Skip to content

Add Common Weakness Enumeration (CWE) table to cve db #4974

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed

Conversation

motto-phytec
Copy link

The Common Weakness Enumerations (CWE) is a category system for hardware and software weakness and
vulnerabilities with the goal of understanding flaws.
The declaration and the information about the CWE are on https://cwe.mitre.org/ available.
The CWEs help to assess a CVE and evaluate it for the system.
NVD, Redhat and curl are supported as data source for the CWE number.
The cve_cwe table has the CVE number, the CWE and the data source.

The CWE is a category system for hardware and software weakness and
vulnerabilities with the goal of understanding flaws.

Signed-off-by: Maik Otto <[email protected]>
@terriko
Copy link
Contributor

terriko commented Apr 21, 2025

This isn't a bad idea, but are you actually needing it for something? It's a lot of data to store and spit out unless there's a clear user need and I'm not sure that's true here.

@terriko
Copy link
Contributor

terriko commented May 5, 2025

No response, so I'm going to go ahead and close this. If you (or anyone else reading this later!) need the CWE data in the cve-bin-tool reports, though, please open an issue so we can talk about storage requirements and download times and whether it should be on by default or in some kind of extended report generation option or what. It may be more feasible after some of our planned architecture changes than it is right now.

@terriko terriko closed this May 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants