+
Skip to content

Add CVSS metrics in search JSON output #2568

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Mar 28, 2025
Merged

Conversation

wagoodman
Copy link
Contributor

Today JSON output for a grype scan shows CVSS metrics for all CVSS vectors, this updates the DB search commands to also output the same metrics:

grype db search CVE-2021-3828 -o json --provider nvd  | jq '.[].vulnerability.severities'
[
  {
    "scheme": "CVSS",
    "value": {
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "version": "3.1",
      "metrics": {
        "baseScore": 7.5,
        "exploitabilityScore": 3.9,
        "impactScore": 3.6
      }
    },
    "source": "nvd@nist.gov",
    "rank": 1
  },
  {
    "scheme": "CVSS",
    "value": {
      "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
      "version": "2.0",
      "metrics": {
        "baseScore": 5,
        "exploitabilityScore": 10,
        "impactScore": 2.9
      }
    },
    "source": "nvd@nist.gov",
    "rank": 1
  },
  {
    "scheme": "CVSS",
    "value": {
      "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "version": "3.0",
      "metrics": {
        "baseScore": 7.5,
        "exploitabilityScore": 3.9,
        "impactScore": 3.6
      }
    },
    "source": "security@huntr.dev",
    "rank": 2
  }
]

Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
@wagoodman wagoodman added the enhancement New feature or request label Mar 28, 2025
@wagoodman wagoodman self-assigned this Mar 28, 2025
@wagoodman wagoodman added this to OSS Mar 28, 2025
@wagoodman wagoodman moved this to In Review in OSS Mar 28, 2025
@wagoodman wagoodman marked this pull request as ready for review March 28, 2025 18:26
@wagoodman wagoodman merged commit d9a2cd2 into main Mar 28, 2025
12 checks passed
@wagoodman wagoodman deleted the output-cvss-metrics-in-search branch March 28, 2025 18:56
@github-project-automation github-project-automation bot moved this from In Review to Done in OSS Mar 28, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Archived in project
Development

Successfully merging this pull request may close these issues.

2 participants
点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载