
Product Announcements — pmonaghan (Veracode, Inc.) asked a question.
On April 1st, 2024, SCA support for version 2 of the Common Vulnerability Scoring System (CVSS) will reach its end of life (EOL). Why? There are several reasons:
- CVSS v2 is 16 years old.
- CVSS v3 is 8 years old.
- National Vulnerability Database (NVD) has stopped consistently publishing v2 scores for new CVEs.
- Customer demand for v2 support has dropped.
- Supporting one version will pave a faster road to unifying the SCA agent and SCA upload scanners.
We will be moving customers from v2 to v3 in batches (with plenty of advanced warning), but if you would like to move now, contact Veracode’s Technical Support team, and ask them to activate CVSS v3 for your account. For more details, please see the attached FAQs.
For customers who are already using CVSS v3, the SCA team has released a feature that will align the severities displayed in your Veracode results with the severities you see in the NVD. Since the underlying score for each vulnerability (CVE) will not change, the impact will be minimal:
- For CVEs with scores between 8.1 and 8.9, the severity will drop from Very High to High.
- For CVEs with scores between 6.1 and 6.9, the severity will drop from High to Medium.
- For all other ranges, the Veracode-proprietary method of converting scores to severities already matches the standard CVSS v3 method, so there will be no change.
We will be activating this feature for v3 customers in batches, but if you would like to activate it now, contact Veracode’s Technical Support team, and ask them to activate the NVD Severities feature for your account. For more details, please see the attached FAQs. Thank you.
.png)
we're starting to see adoption of CVSS 3.1, are there differences in the scoring between 3.0 and 3.1?
Veracode uses 3.1, but the reality is there is no difference in the base score between 3.0 and 3.1, and Veracode only uses the base score.