None
EN
CVE for EOL with Aaron Frost
['Josh Bressers']
Open Source Security
When a vulnerability is discovered in current software versions, what responsibility do maintainers have to verify and disclose whether that same vulnerability affects older, end of life versions? When a vulnerability is discovered in version 2.5, the assumption should be that versions 2.4, 2.3 and earlier are also affected unless specifically verified otherwise, even if version 2.4 is EOL and no effort has been made to investigate if it’s affected. Rather than requiring proof that an older version is vulnerable, we would need to put in the effort to prove an old version isn’t vulnerable to the issue.