doc/user/application_security/cve_id_request.md
{{< details >}}
{{< /details >}}
A Common Vulnerabilities and Exposures ID (CVE ID) is a unique identifier assigned to publicly-disclosed software vulnerabilities. GitLab is a CVE Numbering Authority (CNA), which means we can assign CVE identifiers to vulnerabilities in projects hosted on GitLab.com.
For public projects, you can request a CVE identifier to keep users informed about security issues. For example, GitLab dependency scanning tools can detect when your project uses vulnerable versions of a dependency.
A common vulnerability workflow is:
Prerequisites:
To submit a CVE ID request:
Go to the vulnerability's issue and select Create CVE ID Request. The new issue page of the GitLab CVE project opens.
In the Title box, enter a brief description of the vulnerability.
In the Description box, enter the following details:
GitLab updates your CVE ID request issue when:
After a CVE identifier is assigned, you can reference it as required. Details of the vulnerability submitted in the CVE ID request are published according to your schedule.