Episode 201 - We broke CVSSv3, now how do we fix it? episode artwork

EPISODE · Jun 15, 2020 · 31 MIN

Episode 201 - We broke CVSSv3, now how do we fix it?

from Open Source Security

Josh and Kurt talk about CVSSv3 and how it's broken. We started with a blog post to explain why the NVD CVSS scores are so wrong, and we ended up researching CVSSv3 and found out it's far more broken than any of us expected in ways we didn't expect. NVD isn't broken, CVSSv3 is. How did we get here? Are there any options that work today? Where should we go next? Show Notes Josh's blog post NVD Red Hat security data Josh's CVE data project Microsoft security ratings scale

Episode metadata supplied by the publisher feed · Published Jun 15, 2020

Embed this episode

Ready to play

Episode 201 - We broke CVSSv3, now how do we fix it?

0:00 31:20

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Open Source Security?

This episode is 31 minutes long.

When was this Open Source Security episode published?

This episode was published on June 15, 2020.

Can I download this Open Source Security episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!