• Home
  • About
    • Background
    • LinkedIn
    • Presenting Activities
    • Internet Profile
    • About
    • www.cloud-native.info
  • Observability, Fluent(d) Bit & OpAMP
    • OpAMP Product
    • OpAMP Overview
    • Log Generator
    • Fluent Bit Classic to YAML Format configurations
  • My Books
    • Logs and Telemetry using Fluent Bit
      • Fluent Bit book
      • Book Resources in GitHub
    • Logging in Action with Fluentd, Kubernetes and More
      • Logging in Action with Fluentd – Book
      • Fluentd Book Resources
      • Fluentd & Fluent Bit Additional stuff
    • API & API Platform
      • API Useful Resources
    • Oracle Integration
      • Book Website
      • Useful Reading Sources
    • Publication Contributions
  • Resources
    • GitHub
    • Oracle Integration Site
    • Oracle Resources
    • Mindmaps Index
    • Useful Tech Resources
      • Fluentd & Fluent Bit Additional stuff
      • Recommended Tech Podcasts
      • Official Sources for Product Logos
      • Java and Graal Useful Links
      • DevTips
  • Music
    • Monster On Music
    • Music Listening
    • Music Reading

Phil (aka MP3Monster)'s Blog

~ from Technology to Music

Phil (aka MP3Monster)'s Blog

Tag Archives: standards

Relationship between CVEs, CVSS, CWE and lots of other TLAs starting with C

07 Friday Aug 2026

Posted by mp3monster in development, General, Security, Technology

≈ Leave a comment

Tags

CVE, CVSS, CWE, cyber, MITRE, NIST, Owasp, Security, standards

A lot of developers are focused on CVEs, as we need to know does the library, language or other building block I use to create a solution have an identified vulnerability that needs mitigating? We probably also pay attention to OWASP (Open Worldwide Application Security Project). But CVEs and OWASP aren’t the beginning and end of the story. This a larger ecosystem of standards involved.

CWE (Common Weakness Enumeration) is of particular interest if you get a chance to step back from fire fighting CVEs. This is interesting because, rather than addressing individually identified vulnerabilities, like the OWASP Top 10s, it looks at a classifies the vulnerabilities. When you get down the Base and Variant categories we’re into specific details. This is helpful, as classifying our CVEs against CWE can tell us the technical domains where the maximum effort can return the greatest level of mitigation/remediation of CVEs (be that creating a patch or defining a mitigation strategy).

I was going to sketch out the relationships between the key standards, but realized an LLM can do a better job, so here is a visual summary:

With so many TLAs in the diagram, here is a quick reference pulled together (including from my own library of handy links).

Acronym / referenceExpanded formOfficial HTTP linkOne-sentence summaryAuthority / allocation relevance
CVECommon Vulnerabilities and Exposurescve.org/about/overviewCVE provides globally recognised identifiers and records for publicly disclosed cybersecurity vulnerabilities. (cve.org)CVE IDs are assigned by authorised CNAs or by MITRE/CVE Program structures.
CNACVE Numbering Authoritycve.org/partnerinformation/listofpartnersCNAs are authorised organisations that assign CVE IDs and publish CVE Records within an agreed scope. (cve.org)Primary delegated authorities for allocating CVE IDs.
CNA-LRCNA of Last Resortcve.org/ProgramOrganization/StructureA CNA-LR supports CVE assignment when no more specific CNA is available for a vulnerability. (cve.org)Fallback route for CVE ID allocation.
MITREThe MITRE Corporationmitre.org/focus-areas/cybersecurity/capabilities-resourcesMITRE is closely associated with CVE, CWE, CAPEC and ATT&CK as a maintainer, operator or steward of major cybersecurity knowledge bases. (MITRE)Current CVE Program Secretariat and maintainer of CWE/CAPEC resources.
CWECommon Weakness Enumerationcwe.mitre.orgCWE is a community-developed catalogue of software and hardware weakness types that can lead to vulnerabilities. (Common Weakness Enumeration)CWE IDs are maintained by MITRE; they classify weakness types, not individual vulnerabilities.
CWSSCommon Weakness Scoring Systemcwe.mitre.org/cwssCWSS is a CWE-related scoring method for prioritising software weaknesses, but the older version referenced by MITRE is marked obsolete. (Common Weakness Enumeration)Scores weaknesses, not CVE vulnerabilities; largely secondary compared with CVSS in current vulnerability workflows.
CVSS v4.0Common Vulnerability Scoring System version 4.0first.org/cvss/v4.0CVSS v4.0 is the current major CVSS standard family used to express vulnerability severity with base, threat, environmental and supplemental metrics. (FIRST Forum) (Forum of Incident Response and Security Teams)Maintained by FIRST; it scores vulnerabilities but does not allocate vulnerability IDs.
Defines the scoring structure/ranking scale, not ID allocation.
NISTNational Institute of Standards and Technologynist.govNIST hosts and maintains important security automation resources including NVD and CPE-related specifications. (NVD)Maintains NVD and official CPE dictionary infrastructure.
NVDNational Vulnerability Databasenvd.nist.govNVD enriches CVE records with structured metadata such as affected platforms, weakness classifications, references and severity scores.Enrichment database, not the allocator of CVE IDs.
CPECommon Platform Enumerationnvd.nist.gov/Products/CPECPE provides standardised names for identifying affected products, platforms and software configurations. (NVD)Supports product/platform matching in NVD and vulnerability scanners.
CAPECCommon Attack Pattern Enumeration and Classificationcapec.mitre.orgCAPEC is a MITRE-maintained catalogue of attack patterns used to understand how weaknesses may be exploited. (CAPEC)CAPEC entries relate to CWEs and help connect weaknesses to attack behaviour.
CSAFCommon Security Advisory Frameworkoasis-open.org/committees/csafCSAF is an OASIS standard for creating and exchanging structured machine-readable security advisories. (OASIS)Advisory exchange format that can carry CVE, product status, remediation and scoring data.
VEXVulnerability Exploitability eXchangecisa.gov SBOM resourcesVEX communicates whether a known vulnerability is exploitable in a specific product or deployment context. (CISA)Helps qualify CVE findings so consumers can distinguish exploitable from non-exploitable exposure.
CISACybersecurity and Infrastructure Security Agencycisa.govCISA publishes operational vulnerability guidance and maintains the Known Exploited Vulnerabilities catalogue. (CISA)Maintains KEV and participates in the wider CVE/vulnerability ecosystem.
KEVKnown Exploited Vulnerabilities cataloguecisa.gov/known-exploited-vulnerabilities-catalogKEV is CISA’s authoritative catalogue of vulnerabilities known to have been exploited in the wild. (CISA)Prioritisation signal based on observed exploitation, not severity alone.
EPSSExploit Prediction Scoring Systemfirst.org/epssEPSS estimates the probability that a published CVE will be exploited in the wild within the next 30 days. (FIRST Forum)Probability-based prioritisation signal that complements CVSS and KEV.
CERT/CCCERT Coordination Centerkb.cert.org/vulsCERT/CC coordinates vulnerability disclosure and publishes Vulnerability Notes. (CERT Coordination Center)Can act as a coordinator in disclosure workflows and may interact with CNA/CVE processes.
CVDCoordinated Vulnerability DisclosureCERT Guide to CVDCVD is the process of coordinating information among finders, vendors and other stakeholders before public disclosure and mitigation communication. (CERT Coordination Center)Process framework around disclosure; not itself an ID system.
SBOMSoftware Bill of Materialsntia.gov/software-bill-materialsAn SBOM describes the software components that make up a product so downstream users can reason about exposure and supply-chain risk. (NTIA)Often paired with VEX and vulnerability feeds to assess affected components.
CycloneDXCycloneDX Bill of Materials standardcyclonedx.orgCycloneDX is an OWASP full-stack Bill of Materials standard for supply-chain and cyber-risk use cases. (CycloneDX)SBOM/VEX-capable format used in vulnerability management pipelines.
SPDXSoftware Package Data Exchangespdx.devSPDX is an open standard, ISO/IEC 5962:2021, for representing SBOMs and other software supply-chain metadata. (SPDX)SBOM format often used alongside vulnerability data sources.
SWIDSoftware Identification tagNIST SWID guidanceSWID tags are ISO/IEC 19770-2 software identification files that can support software asset, patch and vulnerability management. (NIST Computer Security Resource Center)Product identification standard related to CPE-style inventory matching.
SSVCStakeholder-Specific Vulnerability CategorizationCMU SEI SSVC v2.0SSVC uses decision trees to prioritise vulnerability response actions for specific stakeholder contexts. (SEI)Prioritisation model that complements CVSS, KEV and EPSS.
MITRE ATT&CKAdversarial Tactics, Techniques and Common Knowledgeattack.mitre.orgMITRE ATT&CK is a knowledge base of adversary tactics, techniques and procedures based on real-world observations. (MITRE ATT&CK)Related attack-behaviour framework that can be connected to CAPEC/CWE/CVE analysis.
OWASP Top 10Open Worldwide Application Security Project Top 10owasp.org/Top10The OWASP Top 10 is a standard awareness document for developers and web application security risks. (OWASP Foundation)Useful application-security reference that often maps conceptually to CWEs.
OSVOpen Source Vulnerabilities / OSV schemaosv.devOSV provides a machine-readable vulnerability format and database that maps open-source vulnerabilities precisely to package versions or commit hashes. (OSV)Adjacent vulnerability-data ecosystem, especially useful for open-source dependency scanning.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Print (Opens in new window) Print
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Bluesky (Opens in new window) Bluesky
Like Loading...

