Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Automatic vulnerability scoring decision #85

Open
adulau opened this issue Nov 18, 2024 · 0 comments
Open

Automatic vulnerability scoring decision #85

adulau opened this issue Nov 18, 2024 · 0 comments
Labels
enhancement New feature or request

Comments

@adulau
Copy link
Member

adulau commented Nov 18, 2024

Following a discussion with @cedricbonhomme about automatic scoring with information within vulnerability-lookup, an automatic vulnerability scoring decision can be calculated automatically:

Screenshot from 2024-11-18 11-02-44

Mapping for vulnerability lookup

  • Track - The vulnerability is sourced in vulnerability lookup from one or more sources without any sighting or comments.
  • Track* - The vulnerability is sourced (or not for vulnerability without source publication) in vulnerability lookup from one or more sources with one or more comments or one sighting from non-sources (not NVD or alike).
  • Attend - The vulnerability is sourced (or not for vulnerability without source publication) in vulnerability lookup from one or more sources with one or more comments or two or more sightings from non-sources (not NVD or alike).
  • Act - The vulnerability is sourced (or not for vulnerability without source publication) in vulnerability lookup from one or more sources with one or more comments or two or more sightings from non-sources (not NVD or alike) and present in KEV (CISA) or KEV (local instance) flag?.

Based on CISA - THE VULNERABILITY SCORING DECISION - Page 3

@adulau adulau added the enhancement New feature or request label Nov 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant