-
Couldn't load subscription status.
- Fork 62
Open
Description
Currently, although the website can render different metrics found in containers:cna:metrics, it doesn't take into account the attached scenarios. The end result can lead to confusion for users of the website.
A couple of examples:
- Record with only one CVSS metric for a non-
GENERALscenario; it seems that the metric is universal for said product and vulnerability
https://www.cve.org/CVERecord?id=CVE-2023-39916 - Record with two distinct CVSS metrics for two distinct scenarios; both metrics are shown but there is no clear indication which one applies when
https://www.cve.org/CVERecord?id=CVE-2024-0012
In both cases, because the descriptions of the CVEs are concise and clear, a user can deduce how the metric score is to be taken into account.
However this is not always the case and having the extra scenario information would benefit the readability of the metric section.
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
Needs Triage