Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add CVSSv4 score #306

Merged
merged 4 commits into from
Jan 25, 2025
Merged

Add CVSSv4 score #306

merged 4 commits into from
Jan 25, 2025

Conversation

SashaTail
Copy link
Contributor

@SashaTail SashaTail commented Jan 24, 2025

fixes #305

@SashaTail SashaTail changed the title Add CVSSv4 score #305 Add CVSSv4 score Jan 24, 2025
@SashaTail
Copy link
Contributor Author

Example document in mongodb
{ "_id": { "$oid": "6793f40cb0f97a34a12abfbb" }, "access": {}, "assigner": "[email protected]", "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*", "matchCriteriaId": "E70C6D8D-C9C3-4D92-8DFC-71F59E068295" }, { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "691FA41B-C2CE-413F-ABB1-0B22CB322807" }, { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:*", "matchCriteriaId": "09E6085C-A61E-4A89-BF80-EDD9A7DF1E47" }, { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:7.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "D835D592-2423-44C6-804A-3AD010112E7C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:7.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "568E2561-A068-46A2-B331-BBA91FC96F0C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*", "matchCriteriaId": "B578E383-0D77-4AC7-9C81-3F0B8C18E033" }, { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*", "matchCriteriaId": "B06BE74B-83F4-41A3-8AD3-2E6248F7B0B2" } ] } ] } ], "cvss": null, "cvss3": 5.5, "cvss3Source": "[email protected]", "cvss3Time": { "$date": "2025-01-23T19:54:01.037Z" }, "cvss3Type": "Primary", "cvss3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss4": 10, "cvss4Source": "[email protected]", "cvss4Time": { "$date": "2025-01-23T19:54:01.037Z" }, "cvss4Type": "Secondary", "cvss4Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "cwe": "NVD-CWE-noinfo", "epss": "0.00043", "epssMetric": { "percentile": "0.11404", "lastModified": { "$date": "2025-01-24T09:09:31.000Z" } }, "exploitability3": { "attackvector": "LOCAL", "attackcomplexity": "LOW", "privilegesrequired": "LOW", "userinteraction": "NONE", "scope": "UNCHANGED" }, "exploitability4": { "attackvector": "NETWORK", "attackcomplexity": "LOW", "attackrequirements": "NONE", "privilegesrequired": "NONE", "userinteraction": "NONE", "exploitmaturity": "NOT_DEFINED" }, "exploitabilityScore3": 1.8, "id": "CVE-2017-13322", "impact": {}, "impact3": { "availability": "HIGH", "confidentiality": "NONE", "integrity": "NONE" }, "impact4": { "vulnerable_system_confidentiality": "HIGH", "vulnerable_system_integrity": "HIGH", "vulnerable_system_availability": "HIGH", "subsequent_system_confidentiality": "HIGH", "subsequent_system_integrity": "HIGH", "subsequent_system_availability": "HIGH" }, "impactScore3": 3.6, "lastModified": { "$date": "2025-01-23T19:54:01.037Z" }, "modified": { "$date": "2025-01-23T19:54:01.037Z" }, "products": [ "android" ], "published": { "$date": "2025-01-17T23:15:10.747Z" }, "references": [ "https://source.android.com/security/bulletin/pixel/2018-05-01" ], "status": "Analyzed", "summary": "In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", "vendors": [ "google" ], "vulnerable_configuration": [ "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:7.1.1:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:7.1.2:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*" ], "vulnerable_configuration_cpe_2_2": [], "vulnerable_configuration_stems": [ "cpe:2.3:o:google:android" ], "vulnerable_product": [ "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:7.1.1:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:7.1.2:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*", "cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*" ], "vulnerable_product_stems": [ "cpe:2.3:o:google:android" ] }

@P-T-I
Copy link
Member

P-T-I commented Jan 25, 2025

Thank you! I'll have a look at this asap!

@P-T-I
Copy link
Member

P-T-I commented Jan 25, 2025

@SashaTail would you be so kind to incorporate the black formatting changes?

@P-T-I P-T-I merged commit 7df9dee into cve-search:master Jan 25, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

CVSSv4 score
2 participants