In a previous blog post, we highlighted the announcement of the Common Vulnerability Scoring System version 4.0 (CVSS v4.0) public comment period, which closed on September 30, 2023. In the time since, the CVSS Special Interest Group (SIG) has been hard at work addressing and responding to each comment, finalizing documentation and code and putting some final touches in place.

As a member of the CVSS SIG and an avid consumer of the CVSS standards, Red Hat is happy to highlight FIRST’s official release of the version 4.0 standard. As of November 1st, 2023, CVSS v4.0 is available for all to use and consume, and various companies (including Red Hat) are working to roll out official support of the v4.0 standard.

If CVSS v4.0 is of interest to you or your organization, we recommend reviewing FIRST’s CVSS v4.0 landing page, which highlights the primary differences between v3.1 and v4.0. Additional technical information can also be found in a FIRST authored presentation, which describes the changes and additions in more detail. With this new release, a Specification DocumentUser Guide and FAQ page have been created to help with the understanding and adoption of the new standard. Finally, FIRST provides a self-paced, no-cost CVSS training course that does not require a user account.

All of the CVSS v4.0 information linked in this blog post can also be found by visiting FIRST’s CVSS home page.

Any questions or feedback about the new standard can be submitted to cvss@first.org.

Additional resources:


关于作者

Austin Kimbrell began working at Red Hat in 2021, but his interest in networking and security stems back to college, where he majored in Computer Science concentrating on Networking and Security. He has worked as a developer, evaluator and product security engineer since 2014 when he had his first co-op internship and graduated in 2015 from University of the Pacific.

UI_Icon-Red_Hat-Close-A-Black-RGB

按频道浏览

automation icon

自动化

有关技术、团队和环境 IT 自动化的最新信息

AI icon

人工智能

平台更新使客户可以在任何地方运行人工智能工作负载

open hybrid cloud icon

开放混合云

了解我们如何利用混合云构建更灵活的未来

security icon

安全防护

有关我们如何跨环境和技术减少风险的最新信息

edge icon

边缘计算

简化边缘运维的平台更新

Infrastructure icon

基础架构

全球领先企业 Linux 平台的最新动态

application development icon

应用领域

我们针对最严峻的应用挑战的解决方案

Virtualization icon

虚拟化

适用于您的本地或跨云工作负载的企业虚拟化的未来