mondoohq/cnquery

CVSS v3.1 vector is identified as v2

Closed this issue · 0 comments

Describe the bug
The cvss parsing identifies "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" as CVSS v2.

The parsing expects the string to start like "/CVSS...".

To Reproduce
Steps to reproduce the behavior:

  1. Try to parse the above string.
  2. Note the wrong version

Expected behavior
The CVSS version should be 3.

Additional background

Is the above vector conformant to the official spec?