Skip to content

CVSS 4.0 calculator on advisory improvement screen does not support non-base metrics #5357

@mhassan1

Description

@mhassan1

The CVSS 4.0 calculator on the advisory improvement screen does not support non-base (i.e. threat, environmental, and supplemental) metrics, as defined in the spec. There are a couple problems with this:

  1. The calculator does not consider them in its calculation of severity (I'm not sure how big of a problem this is)
  2. It's not possible to submit the advisory improvement request if any of those metrics is present (even if it is already present)

Here's an example of a PR where I was required to remove the E threat metric, even though that wasn't something that I wanted to do, in order to submit the page. With the E metric there, I see an error (The entered vector string contains an error and cannot populate a score.).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions