arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.33099cs.CR

从未发出:GitHub 机器可读漏洞记录中的报告者归属

Never Emitted: Reporter Attribution in GitHub's Machine-Readable Vulnerability Records

Anas Mohiuddin Syed

首次发表
浏览论文内容

中文总结 AI 辅助

研究发现 GitHub 在 CVE 和 OSV 记录中从不输出报告者归属字段,导致归属信息缺失,且 NVD 也不支持该字段,影响漏洞归属的透明性。

中文摘要 AI 辅助

CVE 记录格式定义了一个 credits 容器,用于命名发现或报告漏洞的个人或组织,并为每个条目分配一个类型化角色。OSV 模式定义了一个等效字段。GitHub 为其生态系统中的安全公告分配 CVE 标识符,从报告者处收集此信息,要求他们接受,在公告页面上显示,并通过其自己的 REST API 提供服务。然而,它并未将这一信息输出到上述任何一种标准化格式中。在 238 条由 GitHub 分配的 CVE 记录中,其关联的公告公开致谢了至少一方,但没有任何一条记录包含 credits 容器,而所有 238 条记录都包含 metrics 和 problemTypes 字段,这两个字段在 CVE 模式中与 credits 一样是可选的。在同一池中的 302 条公告中,我们检索了 GitHub 自己的 OSV 导出文件,没有任何一条包含 credits 字段。这一遗漏并非格式本身的问题:在同一池中,Erlang 生态系统基金会使用一个免费的 CVE 服务客户端,在 18 条记录中的 18 条上填充了 CVE 字段。在对两周窗口内所有 4,889 条已发布 CVE 记录的人口普查中,46.9% 包含 credits,而 GitHub 在不加任何公告筛选的情况下,570 条记录中为 0 条,且分配者的行为集中在两个极端,但并未被这些极端所穷尽:16 个分配者在任何记录上都不发出该字段,13 个分配者在几乎所有记录上都发出该字段,而覆盖 23% 记录的 8 个分配者则介于两者之间。自 2023 年 1 月以来,一项弥补这一差距的请求一直处于开放状态;GitHub 推迟该请求的陈述理由被逐字引用。我们进一步表明,NVD API 模式未定义 credits 字段,因此 CNA 确实发出的归属信息不会到达大多数工具所消费的数据库:在从公告到 CVE 记录再到 NVD 追踪的 43 条含 credits 的记录中,没有一条保留该字段。我们发布了收集脚本和所有 API 响应的冻结快照。

英文摘要

The CVE record format defines a credits container that names who found or reported a vulnerability, with a typed role per entry. The OSV schema defines an equivalent field. GitHub, which assigns CVE identifiers for advisories in its ecosystems, collects this information from reporters, requires them to accept it, displays it on the advisory page, and serves it through its own REST API. It emits it into neither standardized format. Across 238 GitHub-assigned CVE records whose linked advisory publicly credits at least one party, zero carry a credits container, while all 238 carry metrics and problemTypes, two fields the CVE schema leaves optional exactly as it leaves credits. Across 302 advisories in the same pool we retrieved GitHub's own OSV export file, and zero carry a credits field. The omission is not a property of either format: the Erlang Ecosystem Foundation populates the CVE field on 18 of 18 records in the same pool using a freely available client for CVE Services. In a census of all 4,889 published CVE records in a two-week window, 46.9% carry credits, GitHub's rate is 0 of 570 without any advisory filter, and assigner behaviour is concentrated at the extremes without being exhausted by them: 16 assigners emit the field on no record and 13 on essentially every record, while 8 assigners covering 23% of the records sit in between. A request to close the gap has been open since January 2023; GitHub's stated reason for deferring it is quoted verbatim. We further show that the NVD API schema defines no credits field, so attribution that CNAs do emit does not reach the database most tooling consumes: of 43 credit-bearing records traced from advisory to CVE record to NVD, none retained it. We release the collection scripts and a frozen snapshot of every API response.

补充信息

↑