Skip to content

CVSS 4.0 calculator on advisory improvement screen does not support non-base metrics #5357

Open
@mhassan1

Description

@mhassan1

The CVSS 4.0 calculator on the advisory improvement screen does not support non-base (i.e. threat, environmental, and supplemental) metrics, as defined in the spec. There are a couple problems with this:

  1. The calculator does not consider them in its calculation of severity (I'm not sure how big of a problem this is)
  2. It's not possible to submit the advisory improvement request if any of those metrics is present (even if it is already present)

Here's an example of a PR where I was required to remove the E threat metric, even though that wasn't something that I wanted to do, in order to submit the page. With the E metric there, I see an error (The entered vector string contains an error and cannot populate a score.).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions