dependency-track icon indicating copy to clipboard operation
dependency-track copied to clipboard

Cvss4 support in Dependency Track

Open itmanju opened this issue 9 months ago • 7 comments

Current Behavior

currently we are not able to see Cvss4 scoring in Dependency Track

Image

Proposed Behavior

As NVD supports CVSS4 scoring system for vulnerabilities it should also be shown in Dependency Track

Checklist

itmanju avatar Mar 03 '25 08:03 itmanju

We've been waiting on https://github.com/stevespringett/cvss-calculator/issues/78 as a precondition, but I think we might just switch to https://github.com/org-metaeffekt/metaeffekt-core instead.

nscuro avatar Mar 04 '25 11:03 nscuro

Switching to that is currently soft-blocked by https://github.com/org-metaeffekt/metaeffekt-core/issues/242 - there are workarounds possible, but they are pretty ugly.

stohrendorf avatar Apr 28 '25 15:04 stohrendorf

This is critical as many CVEs with CRITICAL , HIGH SEVERITY falls under this bucket

prabhushan avatar May 09 '25 18:05 prabhushan

Are there any updates on this issue? I noticed a vulnerability with Severity Unassigned, but it is actually a critical vulnerability.

Image

https://nvd.nist.gov/vuln/detail/CVE-2025-7783

I assume it is Unassigned because it does not have CVSS 3.x.

Image

It only has CVSS 4.0.

Image

d-afanasiev avatar Jul 25 '25 15:07 d-afanasiev

Technically, DT can now handle 4.0, but it's not used anywhere yet.

stohrendorf avatar Jul 25 '25 16:07 stohrendorf

Any updates on this? We're looking to start moving over to CVSS 4.0 and Dependency Track can't be part of that move until that gets implemented.

acaivano-vmt avatar Oct 14 '25 20:10 acaivano-vmt

I have created pull request #5456 with an initial implementation of CVSSv4 support. For now my work is focused on the server side, though I plan to work on the frontend next. If you're tracking this issue, I would love to hear your feedback.

tobiasgies avatar Oct 28 '25 19:10 tobiasgies