Replies: 2 comments
-
|
Hi @aringo, the response time to this discussion was much longer than usual thank you for your patience and for taking the time to create it. We previously had a workflow in place, but it was causing several errors, and this issue ended up being overlooked for quite some time. Thank you for bringing it to our attention. We’ll be working on fixing it. Thanks again! |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
@aringo We have updated the EPSS scores of all CVEs and will continue to do so in upcoming releases. #12526 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
This concerns the use of EPSS (Exploit Prediction Scoring System) scores in Nuclei templates.
Currently, the EPSS scores appear to be statically included in the templates. EPSS is a daily-updated score provided by FIRST.org, so the values can change significantly over time and vary a lot - like if something gets added to the KEV. Additionally, templates are signed so they would need resigned daily.
Issues with stale data: EPSS scores embedded in the templates can quickly become outdated.
Possible Ideas:
Looking at templates today finally decided to say something. Sorry if this has been covered in another thread.
RingoBeta Was this translation helpful? Give feedback.
All reactions