Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVSS 4.0 #715

Open
DanielRuf opened this issue Oct 31, 2023 · 3 comments
Open

CVSS 4.0 #715

DanielRuf opened this issue Oct 31, 2023 · 3 comments

Comments

@DanielRuf
Copy link

Tomorrow (1st of November) CVSS 4.0 will be published according to the details at https://www.first.org/cvss/v4-0/

What needs to be done to support this?

@StefanFl
Copy link
Collaborator

StefanFl commented Nov 1, 2023

Hi @DanielRuf, thanks for making me aware of this. I will have a look into it soon. The mechanics that are relevant for SecObserve seem not to have changed (0-10 and mapping to severities). Will have to update some scanners and rename the cvss fields.

@DanielRuf
Copy link
Author

That sounds good.

I'm not sure if renaming fields makes sense. Normally I'm accustomed to having two versions shown in the CVE databases (if provided).

I didn't check SecObserve in detail yet, so not sure if currently v2 and v3 CVSS scores are used and supported per entry or if it is just v3.

CVSS v4 will lead to different results because of the environmental factor.

It will probably take some time until the CVE databases, CNAs and tools add (additional) support for CVSS v4 and they will still use CVSS v2 and v3 as fields.

Is it encouraged by SecObserve to use the latest available "stable" CVSS version?

@StefanFl
Copy link
Collaborator

StefanFl commented Nov 8, 2023

I will wait until one of the SCA scanners (Trivy, Grype, dependency-check) implements support for CVSS 4. Then we will see, how they put the information in their output and how to use it in SecObserve. Separate fields for v3 and v4 might be a good idea.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants