Skip to content

Add CVE compensating control fixtures#2071

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/cve-compensating-control-fixtures-1629
Open

Add CVE compensating control fixtures#2071
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/cve-compensating-control-fixtures-1629

Conversation

@DENGXUELIN

Copy link
Copy Markdown

/claim #1629

Summary

  • Adds compensating-control exploit-path verification to cve-triage with CVE-COMP-01 through CVE-COMP-08.
  • Requires exploit-path mapping, runtime/fleet scope, control configuration, effectiveness evidence, bypass review, owner/expiry, SLA impact, and revalidation triggers before a control can reduce remediation urgency.
  • Adds vulnerable and benign fixtures for generic WAF/segmentation de-escalation versus verified service-mesh mitigation with negative tests and governance evidence.

Validation

  • git diff --cached --check
  • git diff --check origin/main...HEAD
  • git merge-tree --write-tree origin/main HEAD
  • Markdown fence balance check
  • Added-line ASCII check
  • Marker check for CVE-COMP-01 through CVE-COMP-08, Compensating Control Verification, and version: "1.0.1"
  • Added-line sensitive/public-contact pattern scan

Bounty

Requested tier: Improver Moderate / USD 100 if accepted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant