Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-7858

Make EPSS available in policy field when configure policy

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • rhacs-4.7.0
    • rhacs-policy
    • None
    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • Application Services Delivery Platform
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      RHACS 4.7 has EPSS available as chance of exploitation of a CVE.
      But it's impossible to define policy by using this new feature, for example: CVE1 which has CVSS score 9.5 but EPSS 5% should be taken as less important than CVE2 which has CVSS score 8.5 but with EPSS 90%.
      Customer will be able to leverage this new feature and prioritize the CVE more reasonable. 

              bmichael@redhat.com Boaz Michaely
              laliu1@redhat.com Lan Liu
              None
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                None
                None