diff options
author | Peter Marko <peter.marko@siemens.com> | 2024-10-23 11:45:22 +0200 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2024-10-25 15:25:33 +0100 |
commit | 3b551fc466b992ac09ab04d54ddcb3c36e1dd670 (patch) | |
tree | 936a552df0d2db48fd85b3e62c39754791c4771e /scripts/cve-json-to-text.py | |
parent | 96a6df7b14c51be156995b79767b9fadd15f9b6e (diff) | |
download | poky-3b551fc466b992ac09ab04d54ddcb3c36e1dd670.tar.gz |
cve-check: add support for cvss v4.0
https://nvd.nist.gov/general/news/cvss-v4-0-official-support
CVSS v4.0 was released in November 2023
NVD announced support for it in June 2024
Current stats are:
* cvss v4 provided, but also v3, so cve-check showed a value
sqlite> select count(*) from nvd where scorev4 != 0.0 and scorev3 != 0.0;
2069
* only cvss v4 provided, so cve-check did not show any
sqlite> select count(*) from nvd where scorev4 != 0.0 and scorev3 = 0.0;
260
(From OE-Core rev: 358dbfcd80ae1fa414d294c865dd293670c287f0)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'scripts/cve-json-to-text.py')
-rwxr-xr-x | scripts/cve-json-to-text.py | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/scripts/cve-json-to-text.py b/scripts/cve-json-to-text.py index 5531ee5eb6..87a5669987 100755 --- a/scripts/cve-json-to-text.py +++ b/scripts/cve-json-to-text.py | |||
@@ -125,6 +125,8 @@ def process_data(filename, data): | |||
125 | lines += "CVSS v2 BASE SCORE: %s\n" % issue["scorev2"] | 125 | lines += "CVSS v2 BASE SCORE: %s\n" % issue["scorev2"] |
126 | if "scorev3" in issue: | 126 | if "scorev3" in issue: |
127 | lines += "CVSS v3 BASE SCORE: %s\n" % issue["scorev3"] | 127 | lines += "CVSS v3 BASE SCORE: %s\n" % issue["scorev3"] |
128 | if "scorev4" in issue: | ||
129 | lines += "CVSS v4 BASE SCORE: %s\n" % issue["scorev4"] | ||
128 | if "vector" in issue: | 130 | if "vector" in issue: |
129 | lines += "VECTOR: %s\n" % issue["vector"] | 131 | lines += "VECTOR: %s\n" % issue["vector"] |
130 | if "vectorString" in issue: | 132 | if "vectorString" in issue: |