Skip to content

[Feature Request] Add CVSS4 support #203

@nishitm

Description

@nishitm

Description
Currently, the endpoint /security/updates/cves.json only considers CVSS3 scores and includes only CVSS3 details in the webpage under impact.baseMetricV3 key. Since CVSS4 is now widely adopted and UCT CVE files also contain CVSS4 scores, it would be beneficial for users to see CVSS4 scores on the CVE webpage.

Proposed Solution

  • Extend the endpoint to include CVSS4 scores (e.g., new impact.baseMetricV4)
  • Update the security webpage design to display CVSS4 scores alongside CVSS3 scores

Additional Context
CVSS4 provides more granular and up-to-date vulnerability scoring, improving risk assessment for users. Supporting it would align with industry standards.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions