-
Bug
-
Resolution: Done
-
Major
-
None
-
None
-
None
-
False
-
-
False
-
Very Likely
-
0
I noticed that CVE-2024-24791 is available on both the Red Hat website
and the Security Data API:
- https://access.redhat.com/security/cve/cve-2024-24791
- https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2024-24791.json
However, according to the VEX deletion record, this CVE was removed on
2025-07-17:
$ curl -s https://security.access.redhat.com/data/csaf/v2/vex/deletions.csv | grep cve-2024-24791 "2024/cve-2024-24791.json","2025-07-17T13:48:37+00:00"
Could you please clarify why it was removed from VEX?
Also, are there different criteria for publishing data across the web
interface, the Security Data API, and the VEX feed?