]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commit
cve-check: add support for cvss v4.0
authorPeter Marko <peter.marko@siemens.com>
Wed, 23 Oct 2024 09:45:22 +0000 (11:45 +0200)
committerSteve Sakoman <steve@sakoman.com>
Tue, 19 Nov 2024 19:00:18 +0000 (11:00 -0800)
commit7ce34ce58f83bc02fa2c04bec54e358e8614157e
tree41275cf630831b1cd001965a287cd42b2c286983
parent242bf4dcd4f85ec4d212fd68e060cf9fb307e96e
cve-check: add support for cvss v4.0

https://nvd.nist.gov/general/news/cvss-v4-0-official-support

CVSS v4.0 was released in November 2023
NVD announced support for it in June 2024

Current stats are:
* cvss v4 provided, but also v3, so cve-check showed a value
sqlite> select count(*) from nvd where scorev4 != 0.0 and scorev3 != 0.0;
2069
* only cvss v4 provided, so cve-check did not show any
sqlite> select count(*) from nvd where scorev4 != 0.0 and scorev3 = 0.0;
260

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 358dbfcd80ae1fa414d294c865dd293670c287f0)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/classes/cve-check.bbclass
meta/classes/vex.bbclass
meta/recipes-core/meta/cve-update-nvd2-native.bb
scripts/cve-json-to-text.py