Carnegie Mellon University Cert Vulnerability Note Example
UniversityHigher EducationEducationUnited StatesPrivate Research UniversityResearchEpidemiologyPublic HealthCybersecurityVulnerability DisclosureScholarly PublishingInstitutional RepositoryIdentity FederationOpen AccessOpen Data
Carnegie Mellon University Cert Vulnerability Note Example is an example object payload from Carnegie Mellon University, with 2 top-level fields. It illustrates the shape of data this provider's APIs accept or return.
{
"x-provenance": {
"generated": "2026-08-19",
"method": "probed",
"source": "https://kb.cert.org/vuls/api/421644/",
"authorship": "Captured live by API Evangelist from the institution-operated endpoint named in source; payload truncated for size, values unedited.",
"notes": "Field subset of the 55-field Vulnerability Note record for VU#421644; `overview` truncated. No values altered."
},
"example": {
"vuid": "VU#421644",
"idnumber": "421644",
"name": "HTTP/2 CONTINUATION frames can be utilized for DoS attacks",
"keywords": null,
"datecreated": "2024-04-03T17:15:19.831533Z",
"publicdate": "2024-04-03T17:15:18.031722Z",
"datefirstpublished": "2024-04-03T17:15:19.844659Z",
"dateupdated": "2024-07-19T11:21:11.890081Z",
"revision": 18,
"cveids": [
"CVE-2024-27268",
"CVE-2024-27983",
"CVE-2024-27316",
"CVE-2024-30255",
"CVE-2024-31309",
"CVE-2024-27919",
"CVE-2024-2758",
"CVE-2024-2653",
"CVE-2023-45288",
"CVE-2024-28182"
],
"cvss_basescore": null,
"cvss_basevector": null,
"metric": null,
"overview": "### Overview\r\n\r\nHTTP allows messages to include named fields in both header and trailer sections. These header and trailer fields are serialised as field blocks in HTTP/2, so that they can be transmitted in multiple fragments to the target implementation. Many HTTP/2 implementations do not properly limit or sanitize the amount of CONTINUATION frames sent within a single stream. An attacker that ca \u2026[truncated]"
}
}
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.