aboutcode-org / aboutcode-org/vulnerablecode
Wrong CVSS3 V3.1 QR "MODERATE"
- 主要语言
- Python
- 星标
- 702
- 派生
- 328
- 平均合并
- 3 天 8 小时
- 30 天内合并 PR
- 3
描述
GitHub advisories provide the severity "MODERATE" and as a result VulnerableCode does also provide this severity which according to the [specification](https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale) should be "MEDIUM" instead.
For example, this severity is classified as "MODERATE" by GitHub:
https://github.com/advisories/GHSA-c7mc-q43h-5672
It is reported by VulnerableCode as:
```json
{
"reference_url": "https://github.com/advisories/GHSA-c7mc-q43h-5672",
"reference_id": "GHSA-c7mc-q43h-5672",
"scores": [
{
"value": "MODERATE",
"scoring_system": "cvssv3.1_qr",
"scoring_elements": ""
}
],
"url": "https://github.com/advisories/GHSA-c7mc-q43h-5672"
}
```
It would be good if VulnerableCode could map "MODERATE" to the correct "MEDIUM" in its API response.
贡献指南
这个仓库没有索引到贡献指南
评估
这个 Issue 还没有评估数据。