-
Notifications
You must be signed in to change notification settings - Fork 9
Open
Description
Description
Currently, the endpoint /security/updates/cves.json only considers CVSS3 scores and includes only CVSS3 details in the webpage under impact.baseMetricV3 key. Since CVSS4 is now widely adopted and UCT CVE files also contain CVSS4 scores, it would be beneficial for users to see CVSS4 scores on the CVE webpage.
Proposed Solution
- Extend the endpoint to include CVSS4 scores (e.g., new
impact.baseMetricV4) - Update the security webpage design to display CVSS4 scores alongside CVSS3 scores
Additional Context
CVSS4 provides more granular and up-to-date vulnerability scoring, improving risk assessment for users. Supporting it would align with industry standards.
Metadata
Metadata
Assignees
Labels
No labels