Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVSS vector should be generated in Base/Threat/Environmental/Supplemental order #34

Closed
ViperGeek opened this issue Oct 6, 2023 · 3 comments
Labels
bug Something isn't working good first issue Good for newcomers

Comments

@ViperGeek
Copy link
Contributor

When we asked to reorder the Base and Supplemental sections of the GUI, the vector string got inadvertently reordered as well. In all our docs, JSON, and regex, the official order of the CVSS vector string is:

AV/AC/AT/PR/UI/V[CIA]/S[CIA]/E/[CIA]R/MAV/MAC/MAT/MPR/MUI/MV[CIA]/MS[CIA]/S/AU/R/V/RE/U

(Base/Threat/Environmental/Supplemental)

Please keep the GUI arrangement as-is, but update the vector string generation order.

@pandatix
Copy link
Contributor

Fixed by #35, merged 🎉

@skontar skontar closed this as completed Oct 17, 2023
@ViperGeek
Copy link
Contributor Author

This may be unrelated to this fix, but it seems like the Supplemental Metrics no longer "stick" when selected:

https://redhatproductsecurity.github.io/cvss-v4-calculator/

@pandatix
Copy link
Contributor

pandatix commented Oct 17, 2023

Thanks for the info Dave, I'll test it and provide a fix as soon as possible :)

EDIT: easy to diagnose, I did not implement the behavior of (non-)mandatory metrics, working on it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working good first issue Good for newcomers
Projects
None yet
Development

No branches or pull requests

3 participants