Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature request: Add source (reference) to CVSS #624

Closed
jaccoNCSCNL opened this issue May 22, 2023 · 4 comments · Fixed by #761 or #767
Closed

Feature request: Add source (reference) to CVSS #624

jaccoNCSCNL opened this issue May 22, 2023 · 4 comments · Fixed by #761 or #767
Assignees
Labels
csaf 2.1 csaf 2.1 work editor-revision already worked on in the editor revision

Comments

@jaccoNCSCNL
Copy link

As a national CERT we often bundle multiple advisories into one. This also means that we sometimes have conflicting CVSS scores from different sources for the same vulnerability.
We think that it would make sense to add an optional source (or reference) to a CVSS score which would indicate who made this score.

@tschmidtb51
Copy link
Contributor

Thank you for the suggestion. The TC will discuss the suggestion.

@sthagen
Copy link
Contributor

sthagen commented Sep 27, 2023

During the 2023-09-27 meeting of the TC the members agreed to implement the feature in CSAF v2.1.

@tschmidtb51 tschmidtb51 added csaf 2.1 csaf 2.1 work and removed csaf 2.x Maybe future labels Oct 25, 2023
@jaccoNCSCNL
Copy link
Author

Thanks!

@tschmidtb51 tschmidtb51 added the motion_passed A motion has passed label May 29, 2024
tschmidtb51 added a commit to tschmidtb51/csaf that referenced this issue Jul 31, 2024
- addresses parts of oasis-tcs#624
- rename scores to metrics
- add new level `content` to group scores (and metrics)
- add `source` as URI
tschmidtb51 added a commit to tschmidtb51/csaf that referenced this issue Jul 31, 2024
- addresses parts of oasis-tcs#624
- adopt prose in section 3 to reflect schema
tschmidtb51 added a commit to tschmidtb51/csaf that referenced this issue Jul 31, 2024
- addresses parts of oasis-tcs#624
- adopt prose in other sections to reflect schema
tschmidtb51 added a commit to tschmidtb51/csaf that referenced this issue Jul 31, 2024
- addresses parts of oasis-tcs#624
- adapt examples to reflect changed schema
tschmidtb51 added a commit to tschmidtb51/csaf that referenced this issue Jul 31, 2024
- addresses parts of oasis-tcs#624
- adapt testfiles to reflect current schema
@tschmidtb51 tschmidtb51 added the editor-revision already worked on in the editor revision label Jul 31, 2024
@tschmidtb51 tschmidtb51 linked a pull request Jul 31, 2024 that will close this issue
@tschmidtb51
Copy link
Contributor

@jaccoNCSCNL To follow the OASIS process, please also announced the request on the comment mailing list. A simple email pointing to the issue should be sufficient.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
csaf 2.1 csaf 2.1 work editor-revision already worked on in the editor revision
Projects
None yet
3 participants