oss-sec mailing list archives
Change to ASF httpd vulnerability XML format
From: Mark Cox <mjc () apache org>
Date: Tue, 10 Apr 2018 12:18:11 +0100
Various OSS projects I've been involved with use a master vulnerability database in XML used for various internal functions such as generating web pages. I know some folks monitor or use/convert these XML feeds too even though we've not really publicised them or given them a schema. Later today I will be performing a major update to the Apache HTTP Server XML file[1] so that each CVE has a unique entry (rather than currently where the issues are repeated for each major version affected). This brings it more into line with the OpenSSL XML file[2] and allows us to automate more of our release process (i.e. generating the required JSON for Mitre CVE submissions). Some entries will have other minor updates to their text and to fix link locations so if you are monitoring the html pages you will see some minor changes at that time. Regards, Mark J Cox [1] https://httpd.apache.org/security/vulnerabilities-httpd.xml [2] https://www.openssl.org/news/vulnerabilities.xml
Current thread:
- Change to ASF httpd vulnerability XML format Mark Cox (Apr 10)