TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The curl website now features text alerting about NVD “abuse”

2 点作者 samueloph将近 2 年前

2 条评论

samueloph将近 2 年前
"Alert: if you look up curl CVEs in public sources like NVD you will find they use inflated severity levels and CVSS scores. They think they know better and override our assessments. This is a systemic error that we unfortunately cannot fix. Feel free to complain to them - we keep doing it to no use - and consider using our material as the canonical sources for curl issues."
jruohonen将近 2 年前
While it is well-documented that there are erroneous assignments, I think it is still better that a vendor-independent body does the scoring. Though, the presence of CNAs kind of admittedly downplays this line of argumentation.