Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add EPSS Scores to Vulnerabilities Pages for CVEs #544

Closed
2 tasks done
msymons opened this issue Jul 10, 2023 · 3 comments · Fixed by #832
Closed
2 tasks done

Add EPSS Scores to Vulnerabilities Pages for CVEs #544

msymons opened this issue Jul 10, 2023 · 3 comments · Fixed by #832
Labels
enhancement New feature or request
Milestone

Comments

@msymons
Copy link
Member

msymons commented Jul 10, 2023

Current Behavior

The Vulnerability page for a CVE vulnerability lists CVSS scores but does not include any information on EPSS scores.

Proposed Behavior

Add EPSS score and EPSS Percentile score to vulnerability pages for CVE vulnerabilities.

Currently, when viewing such a vulnerability, one has to click on "Affected Projects" and then choose a project and then click on "Exploit Predictions". And remember exactly which CVE you were interested in!

Checklist

@msymons msymons added the enhancement New feature or request label Jul 10, 2023
@nscuro
Copy link
Member

nscuro commented Jul 10, 2023

Great suggestion @msymons!

Do you have any idea of how you'd prefer this information to be presented? Just raw numbers, or some sort of graph or widget?

@msymons
Copy link
Member Author

msymons commented Jul 11, 2023

Well, the raw numbers would be an MVP and would (hopefully) be a prompt for other users to weigh in.
As for graph/widget, I would want such to be considered as part of an overhaul of the whole vulnerability screen... something that could address a lot of niggles:

  1. Make it clear whether dislayed CVSS scores are CVSS2 or CVSS3. Or CVSS4.... not yet supported in DT but on the backlog.
  2. Link to orginal CVE. A GHSA vulnerability include links to the NVD in the references section, But a CVE vuln has no equivalent link... although I am pretty certain it used to older versions of DT.
  3. Weakness (CWE) could have an additional link to (say) "Other vulnerabilities with same CWE".

ie, by considering overall functionality/layout of the screen, it should be easier to design how to fit a graph/widget for EPSS into the whole.

@aravindparappil46
Copy link
Contributor

aravindparappil46 commented Mar 26, 2024

Hello!
I have raised a PR to address this request: #789
(Just displaying the raw numbers for now)

EDIT: Something happened to the old branch while I was attempting to fix conflicts and the PR got closed 🙈 .
Have opened a new PR #832

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
3 participants