Skip to content

Comment on CVE Stuffing

Comments

Didn't check who filled those bugs, but I've seen companies requiring having discovered CVE to apply for some jobs, and the natural consequence is gaming the system...

I checked, it seems to be a student of Seoul National University, South Korea. https://github.com/donghyunlee00/CVE

Huh. I wonder if it's a student doing an assignment and not realizing they're submitting to a real database.

Their other GitHub work is following tutorials, labs and courses.

A second guy is also doing this. CVEs have a reference to third party advisories such as https://github.com/koharin/koharin2/blob/main/CVE-2020-35185

This repository does no longer exists.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.