NVD damage continued

https://daniel.haxx.se/blog/2023/06/12/nvd-damage-continued/

5 points · 1 comments · view on lemmy.world

1 Comments

0xCBE@infosec.pub · 2 pts · 3y

I found it interesting because starting from NVD, CVSS etc we have a whole industry (Snyk, etc) that is taking vuln data, mostly refuse to contextualize it and just wrap it in a nice interface for customers to act on.

The lack of deep context shines when you have vulnerability data for os packages, which might have a different impact if your workloads are containerized or not. Nobody seems to really care that much, they sell a wet blanket and we are happy to buy for the convenience.