Hi everyone,
I’m posting this to inform you that we currently have delays in disclosing our security advisories because of a bottleneck in the CVE ID assignation.
Per our Security Policy we should publish the vulnerabilities related to XWiki with a public CVE, after the 3 months of embargo. Our internal process to publish our vulnerability is currently using Github to issue the CVE ID to our advisories.
Until recently we were requesting the CVE ID only before performing the publication: it used to work correctly we were receiving the CVE ID one or 2 days after request and the planned date of disclosure was almost respected at 1 or 2 days.
But we started to notice during this summer that Github was not responding to some of our requests for getting CVE ID in some advisories. We thought it was a bug for some of them, but it’s apparently reproducing in almost all our advisories: even now we started to request the CVE ID way before the planned publication date.
Clearly this is related to the volume of CVE Github now has to handle (see also: Inside the Advisory Database and what happens when vulnerability volume breaks records - The GitHub Blog).
But for us right now it means that we’re stuck for publishing our advisories until they can process our requests.
In order to fix that, XWiki SAS started to look at becoming a CNA: if it’s accepted I’ll make a proposal to use in priority XWiki SAS as CNA for issuing CVE ID, so we wouldn’t depend anymore on Github for it.
In the meantime we are waiting, hoping that some requests we made to get CVE IDs are anwered in coming weeks. We will keep you informed.