Skip to content

Fixed severity assignment for Default Vulnerabilities added by APIs#110

Merged
summitt merged 1 commit intofactionsecurity:mainfrom
skit-cyber-security:main
Oct 27, 2025
Merged

Fixed severity assignment for Default Vulnerabilities added by APIs#110
summitt merged 1 commit intofactionsecurity:mainfrom
skit-cyber-security:main

Conversation

@skit-cyber-security
Copy link
Copy Markdown
Contributor

BUG: Severity for Default Vulnerabilities uploaded from APIs are ignored because are recalculated starting from the CVSS score even if it is not provided. This causes all vulnerabilities uploaded from APIs to be assigned an overall Recommended risk.

Solution: Recalculate severity based on CVSS only if no severity is provided from the API. Prompt to provide a severity or CVSS for Default Vulnerabilities without them.

BUG: Severity for Default Vulnerabilities uploaded from APIs are ignored because are recalculated starting from the CVSS score even if it is not provided. This causes all vulnerabilities uploaded from APIs to be assigned an overall Recommended risk.

Solution: Recalculate severity based on CVSS only if no severity is provided from the API. Prompt to provide a severity or CVSS for Default Vulnerabilities without them.
@summitt summitt merged commit 6c29e71 into factionsecurity:main Oct 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants