-
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathsource.json
More file actions
122 lines (122 loc) · 5.26 KB
/
Copy pathsource.json
File metadata and controls
122 lines (122 loc) · 5.26 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
{
"owner": "Forum of Incident Response and Security Teams, Inc.",
"licence": "CVSS is owned by FIRST and used by permission",
"terms": "https://www.first.org/cvss/v4.0/specification-document#CVSS-License",
"cvss_31_source": "https://www.first.org/cvss/v3.1/examples",
"cvss_40_source": "https://www.first.org/cvss/v4.0/examples",
"cvss_40_document_version": "1.8",
"transformation": "selected published Base vector, score and severity values encoded as JSON",
"cvss_20_complete_qualification": {
"source": "https://www.first.org/cvss/v2/guide",
"transformation": "selected the published Base, Temporal and Environmental examples and encoded their vectors and scores as JSON"
},
"cvss_30_complete_qualification": {
"sources": [
"https://www.first.org/cvss/v3.1/user-guide",
"https://www.first.org/cvss/v3.0/use-design"
],
"transformation": "selected the published complete vector and Base, Temporal and Environmental scores and encoded them as JSON"
},
"cvss_31_complete_qualification": {
"sources": [
"https://www.first.org/cvss/v3.1/user-guide",
"https://www.first.org/cvss/v3-1/use-design"
],
"transformation": "selected the published complete vector and Base, Temporal and Environmental scores and encoded them as JSON"
},
"cvss_40_qualification": {
"repository": "https://github.com/FIRSTdotorg/cvss-resources",
"commit": "48f85d84a036de9c610668f9496c12b5040a9ae3",
"path": "vectorFiles/reference-scores",
"sha256": "3b60f12899249bf8b48e01ff0aba451f052a836b22c6a3ffd880b7a5cc2fea4f",
"length": 11648072,
"transformation": "retained every record ending in E:A, removed that default threat suffix, uppercased severity labels and encoded the result as compact JSON"
},
"cvss_40_complete_qualification": {
"repository": "https://github.com/FIRSTdotorg/cvss-resources",
"commit": "48f85d84a036de9c610668f9496c12b5040a9ae3",
"path": "vectorFiles/reference-scores",
"sha256": "3b60f12899249bf8b48e01ff0aba451f052a836b22c6a3ffd880b7a5cc2fea4f",
"length": 11648072,
"records": 66298,
"valid": 41270,
"invalid": 25028,
"bare_invalid": 33,
"decoded_sha256": "0bcc7bb6227d75d24dd1dc89db1c903649e4b951837e573abf290d255d9523bd",
"decoded_length": 9911450,
"transformation": "discarded 33 source lines which contain no vector, parsed the remaining Python literals, represented error records as invalid vectors without implementation-specific error text, uppercased valid severity labels, encoded compact JSON and gzip-compressed it with an empty filename and zero timestamp"
},
"cvss_40_rounding_qualification": {
"repository": "https://github.com/RedHatProductSecurity/cvss-v4-calculator",
"commit": "d1eafe06859e6610600f772ed98502bc1cd63526",
"path": "cvss40.js",
"sha256": "6625cc93aae9f01bc9990e4b36f4b133995b32072da90bb7be369d93db9173aa",
"length": 44895,
"records": 157,
"occurrences": 159,
"generator": "differential/cmd/cvss40-corrections",
"transformation": "ran every valid retained reference vector through the pinned Red Hat calculator revision, retained each unique vector whose score changed under the current half-up rounding correction and verified duplicate vectors produced identical corrections"
},
"cvss_40_macro_qualification": {
"repository": "https://github.com/FIRSTdotorg/cvss-resources",
"commit": "48f85d84a036de9c610668f9496c12b5040a9ae3",
"vectors": {
"path": "vectorFiles/macro-vectors",
"sha256": "f653914506e697a94a18b690c051144b295626c534737fb79c589a61c1e0e8a3",
"length": 23490
},
"scores": {
"path": "vectorFiles/macro-scores",
"sha256": "b55926940d4fbb073a0d30a98d6983de93f4542209eee936a671713387f92213",
"length": 36677
},
"transformation": "paired the 270 vector and score records by exact vector identity, uppercased severity labels and encoded the result as compact JSON"
},
"files": [
{
"path": "v20-complete.json",
"sha256": "63400ecb25cc1b2f46981fdf39ec6614bbd7c095df8fe0f32cb4d838b20e5dc8",
"length": 840
},
{
"path": "v30-complete.json",
"sha256": "3c47d5574c4ef3f706c9c28093f0fb0bb96f0e0fa6f0aaa057f5c3c255241f1e",
"length": 451
},
{
"path": "v31-base.json",
"sha256": "279b7b3ad77170d7fc9662e0ff01980914f0256b06bc0a8c790ae2039b1117cc",
"length": 559
},
{
"path": "v31-complete.json",
"sha256": "bd48e4dfd50d045fe64bfb770c53ac14ad876b34fc30628e3c299aaf65ca0627",
"length": 451
},
{
"path": "v40-base.json",
"sha256": "459167f12107242e9c11a6bd16f6ca6aa54be41c06c1ca1dd9dcce066e95a2be",
"length": 898
},
{
"path": "v40-reference-base.json",
"sha256": "69ea049ece43b61e7d93d95ee8786cef945dfb12b9c9e8e301730a8d0004e538",
"length": 446772
},
{
"path": "v40-reference-complete.json.gz",
"sha256": "db7355c4074dd6e962e4f9a200e26a8c1026083ffc41eebd9ec768f96729957c",
"length": 791054
},
{
"path": "v40-rounding-corrections.json",
"sha256": "bf44b93801b29ab04755fba3bfc0356eb474f139cbef9fda014219419ef6ff3a",
"length": 23245
},
{
"path": "v40-macro.json",
"sha256": "d898f884d677238a72dbcbf298bae7ed73cbd383ffbf889ff24884aefdc79cf5",
"length": 35329
}
]
}