In a previous blog post, we highlighted the announcement of the Common Vulnerability Scoring System version 4.0 (CVSS v4.0) public comment period, which closed on September 30, 2023. In the time since, the CVSS Special Interest Group (SIG) has been hard at work addressing and responding to each comment, finalizing documentation and code and putting some final touches in place.
As a member of the CVSS SIG and an avid consumer of the CVSS standards, Red Hat is happy to highlight FIRST’s official release of the version 4.0 standard. As of November 1st, 2023, CVSS v4.0 is available for all to use and consume, and various companies (including Red Hat) are working to roll out official support of the v4.0 standard.
If CVSS v4.0 is of interest to you or your organization, we recommend reviewing FIRST’s CVSS v4.0 landing page, which highlights the primary differences between v3.1 and v4.0. Additional technical information can also be found in a FIRST authored presentation, which describes the changes and additions in more detail. With this new release, a Specification Document, User Guide and FAQ page have been created to help with the understanding and adoption of the new standard. Finally, FIRST provides a self-paced, no-cost CVSS training course that does not require a user account.
All of the CVSS v4.0 information linked in this blog post can also be found by visiting FIRST’s CVSS home page.
Any questions or feedback about the new standard can be submitted to cvss@first.org.
Additional resources:
Sobre el autor
Austin Kimbrell began working at Red Hat in 2021, but his interest in networking and security stems back to college, where he majored in Computer Science concentrating on Networking and Security. He has worked as a developer, evaluator and product security engineer since 2014 when he had his first co-op internship and graduated in 2015 from University of the Pacific.
Más como éste
Confidential clusters for Red Hat OpenShift: Developer Preview now available on Microsoft Azure with AMD SEV-SNP
Redefining security data: Red Hat’s new VEX experience heading to Red Hat Summit 2026
Collaboration In Product Security | Compiler
Keeping Track Of Vulnerabilities With CVEs | Compiler
Navegar por canal
Automatización
Las últimas novedades en la automatización de la TI para los equipos, la tecnología y los entornos
Inteligencia artificial
Descubra las actualizaciones en las plataformas que permiten a los clientes ejecutar cargas de trabajo de inteligecia artificial en cualquier lugar
Nube híbrida abierta
Vea como construimos un futuro flexible con la nube híbrida
Seguridad
Vea las últimas novedades sobre cómo reducimos los riesgos en entornos y tecnologías
Edge computing
Conozca las actualizaciones en las plataformas que simplifican las operaciones en el edge
Infraestructura
Vea las últimas novedades sobre la plataforma Linux empresarial líder en el mundo
Aplicaciones
Conozca nuestras soluciones para abordar los desafíos más complejos de las aplicaciones
Virtualización
El futuro de la virtualización empresarial para tus cargas de trabajo locales o en la nube