← Prev in month ← Prev in thread
Next in thread → Next in month →

CVSS logic

From
Art Manion <>
Date
2017-02-23T16:22:28+00:00
ID
Thread
CVSS logic
All,

Harold Booth noted this on the call yesterday via chat:

> From [~harold.booth]: I am afraid I missed the opportunity to mention
> concerns...I have one suggested change: line 456 in vuln.xsd should
> be: <xs:element name="ScoreSetV3" minOccurs="0"
> maxOccurs="unbounded"> to not require CVSSv3

This caused me to look through the rest of the CVSS XML.

For each vulnerability in a CVRF document
  CVSSScoreSets are optional, there can be 0 or 1
    there can be 0 or more CVSSv2 scores
    there can be 0 or more CVSSv3 scores
      for either v2 or v3 there must be 1 and only 1 Base score
      other CVSS scores and the vectors are optional

This means there can be one CVSS base score but more than one vector, or
more than one Temporal score per vulnerability?

Do we need to clarify/tighten the CVSS score logic, beyond Harold's change?

JIRA ticket:

  https://issues.oasis-open.org/browse/CSAF-21


 - Art
← Prev in month ← Prev in thread
Next in thread → Next in month →