Problem/Motivation
In a world where anyone and their granny can load up an AI tool to attack a published vector, the policy to not cover DOS vulnerabilities that have a lot of steps is no longer a workable policy.
Proposed resolution
Update the policies to reduce the threshold at which we consider an advisory is necessary.
Remaining tasks
Reach an agreement, update the policies if appropriate.
Comments
Comment #2
damienmckennaComment #3
cmlaraThis is (part of) what #3471501: Align DST vulnerability determination criteria to CVE standards was arguing in requesting that the DST align to CNA standards that all vulnerabilities receive advisories.
Question: is this only targeting DoS or any low score?
In either case +1 for allowing more advisories to be issued.
Comment #4
damienmckennaWith this I was intending to narrow the scope to reduce the chance of bike shedding.