aboutcode-org / aboutcode-org/vulnerablecode

Wrong CVSS3 V3.1 QR "MODERATE"

Aperta
#1,186 1 commento 1 reazione 0 assegnatari Vedi su GitHub
Lingua principale
Python
Stelle
702
Fork
328
Merge medio
3g 8h
PR unite (30g)
3

Descrizione

GitHub advisories provide the severity "MODERATE" and as a result VulnerableCode does also provide this severity which according to the [specification](https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale) should be "MEDIUM" instead.

For example, this severity is classified as "MODERATE" by GitHub:
https://github.com/advisories/GHSA-c7mc-q43h-5672

It is reported by VulnerableCode as:
```json
{
"reference_url": "https://github.com/advisories/GHSA-c7mc-q43h-5672",
"reference_id": "GHSA-c7mc-q43h-5672",
"scores": [
{
"value": "MODERATE",
"scoring_system": "cvssv3.1_qr",
"scoring_elements": ""
}
],
"url": "https://github.com/advisories/GHSA-c7mc-q43h-5672"
}
```

It would be good if VulnerableCode could map "MODERATE" to the correct "MEDIUM" in its API response.

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.