diff options
author | Peter Marko <peter.marko@siemens.com> | 2024-10-23 11:45:22 +0200 |
---|---|---|
committer | Steve Sakoman <steve@sakoman.com> | 2024-11-26 05:37:09 -0800 |
commit | a99c033f4c22b2270acebb45e16487eade2b77c5 (patch) | |
tree | 72df7f62f7e20916eb75f45fe36b9a9436c9e4de /meta/classes/vex.bbclass | |
parent | 6a44d7c07807fc1f84b412a2fced054f71818d70 (diff) | |
download | poky-a99c033f4c22b2270acebb45e16487eade2b77c5.tar.gz |
cve-check: add support for cvss v4.0
https://nvd.nist.gov/general/news/cvss-v4-0-official-support
CVSS v4.0 was released in November 2023
NVD announced support for it in June 2024
Current stats are:
* cvss v4 provided, but also v3, so cve-check showed a value
sqlite> select count(*) from nvd where scorev4 != 0.0 and scorev3 != 0.0;
2069
* only cvss v4 provided, so cve-check did not show any
sqlite> select count(*) from nvd where scorev4 != 0.0 and scorev3 = 0.0;
260
(From OE-Core rev: 7ce34ce58f83bc02fa2c04bec54e358e8614157e)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 358dbfcd80ae1fa414d294c865dd293670c287f0)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta/classes/vex.bbclass')
-rw-r--r-- | meta/classes/vex.bbclass | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/meta/classes/vex.bbclass b/meta/classes/vex.bbclass index bb16e2a529..01d4e52051 100644 --- a/meta/classes/vex.bbclass +++ b/meta/classes/vex.bbclass | |||
@@ -282,6 +282,7 @@ def cve_write_data_json(d, cve_data, cve_status): | |||
282 | cve_item["summary"] = cve_data[cve]["NVD-summary"] | 282 | cve_item["summary"] = cve_data[cve]["NVD-summary"] |
283 | cve_item["scorev2"] = cve_data[cve]["NVD-scorev2"] | 283 | cve_item["scorev2"] = cve_data[cve]["NVD-scorev2"] |
284 | cve_item["scorev3"] = cve_data[cve]["NVD-scorev3"] | 284 | cve_item["scorev3"] = cve_data[cve]["NVD-scorev3"] |
285 | cve_item["scorev4"] = cve_data[cve]["NVD-scorev4"] | ||
285 | cve_item["vector"] = cve_data[cve]["NVD-vector"] | 286 | cve_item["vector"] = cve_data[cve]["NVD-vector"] |
286 | cve_item["vectorString"] = cve_data[cve]["NVD-vectorString"] | 287 | cve_item["vectorString"] = cve_data[cve]["NVD-vectorString"] |
287 | if 'status' in cve_data[cve]: | 288 | if 'status' in cve_data[cve]: |