Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-5616

OSV Updater cannot determine severity without CVSS score

XMLWordPrintable

      OSV scheme basically relies on CVSS scores for "severity", which is fine, but I found a case where CVSS score was not specified, yet a severity existed. It was inside the "database_specific" field. I wonder if we should look for this as a backup.

      Here is the example: https://osv.dev/vulnerability/GHSA-j436-h7hm-rx46

       

              jcroslan@redhat.com Joseph Crosland
              rtannenb@redhat.com Ross Tannenbaum
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: