DependencyTrack / DependencyTrack/dependency-track

unassigned severity while the score is set for the vulnerability

Open
#4,706 3 comments 0 reactions 0 assignees View on GitHub
defect in triage
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

![Image](https://github.com/user-attachments/assets/a47cc4fb-7da8-40f8-8a1e-dfebe03915cf)

![Image](https://github.com/user-attachments/assets/dae0bff4-3307-4348-90e1-f300bbdb3e15)

Hey guys,
I am using Dependecy track for a project and I just noticed that some vulnerabilities have the unassigned status while when you search the vulnerability on the NVD you see the actual score of the vulnerability.
Also, the link that Dependecy track gives you on the vulnerability clearly says the severity of the vulnerability so I do not understand why the status is unassigned .

### Steps to Reproduce

1.upload a BOM with windows 10 family edition (version: 10.0.19045.3930)
2. Watch the latest vulnerabilities
The BOM I use only has windows family edition and here are some screenshots has an example of the issue.

### Expected Behavior

I would expect to have the severity of the CVE instead of (UNASSIGNED ) as is it shown in NVD database.

### Dependency-Track Version

4.12.6

### Dependency-Track Distribution

Executable WAR

### Database Server

H2

### Database Server Version

_No response_

### Browser

Mozilla Firefox

### Checklist

- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.