Skip to content

Tool to check CVE database for triage re-considerations

There are cases when the triaging decision should be re-considered.

For example if a CVE has been fixed in a previous release. Or if the CVE is postponed in both previous and next release but no-dsa in current.

(Added by Roberto) An additional case (which requires inspecting the Git history) is when the security team updates the triage of a CVE after the LTS triage has been performed. We would want to re-examine the LTS triage, especially if the security team marked the CVE as ignored or postponed.

Edited by Roberto C. Sánchez