You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Vulnerability page for a CVE vulnerability lists CVSS scores but does not include any information on EPSS scores.
Proposed Behavior
Add EPSS score and EPSS Percentile score to vulnerability pages for CVE vulnerabilities.
Currently, when viewing such a vulnerability, one has to click on "Affected Projects" and then choose a project and then click on "Exploit Predictions". And remember exactly which CVE you were interested in!
Well, the raw numbers would be an MVP and would (hopefully) be a prompt for other users to weigh in.
As for graph/widget, I would want such to be considered as part of an overhaul of the whole vulnerability screen... something that could address a lot of niggles:
Make it clear whether dislayed CVSS scores are CVSS2 or CVSS3. Or CVSS4.... not yet supported in DT but on the backlog.
Link to orginal CVE. A GHSA vulnerability include links to the NVD in the references section, But a CVE vuln has no equivalent link... although I am pretty certain it used to older versions of DT.
Weakness (CWE) could have an additional link to (say) "Other vulnerabilities with same CWE".
ie, by considering overall functionality/layout of the screen, it should be easier to design how to fit a graph/widget for EPSS into the whole.
Current Behavior
The Vulnerability page for a CVE vulnerability lists CVSS scores but does not include any information on EPSS scores.
Proposed Behavior
Add EPSS score and EPSS Percentile score to vulnerability pages for CVE vulnerabilities.
Currently, when viewing such a vulnerability, one has to click on "Affected Projects" and then choose a project and then click on "Exploit Predictions". And remember exactly which CVE you were interested in!
Checklist
The text was updated successfully, but these errors were encountered: