Problem/Motivation

In a world where anyone and their granny can load up an AI tool to attack a published vector, the policy to not cover DOS vulnerabilities that have a lot of steps is no longer a workable policy.

Proposed resolution

Update the policies to reduce the threshold at which we consider an advisory is necessary.

Remaining tasks

Reach an agreement, update the policies if appropriate.

Comments

damienmckenna created an issue. See original summary.

damienmckenna’s picture

Title: Policy: AI tools allow "anyone" to attack sites, so lower-score vulnerabilities need to be revisited » Policy: AI tools allow "anyone" to attack sites, so lower-score vulnerabilities should still be given SAs
cmlara’s picture

This is (part of) what #3471501: Align DST vulnerability determination criteria to CVE standards was arguing in requesting that the DST align to CNA standards that all vulnerabilities receive advisories.

Question: is this only targeting DoS or any low score?

In either case +1 for allowing more advisories to be issued.

damienmckenna’s picture

With this I was intending to narrow the scope to reduce the chance of bike shedding.