Much Ado About "n/a": The Tragedy of CVE5 Data Quality

by Jess Lowe | - 3:00pm

In this highly optimistic, doomed-to-fail “live”-coding session, we will attempt to build a CVE5 parser on stage and feed it actual, raw records retrieved from the wild. Together, we will watch our code violently combust in real-time as we run into the structural dumpster fires that make up our global security standards.

We will suffer through:

  • “version”: “Before Novemeber 13th”
  • “product”: “n/a”
  • the realisation that an omission of docs is apparently a vulnerability?

and much much more.

and then we’ll chat about why it be this way, why it’s important it’s not, our alternatives and what we can maybe do about it.

About Jess Lowe

I’m a boring ol’ Software Engineer on Google’s Open Source Security Team working on the open source vulnerability database: OSV.dev. I’ve spent way too much time wading through weird CVE records that I’m desperately seeking the answers to questions like “how does anyone live like this?” and “really????”

Other talks