the CVSS scoring system is known to have issues many issues anyway.
- Scores are often much lower or higher than they should be.
- It is possible to easily over- or understate the impact of a vulnerability, intentionally or not.
- Whether the vulnerability is actively exploitable is another question.
After NIST had slowed down enrichment of CVEs, and many other safeguards broke, anyone can now go and issue a CVE for a project without any verification.
https://sqlite.org/forum/forumpost/34bdf3b9bd759d4d
原始 JSON
{
"kind": 1,
"id": "b403362a1e428e33711245d174fe55c9b8885baf918e4ca3cf02372929d49a00",
"pubkey": "52b4a076bcbbbdc3a1aefa3735816cf74993b1b8db202b01c883c58be7fad8bd",
"created_at": 1786095214,
"tags": [
[
"e",
"8c132b89cd9bfcfc4844e86a28d278549a2007529d48f2f69716d14750c17ca6",
"wss://nos.lol/",
"root",
"52b4a076bcbbbdc3a1aefa3735816cf74993b1b8db202b01c883c58be7fad8bd"
],
[
"e",
"1dc28db27eb9cc0bc17259c4160a54763c72307117e12f12a9fb231b250e1da7",
"wss://aggr.nostr.land",
"reply",
"948bca3be1dfaaaf7344d508b00c2ec00abe82568d585e84d29248b5956ddd2d"
],
[
"p",
"948bca3be1dfaaaf7344d508b00c2ec00abe82568d585e84d29248b5956ddd2d"
],
[
"r",
"https://sqlite.org/forum/forumpost/34bdf3b9bd759d4d"
],
[
"client",
"Damus"
]
],
"content": "It does not take time to do CVSS scoring, and the CVSS scoring system is known to have issues many issues anyway.\n\n1. Scores are often much lower or higher than they should be.\n2. It is possible to easily over- or understate the impact of a vulnerability, intentionally or not.\n3. Whether the vulnerability is actively exploitable is another question.\n\nAfter NIST had slowed down enrichment of CVEs, and many other safeguards broke, anyone can now go and issue a CVE for a project without any verification.\n\nhttps://sqlite.org/forum/forumpost/34bdf3b9bd759d4d",
"sig": "54383a95926f93d7b5c1fc38dcf6ae913987339f90d6da490a36b483b280fccbba4c3222ce2d8d0af3923ae92c3e01893f2efce7482fe83834de0f81cce5ae80"
}