Skip to content

CVSS 4.0 calculator on advisory improvement screen does not support non-base metrics #5357

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
mhassan1 opened this issue Mar 12, 2025 · 0 comments

Comments

@mhassan1
Copy link

mhassan1 commented Mar 12, 2025

The CVSS 4.0 calculator on the advisory improvement screen does not support non-base (i.e. threat, environmental, and supplemental) metrics, as defined in the spec. There are a couple problems with this:

  1. The calculator does not consider them in its calculation of severity (I'm not sure how big of a problem this is)
  2. It's not possible to submit the advisory improvement request if any of those metrics is present (even if it is already present)

Here's an example of a PR where I was required to remove the E threat metric, even though that wasn't something that I wanted to do, in order to submit the page. With the E metric there, I see an error (The entered vector string contains an error and cannot populate a score.).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant