피드 구독

The Common Vulnerability Scoring System (CVSS) is well known in the world of product security, development and IT. “The Common Vulnerability Scoring System provides a way to capture the principal characteristics of a vulnerability and produce a numerical score reflecting its severity,” per FIRST’s definition.

In layman’s terms, CVSS is used to assign a common score to a discovered vulnerability to let people know, at a glance, how technically severe the vulnerability is and to provide vendors a starting point for assessing the risk of a vulnerability towards their product.

There are a number of scoring systems used across the industry, but CVSS is one of the most prominent and is used by Red Hat and many other organizations. Red Hat has long served as a contributor to the CVSS Special Interest Group (SIG) which is responsible for the creation, updating and support of the standard. The current version of the CVSS standard that is being used is version 3.1.

At FIRST.org’s 35th Annual FIRST Conference in early June 2023, it was announced that CVSS version 4.0 is ready for feedback from a wider audience. Major changes from v3.1 to v4.0 include the introduction of additional supplemental metrics, an increased focus on safety’s effect on a vulnerability, and increased clarity and granularity for many of the existing metrics and overall score. Please view FIRST’s announcement page for a complete list of the changes.

On behalf of the CVSS SIG, we invite all of our partners and associates to test out the new calculator, review the specification documents and submit your feedback! The SIG would greatly appreciate hearing from as many CVSS users as possible so the standard can best reflect the needs of the CVSS community.

Resources for the new standard, including a mock calculator and guidance documentation, can be found on FIRST’s official CVSS v4.0 Public Preview information page.

Additional resources


저자 소개

Austin Kimbrell began working at Red Hat in 2021, but his interest in networking and security stems back to college, where he majored in Computer Science concentrating on Networking and Security. He has worked as a developer, evaluator and product security engineer since 2014 when he had his first co-op internship and graduated in 2015 from University of the Pacific.

Read full bio
UI_Icon-Red_Hat-Close-A-Black-RGB

채널별 검색

automation icon

오토메이션

기술, 팀, 인프라를 위한 IT 자동화 최신 동향

AI icon

인공지능

고객이 어디서나 AI 워크로드를 실행할 수 있도록 지원하는 플랫폼 업데이트

open hybrid cloud icon

오픈 하이브리드 클라우드

하이브리드 클라우드로 더욱 유연한 미래를 구축하는 방법을 알아보세요

security icon

보안

환경과 기술 전반에 걸쳐 리스크를 감소하는 방법에 대한 최신 정보

edge icon

엣지 컴퓨팅

엣지에서의 운영을 단순화하는 플랫폼 업데이트

Infrastructure icon

인프라

세계적으로 인정받은 기업용 Linux 플랫폼에 대한 최신 정보

application development icon

애플리케이션

복잡한 애플리케이션에 대한 솔루션 더 보기

Original series icon

오리지널 쇼

엔터프라이즈 기술 분야의 제작자와 리더가 전하는 흥미로운 스토리