Blog
CWEs vs CVEs – Identifying vs Responding to the Right Security Issues
By Editorial Staff on Mon, 11/28/2016
For the third time in under a year, I've had to analyze a CVE against a third-party library I use that is related to CWE-502 De-serializing of Untrusted Data. In each case, the library maintainers have pushed back, correctly in my opinion, that the problem is not in the library itself but in the hosting application. Fortunately for me, my...