Open API’s Arazzo and overlay specifications

03 Thursday Apr 2025

Posted by mp3monster in APIs & microservices, General, Technology

≈ Leave a comment

Tags

Apache, Apache Camel, Async API, Azarro, BPEL, business process orchestration language, GeoJSON, GraphQL, OAI, OAS, Open API, orchestration, Overlays, PolyAPI, SOAP, specifications, standards, Swagger, WS-BPEL

The OpenAPI Specification OAS and its Open API Initiative (OAI)—the governing body—have been around for 10 years, and of course, OAS’s foundation, Swagger, has been around a lot longer. OpenAPI is very much a mature proposition. But the OAI community hasn’t stood still. Two standards have been developed, the first being Overlays and the latter being Arazzo.

Overlays

Overlays support the Arazzo specification. So let’s start there. It is a simple specification that describes how an OpenAPI definition can be extended, particularly for providing additional information about the API. While we don’t strictly need such a specification, as the OpenAPI spec provides the means to incorporate additional information, it doesn’t say how to best use the extension points to support use cases such as elaborating on the application.

This means an organisation could use an overlay to describe how internally particular APIs from mainly 3rd party APIs or standards can or should best be used. For example, if we built an API using GeoJSON for passing data describing no-fly zones (sometimes called prohibited airspace), the zone’s shape is easily expressed as a polygon or circle. However, no-fly zones can often have ceilings or base altitudes (consider the use of airspace for military low-altitude air training, which shouldn’t impact airliners at cruising altitude). GeoJSON can support this by attaching attributes to the shapes. What GeoJSON doesn’t describe is the name of the additional attributes. We can document this attribute using the overlay without refining the GeoJSON specification.

Simply put, an Overlay describes a structured way to add detail to an API without changing the original specification. Hopefully, we’ll see tooling to take the overlay detail, merge that content into the original specification, and generate enhanced API documentation.

This presents some interesting possibilities. With the rise of AI, we could potentially use it to provide a structured explanation to an LLM that can then take the additional information to generate the code needed to build functionality using a selected API, which could then be reused when an API is updated. While asking an LLM to generate code will not guarantee the same result (the result of reranking, ongoing training, etc), it is unlikely things will drift radically. This means any breaking changes in the API should be more easily absorbed.

Arazzo

Arazzo, takes the ability to define overlays to APIs a step further, as it leverages the OpenAPI overlay concept to define workflows that can be used to show how APIs can be orchestrated. This is hardly a new idea. Before RESTful APIs became dominant, we saw various standards complementary to WSDL, such as WS-BPEL (bringing BPEL together with WSDL). After open source solutions, which may have closer alignment to languages such as Apache Camel, they also provide the means to define orchestration of APIs that can be used in a language-agnostic manner.

Unlike OAS and Overlays, this standard is not being presented a contract, which will always need a specific way of being written to minimize ambiguity as it is effectively a contract between two or more parties (we even see this in the way contracts are drawn up, from NDAs to T&Cs and Liability disclaimers). It is being presented as a means to be illustrative of API use, where ambiguity can be tolerated (by being stateless, we have to accept some ambiguity in how people will use APIs and eliminate ambiguity through contractual clarity.

While Arrazo’s structure and schema are much easier to work with than BPEL, particularly if you’re comfortable with AOS, as the schema has a similar style and weaves OAS specifications as first-class citizens. My concern is that BPEL, and the more domain-specific orchestration definitions, while adopted by some more prominent organisations in the search for standardisation and consistency, never had a profound impact; most organizations ended up extending, tailoring it, or using the notation as a means to apply effective configuration management. Only time will tell whether Arazzo will make a profound impact. There are certainly some headwinds for Arazzo to overcome. Consider these …

  • The LLM domain is evolving so quickly that we aren’t too far away from mainstream tool vendors that have built or acquired companies like  Poly API, which can document and integrate APIs using LLMs. We can also look at LangGraph’s work on developing AI agents’ ability to orchestrate tools such as APIs to solve complex problems. Remember that LangGraph was launched in January 2023, whereas the Arazzo committee was formed mid-2021.
  • If we can’t reach a point where natural language will be sufficient to see APIs orchestrated in a predictable manner, is it possible to describe sufficient information using structured English (language)?  PlantUML and Mermaid diagrams provide sufficient structured English to achieve the goal, which is less sensitive to things like positioning and white space, such as YAML.

