Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

CNCF [Cloud Native Computing Foundation]

How to Reduce CVE Noise with VEX - Vulnerability-Exploitability eXchange

CNCF [Cloud Native Computing Foundation] via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk explains how Vulnerability Exploitability eXchange (VEX) adds context to CVEs and integrates with software bills of materials. It covers how consumers can assess and mitigate vulnerability risk and how vendors can communicate actionable information to customers.

Syllabus

Intro
Risk
Value
Cost
Log for Shell
Main Message
Software Build Materials
Modeling Gap
Mapping
Not everything is affected
Policies
VEX
Workflow
Gaps
Questions
Sbomb
Sbomb Problems
Open Source
VEX Documents
Is there a repository
CycloneDX
What VEX is trying to do
Duplicate CVs
Conclusion

Taught by

CNCF [Cloud Native Computing Foundation]

Reviews

Start your review of How to Reduce CVE Noise with VEX - Vulnerability-Exploitability eXchange

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.