Migrate CVSS v2 to v3 #678
knqyf263
announced in
Announcements
Replies: 2 comments 3 replies
-
I'm using trivy version: 0.48.1, and what I believe is the latest version of the db:
But trivy is detecting severities for what I believe to be be using CVSS V2 instead of using CVSS V3. Here's an example: CVE-2022-25235: https://avd.aquasec.com/nvd/2022/cve-2022-25235/ Am I doing something wrong, or need to update something? Any help would be much appreciated. Thanks. |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
aquasecurity/trivy-db#72 migrates CVSS v2 to v3. It affects the Trivy DB just after merging the PR, so you will be also affected whether you update Trivy or not. The severity score displayed as a result will change and will probably be higher than before.
Scheduled date: October 19th, 2020
Ref. #655
Beta Was this translation helpful? Give feedback.
All reactions