Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-5616

OSV Updater cannot determine severity without CVSS score

XMLWordPrintable

    • 0

      OSV scheme basically relies on CVSS scores for "severity", which is fine, but I found a case where CVSS score was not specified, yet a severity existed. It was inside the "database_specific" field. I wonder if we should look for this as a backup.

      Here is the example: https://osv.dev/vulnerability/GHSA-j436-h7hm-rx46

       

            jcroslan@redhat.com Joseph Crosland
            rtannenb@redhat.com Ross Tannenbaum
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: