Aliases for Internal Vulnerabilities and Custom CVSS #5584
stenocereus
started this conversation in
Ideas
Replies: 1 comment
-
|
The ability to set your own custom CVSS would be highly appreciated. Or even an own custom risk score? Are there any plan for this? |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
One feature that is highly interesting in Dependency-Track is the possibility to create Internal Vulnerabilities.
Some of these internally reported vulnerabilities may end up as a CVE after being publicly disclosed, and this is where I would suggest have Dependency-Track allow us to add aliases to the internal vulnerability. It would help us in handling two scenarios:
Allowing us to add aliases to the Internal Vulnerability to connect them to the public CVE when available
Enable us to make our own CVSS rating for public vulnerabilities. For example, if NVD scores a CVE at 7.5, but we consider it to be at 5.5 we could make an Internal Vulnerability with CVSS 5.5 and use the CVE alias to connect them
Beta Was this translation helpful? Give feedback.
All reactions