Skip to content

shared test.cve.org URLs are context-dependent #3426

@ElectricNroff

Description

@ElectricNroff

If my web browser (such as desktop Chrome or Firefox) displays a URL such as https://test.cve.org/CVERecord?id=CVE-2025-20624 and I navigated the test.cve.org website through the "Find a Test CVE Record/ID (Legacy)" option, then the web page content shows a published CVE Record with data from the cveawg-test.mitre.org server. However, if I then share this URL with a colleague, their web browser shows "This ID has been reserved by a CNA" (corresponding to cveawg.mitre.org data) because the URL itself does not have sufficient information to uniquely identify what JSON data is being rendered on the test.cve.org website. In addition, there is nothing on the test.cve.org website that warns me that a URL may have a vastly different meaning when accessed by a different person on their own web browser.

Community members may routinely need to share test-server URLs with colleagues, as part of the process of ensuring that the test data has expected properties before using the production server.

It would be best if the URL, displayed by the browser during a test.cve.org visit, was always directly usable upon this sharing.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    Needs Triage

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions