ASW Episode 402
• Mike Shema
Check out the show notes for links to the articles we covered.
Going From Bug Bounty Bugs to More Secure Systems
Hello Packages, Parsers, and Programs,
How does appsec measure software quality failures?
With CVSS, which is a common vulnerability scoring system that turns severity into decimal points.
Those scores are assigned to CVEs, which are common vulnerability enumerations that turn bugs into unique identifiers.
And all those vulns share almost universal underlying problems that we call CWEs, that turn all that bug tracking into commonly wasted efforts.