# Become a Mitre CNA

**URL:** https://forum.opensearch.org/t/become-a-mitre-cna/5807
**Category:** OpenDistro
**Tags:** cve
**Created:** [April 30, 2021, 1:59pm UTC](https://forum.opensearch.org/t/become-a-mitre-cna/5807 "2021-04-30T13:59:06Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![frotsch](https://avatars.discourse-cdn.com/v4/letter/f/839c29/32.png) [@frotsch](https://forum.opensearch.org/u/frotsch)
#### Post date: [April 30, 2021, 1:59pm UTC](https://forum.opensearch.org/t/become-a-mitre-cna/5807/1 "2021-04-30T13:59:06Z")

</div>

In order to publish CVE’s for OpenSearch (and OpenDistro) I propose that Amazon/AWS (or any governance organization which is supposed to govern OpenSearch later) become a [CNA](https://cve.mitre.org/cve/cna.html#become_a_cna) (CVE Numbering Authority) with [MITRE](https://cve.mitre.org). I think its very important to create CVE’s for security issues within OpenSearch to maintain trust and transparency.

BTW: Just wondering that Amazon/AWS is not already listed as CNA for their products (for example: OpenDistro or Corretto) see [List of CNA’s](https://cve.mitre.org/cve/request_id.html)

---

<div class="post-metadata">

### Author: ![kris](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/kris/32/2208_2.png) [@kris](https://forum.opensearch.org/u/kris)
#### Post date: [February 6, 2023, 7:52pm UTC](https://forum.opensearch.org/t/become-a-mitre-cna/5807/2 "2023-02-06T19:52:58Z")

</div>


