{"id":2810,"date":"2024-03-28T16:03:37","date_gmt":"2024-03-28T21:03:37","guid":{"rendered":"https:\/\/cyberscoop.com\/?p=79936"},"modified":"2024-03-28T16:03:37","modified_gmt":"2024-03-28T21:03:37","slug":"plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/28\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism\/","title":{"rendered":"Plan to resuscitate beleaguered vulnerability database draws criticism\u00a0"},"content":{"rendered":"<p><head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <meta name=\"robots\" content=\"index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1\"> <!-- This site is optimized with the Yoast SEO Premium plugin v21.7 (Yoast SEO v21.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ --> <title>Plan to resuscitate beleaguered vulnerability database draws criticism&nbsp; | CyberScoop<\/title> <meta name=\"description\" content=\"The National Vulnerability Database has ceased some of its work, but some experts fear the formation of a consortium to address its problems lacks sufficient urgency.\"> <link rel=\"canonical\" href=\"https:\/\/cyberscoop.com\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism\/\"> <meta property=\"og:locale\" content=\"en_US\"> <meta property=\"og:type\" content=\"article\"> <meta property=\"og:title\" content=\"Plan to resuscitate beleaguered vulnerability database draws criticism&nbsp;\"> <meta property=\"og:description\" content=\"The National Vulnerability Database has ceased some of its work, but some experts fear the formation of a consortium to address its problems lacks sufficient urgency.\"> <meta property=\"og:url\" content=\"https:\/\/cyberscoop.com\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism\/\"> <meta property=\"og:site_name\" content=\"CyberScoop\"> <meta property=\"article:published_time\" content=\"2024-03-28T21:03:37+00:00\"> <meta property=\"article:modified_time\" content=\"2024-03-28T21:03:38+00:00\"> <meta property=\"og:image\" content=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-2.jpg\"> <meta property=\"og:image:width\" content=\"1920\"> <meta property=\"og:image:height\" content=\"1280\"> <meta property=\"og:image:type\" content=\"image\/jpeg\"> <meta name=\"author\" content=\"Tim Starks\"> <meta name=\"twitter:card\" content=\"summary_large_image\"> <meta name=\"twitter:creator\" content=\"@timstarks\"> <!-- \/ Yoast SEO Premium plugin. --> <link rel=\"dns-prefetch\" href=\"\/\/securepubads.g.doubleclick.net\">\n<link rel=\"dns-prefetch\" href=\"\/\/use.typekit.net\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Feed\" href=\"https:\/\/cyberscoop.com\/feed\/\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Comments Feed\" href=\"https:\/\/cyberscoop.com\/comments\/feed\/\"> <link rel=\"stylesheet\" id=\"all-css-2\" href=\"https:\/\/cyberscoop.com\/wp-includes\/css\/dist\/block-library\/style.min.css?m=1710875768g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-6\" href=\"https:\/\/cyberscoop.com\/wp-content\/mu-plugins\/search\/elasticpress-next\/dist\/css\/related-posts-block-styles.min.css?m=1710299038g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-8\" href=\"https:\/\/cyberscoop.com\/wp-content\/themes\/scoopnewsgroup\/dist\/css\/frontend.css?m=1711491965g\" type=\"text\/css\" media=\"all\">\n<link rel=\"stylesheet\" id=\"typekit-css\" href=\"https:\/\/use.typekit.net\/itk2qbh.css?ver=74528d75ce0daeb8628a\" media=\"all\"> <link rel=\"https:\/\/api.w.org\/\" href=\"https:\/\/cyberscoop.com\/wp-json\/\"><link rel=\"alternate\" type=\"application\/json\" href=\"https:\/\/cyberscoop.com\/wp-json\/wp\/v2\/posts\/79936\"><link rel=\"EditURI\" type=\"application\/rsd+xml\" title=\"RSD\" href=\"https:\/\/cyberscoop.com\/xmlrpc.php?rsd\">\n<meta name=\"generator\" content=\"WordPress 6.4.3\">\n<link rel=\"shortlink\" href=\"https:\/\/cyberscoop.com\/?p=79936\">\n<link rel=\"alternate\" type=\"application\/json+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fplan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism%2F\">\n<link rel=\"alternate\" type=\"text\/xml+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fplan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism%2F&amp;format=xml\"> <!-- Google Tag Manager --> <!-- End Google Tag Manager --> <link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=32\" sizes=\"32x32\">\n<link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=192\" sizes=\"192x192\">\n<link rel=\"apple-touch-icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=180\">\n<meta name=\"msapplication-TileImage\" content=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=270\"> <\/head><body class=\"post-template-default single single-post postid-79936 single-format-standard\" id=\"readabilityBody\"> <a href=\"https:\/\/cyberscoop.com\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism\/#main\" class=\"skip-to-content-link visually-hidden-focusable\">Skip to main content<\/a> <\/p>\n<div class=\"ad ad--top ad--top-desktop\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p> <main id=\"main\" role=\"main\" tabindex=\"-1\"> <\/p>\n<div class=\"ad ad--top ad--top-mobile\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<section id=\"stickybar\" class=\"stickybar stickybar--newsletter js-stickybar\" readability=\"0.82\"> <button class=\"stickybar__close js-stickybar-close\" aria-controls=\"stickybar\"> <svg class=\"icon icon--close\" width=\"21\" height=\"22\" viewBox=\"0 0 21 22\" fill=\"none\"><path d=\"m.822.518-.805.805L9.695 11 .017 20.678l.805.805 9.678-9.678 9.677 9.678.806-.805L11.305 11l9.678-9.677-.806-.805-9.677 9.677L.822.518Z\" fill=\"currentColor\" \/><\/svg> <span class=\"visually-hidden\">Close<\/span> <\/button> <\/section>\n<article class=\"single-article content\">\n<div class=\"single-article__container js-single-article-content\">\n<header class=\"single-article__header \" readability=\"25.601351351351\">\n<div class=\"single-article__header-content\" readability=\"31.22695035461\">\n<ul class=\"single-article__eyebrow\">\n<li class=\"single-article__category\"> <a class=\"single-article__category-link\" href=\"https:\/\/cyberscoop.com\/news\/cybersecurity\/\"> <span>Cybersecurity<\/span> <\/a> <\/li>\n<\/ul>\n<p> The National Vulnerability Database has ceased some of its work, but some experts fear the formation of a consortium to address its problems lacks sufficient urgency. <\/p>\n<\/p><\/div>\n<div class=\"single-article__cover-wrap\">\n<figure class=\"single-article__cover\"> <img data-recalc-dims=\"1\" fetchpriority=\"high\" width=\"640\" height=\"426\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism.jpg?resize=640%2C426&#038;ssl=1\" class=\"single-article__cover-image wp-post-image\" alt decoding=\"async\" fetchpriority=\"high\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-2.jpg 1920w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-2.jpg?resize=300,200 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-2.jpg?resize=768,512 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-2.jpg?resize=1024,683 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-2.jpg?resize=1536,1024 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-2.jpg?resize=600,400 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-2.jpg?resize=252,168 252w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-2.jpg?resize=506,337 506w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-2.jpg?resize=1013,675 1013w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-2.jpg?resize=1265,843 1265w\" sizes=\"(max-width: 1013px) 100vw, 1013px\"><figcaption> A digitally generated image of yellow data server discs organized into circular pattern is seen against on beige background. (Andriy Onufriyenko via GettyImages) <\/figcaption><\/figure>\n<\/p><\/div>\n<\/header>\n<div class=\"single-article__content\">\n<div class=\"single-article__content-inner has-drop-cap\"> <html readability=\"59.207583547558\"><body readability=\"121.99721614635\"><\/p>\n<p>The federal official in charge of a crucial vulnerability database that has recently gone mostly dark said Wednesday that she hoped the formation of a consortium would improve the repository, a move that some experts immediately criticized as too slow to address an urgent problem.<\/p>\n<p>In mid-February, the National Institute of Standards and Technology stopped providing key metadata for many vulnerabilities in its National Vulnerability Database, which cybersecurity professionals describe as a critical tool for computer security functions globally and whose absence could result in dangerous vulnerabilities going unfixed.<\/p>\n<p>Tanya Brewer, who manages the National Vulnerability Database program, said at a conference on Wednesday that a notice forthcoming in the Federal Register in the next two weeks will announce the process for forming an outside consortium to help improve the database.<\/p>\n<p>Compared to other resources of its kind, \u201cNVD is not the best database,\u201d Brewer said. If it was, \u201cI would not be putting together a consortium asking industry to help make it better,\u201d she said at VulnCon in Raleigh, N.C. \u201cThere\u2019s a lot of room for the NVD to improve, and I think we have the capability to be a much better database than we are.\u201d<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Planned improvements in the next one to five years include offering customizable alerts and new data types, as well as developing a way to partially automate analysis of Common Vulnerability and Exposures or CVEs, a glossary of vulnerabilities, Brewer said.&nbsp;<\/p>\n<p>Brewer did not offer a detailed explanation about what led to the reduced activity on the database, chalking it up to a long story that amounts to \u201cadministrivia,\u201d a growing volume of data submitted to the database and budget cuts affecting her agency.&nbsp;<\/p>\n<p>Since early 2020, email traffic related to the database has tripled while staff size has remained flat, never rising above 21 people at any point, Brewer said. The program isn\u2019t equipped to receive massive amounts of data either, she said, such as \u201cCommon Platform Enumerations\u201d or CPEs \u2014 a naming scheme for software products.<\/p>\n<p>\u201cOne of my short-term goals for the consortium I\u2019m standing up is to build a system that will let manufacturers give us just big dumps of CPE data,\u201d she said. Now, if someone offers to give the program 74,000 CVEs, the answer would be, \u201c\u2018Oh please don\u2019t,\u2019\u201d Brewer said. \u201cBut in a year\u2019s time, I want the answer to be, \u2018Yes, please.\u201d<\/p>\n<p>Until the formation of the consortium, the NVD program office is reallocating personnel and working with other agencies toward \u201cfixing the current problem,\u201d she said. In the meantime, she said the office is still \u201ctaking care of priority things,\u201d such as responding to vulnerabilities on a Cybersecurity and Infrastructure Security Agency so-called <a href=\"https:\/\/cyberscoop.com\/cisa-kev-catalog-must-patch-list\/\">\u201cmust patch\u201d list<\/a> or Microsoft\u2019s Patch Tuesdays.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Cybersecurity professionals have been pushing for NVD to resume its normal operations in recent months. <a href=\"https:\/\/docs.google.com\/document\/d\/1y6JXhh52b1OMxLMQyl_WH0R2-85iYEBzjSm_fhv8-GY\/edit\">A recent open letter<\/a> to Secretary of Commerce Gina Raimondo and members of Congress that was signed by two dozen security professionals called on the U.S. government \u201cto ensure NIST is provided with the necessary resources to not only resume normal operations of this critical service but to also improve it further to resolve extant issues that preceded the February 2024 service degradation.\u201d<\/p>\n<p>Dan Lorenc, the co-founder and CEO of Chainguard who helped organize the letter, said Brewer\u2019s proposal to form a consortium was insufficient.<\/p>\n<p>\u201cWhile I appreciate hearing directly from NIST regarding the situation involving NVD, the comments do not inspire confidence in a timely resolution,\u201d he said.<\/p>\n<p>A consortium isn\u2019t the answer, he said, because \u201cadding layers of governance and bureaucracy can slow things down, which does not instill confidence. While I believe there\u2019s room for industry to collaborate with NIST, I believe that a single entity should clearly own and operate NVD, especially given its critical role as a source of truth for the federal government.\u201d<\/p>\n<p>Jerry Gamblin, a principal engineer at Cisco Threat Detection &amp; Response, said he was hopeful about the consortium making a difference.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cThey weren\u2019t able to analyze all CVEs before the slowdown, so I hope the consortium can help them get to 100% coverage,\u201d he said via email. \u201cWe don\u2019t have new data we can share, but what we are seeing essentially maps to public reporting about the number of CVEs left unanalyzed. We understand that NIST is aware of the problem and the concerns \u2014 and is working diligently to modernize NVD.\u201d&nbsp;&nbsp;<\/p>\n<p>A consortium could be another six to nine months away from forming, though, said Tom Alrich, who leads the OWASP SBOM Forum project. That\u2019s \u201cnot exactly a solution to the problem,\u201d he said. While Alrich said he was sympathetic to the program\u2019s difficult situation, he was frustrated about the lack of specificity about what had caused the problem in the first place.&nbsp;<\/p>\n<p><\/body> <\/p>\n<footer class=\"single-article__footer\" readability=\"2.1370192307692\">\n<div class=\"author-card\" readability=\"12\">\n<div class=\"author-card__avatar\">\n<figure class=\"author-card__image-wrap\"> <img data-recalc-dims=\"1\" decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism-1.jpg?w=640&#038;ssl=1\" alt=\"Tim Starks\"> <\/figure>\n<\/p><\/div>\n<p><h4 class=\"author-card__name\">Written by Tim Starks<\/h4>\n<p> Tim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he&#8217;s covered cybersecurity since 2003. <\/p>\n<\/p><\/div>\n<div class=\"single-article__tags-container\">\n<h4 class=\"single-article__tags-title\">In This Story<\/h4>\n<\/p><\/div>\n<\/footer>\n<p> <\/html><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"single-article__ads js-single-article-sidebar\">\n<div class=\"ad ad--sidebar js-single-article-sidebar-5 ad--rightrail_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-4 ad--rightrail_2 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-3 ad--rightrail_3 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div><\/div>\n<\/article>\n<div class=\"popular-stories popular-stories--single-post\">\n<div class=\"popular-stories__container\">\n<h2 class=\"popular-stories__title\"> More Scoops <\/h2>\n<p> <!-- .popular-stories__stories --> <\/div>\n<p><!-- .popular-stories__inner -->\n<\/div>\n<p><!-- .popular-stories --> <\/p>\n<section class=\"latest-podcasts\">\n<h2 class=\"latest-podcasts__title\"> Latest Podcasts\t<\/h2>\n<\/section>\n<div class=\"top-categories\">\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Government<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Technology<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Geopolitics<\/h3>\n<\/p><\/div>\n<\/p><\/div>\n<p> <\/main> <\/p>\n<div class=\"ad ad--bottom \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div id=\"interstitial\" class=\"welcome__container\"> <button id=\"close-modal-1\" class=\"welcome__clickable_area\"><\/button> <\/p>\n<div class=\"welcome__ad_wrapper\">\n<p> <button id=\"close-modal-3\" class=\"welcome__continue-button\">Continue to CyberScoop<\/button> <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p> <!-- Start of HubSpot Embed Code --> <!-- End of HubSpot Embed Code --> <\/body> <a href=\"https:\/\/cyberscoop.com\/plan-to-resuscitate-beleaguered-vulnerability-database-draws-criticism\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Plan to resuscitate beleaguered vulnerability database draws criticism&nbsp; | CyberScoop<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1764,655,1765,78,1766,625,1767,927,1768,310,288,643,703],"tags":[1769,657,1770,86,1771,630,1772,929,1773,311,294,645,705],"class_list":["post-2810","post","type-post","status-publish","format-standard","hentry","category-cisco","category-congress","category-cve","category-cybersecurity","category-known-exploited-vulnerabilities-kev","category-microsoft","category-national-vulnerability-database","category-nist","category-software-bill-of-materials","category-technology","category-threats","category-vulnerabilities","category-vulnerability-disclosure","tag-cisco","tag-congress","tag-cve","tag-cybersecurity","tag-known-exploited-vulnerabilities-kev","tag-microsoft","tag-national-vulnerability-database","tag-nist","tag-software-bill-of-materials","tag-technology","tag-threats","tag-vulnerabilities","tag-vulnerability-disclosure"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Cyber Scoop","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/cyberscoop\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cisco\/\" rel=\"category tag\">Cisco<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/congress\/\" rel=\"category tag\">Congress<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cve\/\" rel=\"category tag\">CVE<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cybersecurity\/\" rel=\"category tag\">Cybersecurity<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/known-exploited-vulnerabilities-kev\/\" rel=\"category tag\">known exploited vulnerabilities (KEV)<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/microsoft\/\" rel=\"category tag\">Microsoft<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/national-vulnerability-database\/\" rel=\"category tag\">National Vulnerability Database<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/nist\/\" rel=\"category tag\">NIST<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/software-bill-of-materials\/\" rel=\"category tag\">software bill of materials<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/technology\/\" rel=\"category tag\">Technology<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/threats\/\" rel=\"category tag\">Threats<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/vulnerabilities\/\" rel=\"category tag\">vulnerabilities<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/vulnerability-disclosure\/\" rel=\"category tag\">vulnerability disclosure<\/a>","tag_info":"vulnerability disclosure","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2810","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2810"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2810\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2810"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2810"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2810"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}