Skip to content

Commit fff12d6

Browse files
authored
Merge pull request #1738 from aboutcode-org/nvd_cvss3.1
Allow CVSS3.1 Severities in NVD
2 parents 8f03085 + 5e7e85e commit fff12d6

File tree

1 file changed

+7
-1
lines changed

1 file changed

+7
-1
lines changed

vulnerabilities/pipelines/nvd_importer.py

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -210,8 +210,14 @@ def severities(self):
210210
base_metric_v3 = impact.get("baseMetricV3") or {}
211211
if base_metric_v3:
212212
cvss_v3 = get_item(base_metric_v3, "cvssV3")
213+
version = cvss_v3.get("version")
214+
system = None
215+
if version == "3.1":
216+
system = severity_systems.CVSSV31
217+
else:
218+
system = severity_systems.CVSSV3
213219
vs = VulnerabilitySeverity(
214-
system=severity_systems.CVSSV3,
220+
system=system,
215221
value=str(cvss_v3.get("baseScore") or ""),
216222
scoring_elements=str(cvss_v3.get("vectorString") or ""),
217223
)

0 commit comments

Comments
 (0)