Personal wish

While I applaud Overlays as they allow me to add qualification to an existing API (contract), I would be happier if the OAI worked to find a way for the core OAS syntax to bring OAS and Async API (very possible as Async API makes use of a similar schema structure) without needing the additional complexity of the orchestration concepts in Arazzo. The North Star ideal would be a means to weave GraphQL capabilities into the notation without complexity, although, to be honest, this is a lot further apart, maybe too far apart today.

Today, we must use more advanced (often commercial) tools that combine the notations in a single tool or multiple plugins sourced from different places. These tools are not aligned and don’t offer a seamless experience, e.g., defining JSON structures that could work across multiple APIs.

Additional Reading

  • Swagger blog on Arazzo
  • Arazzo and AsyncAPI
  • New Stack Article on Arazzo
  • PolyAPI
  • GraphQL

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Print (Opens in new window) Print
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Bluesky (Opens in new window) Bluesky
Like Loading...
    • About
      • Internet Profile
      • Music Buying
      • Presenting Activities
    • Books & Publications
      • Logging in Action with Fluentd, Kubernetes and More
      • Logs and Telemetry using Fluent Bit
      • Oracle Integration
      • API & API Platform
        • API Useful Resources
        • Useful Reading Sources
    • Mindmaps Index
    • Monster On Music
      • Music Listening
      • Music Reading
    • OpAMP explained: the control plane for observability agents
    • Oracle Resources
    • Useful Tech Resources
      • Fluentd & Fluent Bit Additional stuff
        • Logging Frameworks and Fluent Bit and Fluentd connectivity
        • REGEX for BIC and IBAN processing
      • Formatting etc
      • Java and Graal Useful Links
      • Official Sources for Product Logos
      • Python Setup & related tips
      • Recommended Tech Podcasts

    TOGAF 9

    Logs and Telemetry using Fluent Bit


    Logging in Action — Fluentd

    Logging in Action with Fluentd


    Oracle Ace Director Alumni

    Oracle Cloud Integration Book


    API Platform Book


    Oracle Dev Meetup London

    Blog Categories

    • App Ideas
    • Books
    • Enterprise architecture
    • General
      • ExternalWebPublications
      • LinkedIn
      • Website
    • Music
      • Music Resources
      • Music Reviews
    • Photography
    • Podcasts
    • Security
    • Technology
      • AI
      • APIs & microservices
      • chatbots
      • Cloud
      • Cloud Native
      • Dev Meetup
      • development
        • languages
      • drone
      • Fluent Observability
        • Fluentbit
        • Fluentd
        • OpAMP
      • logsimulator
      • mindmap
      • OMESA
      • Oracle
        • API Platform CS
          • tools
        • ITSO & OEAF
        • OIC – ICS
        • Oracle Cloud Native
        • OUG
      • railroad diagrams
      • TOGAF

    Enter your email address to subscribe to this blog and receive notifications of new posts by email.

    Join 2,619 other subscribers

    RSS

    RSS Feed RSS - Posts

    RSS Feed RSS - Comments

    September 2026
    M T W T F S S
     123456
    78910111213
    14151617181920
    21222324252627
    282930  
    « Aug    

    Speaker Recognition

    Open Source Summit Speaker

    Twitter

    Tweets by mp3monster

    History

    Flickr Pics

    The real C4 LogoThe real C4 LogoBoxer Rebellion @ Brixton ElectricBoxer Rebellion @ Brixton Electric
    More Photos

    Social

    • View @mp3monster’s profile on Twitter
    • View philwilkins’s profile on LinkedIn
    • View mp3monster’s profile on GitHub
    • View mp3monster’s profile on Flickr
    • View mp3muncher’s profile on WordPress.org
    • View philmp3monster’s profile on Twitch
    Follow Phil (aka MP3Monster)'s Blog on WordPress.com

    Blog at WordPress.com.

    • Subscribe Subscribed
      • Phil (aka MP3Monster)'s Blog
      • Join 232 other subscribers
      • Already have a WordPress.com account? Log in now.
      • Phil (aka MP3Monster)'s Blog
      • Subscribe Subscribed
      • Sign up
      • Log in
      • Report this content
      • View site in Reader
      • Manage subscriptions
      • Collapse this bar
    Loading Comments...

    You must be logged in to post a comment.

    Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.
    To find out more, including how to control cookies, see here: Our Cookie Policy
    %d