Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVSS score incorrect #32

Closed
fkamming opened this issue Nov 4, 2019 · 2 comments
Closed

CVSS score incorrect #32

fkamming opened this issue Nov 4, 2019 · 2 comments
Assignees
Labels
bug Something isn't working released
Projects

Comments

@fkamming
Copy link

fkamming commented Nov 4, 2019

The HTML report uses metadata.exploitability value as CVSS score. While I can't find any documentation on the exact meaning of this value, I don't think it is supposed to reflect a CVSS score.

For example npm mongodb vulnerability has a metadata.exploitability value of 3. While the actual CVSS score is 7.5. Our npm audit html report shows several other examples where the CVSS score in the report is completely different from the actual CVSS score.

I propose to label it 'Exploitability:' instead of 'CVSS' in the npm audit html report. Or otherwise completely remove it.

@nprail
Copy link
Member

nprail commented Nov 4, 2019

@fkamming Interesting, you are right. metadata.exploitability doesn't seem to actually be the CVSS score like I thought. Which makes me curious as to what it represents. I will relabel it to "Exploitability" for now.

@nprail nprail self-assigned this Nov 4, 2019
@nprail nprail added the bug Something isn't working label Nov 4, 2019
@nprail nprail added this to To do in Development via automation Nov 4, 2019
@nprail nprail closed this as completed in 2ccb296 Nov 10, 2019
Development automation moved this from To do to Done Nov 10, 2019
@nprail
Copy link
Member

nprail commented Nov 10, 2019

🎉 This issue has been resolved in version 1.4.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working released
Projects
Development
  
Done
Development

No branches or pull requests

2 participants