Inscreva-se no feed

The Common Vulnerability Scoring System (CVSS) is well known in the world of product security, development and IT. “The Common Vulnerability Scoring System provides a way to capture the principal characteristics of a vulnerability and produce a numerical score reflecting its severity,” per FIRST’s definition.

In layman’s terms, CVSS is used to assign a common score to a discovered vulnerability to let people know, at a glance, how technically severe the vulnerability is and to provide vendors a starting point for assessing the risk of a vulnerability towards their product.

There are a number of scoring systems used across the industry, but CVSS is one of the most prominent and is used by Red Hat and many other organizations. Red Hat has long served as a contributor to the CVSS Special Interest Group (SIG) which is responsible for the creation, updating and support of the standard. The current version of the CVSS standard that is being used is version 3.1.

At FIRST.org’s 35th Annual FIRST Conference in early June 2023, it was announced that CVSS version 4.0 is ready for feedback from a wider audience. Major changes from v3.1 to v4.0 include the introduction of additional supplemental metrics, an increased focus on safety’s effect on a vulnerability, and increased clarity and granularity for many of the existing metrics and overall score. Please view FIRST’s announcement page for a complete list of the changes.

On behalf of the CVSS SIG, we invite all of our partners and associates to test out the new calculator, review the specification documents and submit your feedback! The SIG would greatly appreciate hearing from as many CVSS users as possible so the standard can best reflect the needs of the CVSS community.

Resources for the new standard, including a mock calculator and guidance documentation, can be found on FIRST’s official CVSS v4.0 Public Preview information page.

Additional resources


Sobre o autor

Austin Kimbrell began working at Red Hat in 2021, but his interest in networking and security stems back to college, where he majored in Computer Science concentrating on Networking and Security. He has worked as a developer, evaluator and product security engineer since 2014 when he had his first co-op internship and graduated in 2015 from University of the Pacific.

Read full bio
UI_Icon-Red_Hat-Close-A-Black-RGB

Navegue por canal

automation icon

Automação

Últimas novidades em automação de TI para empresas de tecnologia, equipes e ambientes

AI icon

Inteligência artificial

Descubra as atualizações nas plataformas que proporcionam aos clientes executar suas cargas de trabalho de IA em qualquer ambiente

open hybrid cloud icon

Nuvem híbrida aberta

Veja como construímos um futuro mais flexível com a nuvem híbrida

security icon

Segurança

Veja as últimas novidades sobre como reduzimos riscos em ambientes e tecnologias

edge icon

Edge computing

Saiba quais são as atualizações nas plataformas que simplificam as operações na borda

Infrastructure icon

Infraestrutura

Saiba o que há de mais recente na plataforma Linux empresarial líder mundial

application development icon

Aplicações

Conheça nossas soluções desenvolvidas para ajudar você a superar os desafios mais complexos de aplicações

Original series icon

Programas originais

Veja as histórias divertidas de criadores e líderes em tecnologia empresarial