This Ruby gem helps you to process the vector of the Common Vulnerability Scoring System. Besides calculating the Base, Temporal and Environmental Score, you are able to extract the selected option.
Add this line to your application's Gemfile:
gem 'cvss-suite'
Since the naming of this gem is not following the naming convention you can also add the following line to automatically require the gem:
gem 'cvss-suite', require: 'cvss_suite'
And then execute:
$ bundle
Or install it yourself as:
$ gem install cvss-suite
If you are still using CvssSuite 3.x please refer to the specific branch for documentation and changelog.
If you are still using CvssSuite 2.x please refer to the specific branch for documentation and changelog.
If you are still using CvssSuite 1.x please refer to the specific branch for documentation and changelog.
require 'cvss_suite'
cvss4 = CvssSuite.new('CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N')
vector = cvss4.vector # 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
version = cvss4.version # 4.0
valid = cvss4.valid? # true
severity = cvss4.severity # 'Critical'
cvss31 = CvssSuite.new('CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H/E:H/RL:U/RC:U')
vector = cvss31.vector # 'CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H/E:H/RL:U/RC:U'
version = cvss31.version # 3.1
valid = cvss31.valid? # true
severity = cvss31.severity # 'Medium'
cvss3 = CvssSuite.new('CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L/CR:L/IR:M/AR:H/MAV:N/MAC:H/MPR:N/MUI:R/MS:U/MC:N/MI:L/MA:H')
vector = cvss3.vector # 'CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L/CR:L/IR:M/AR:H/MAV:N/MAC:H/MPR:N/MUI:R/MS:U/MC:N/MI:L/MA:H'
version = cvss3.version # 3.0
valid = cvss3.valid? # true
severity = cvss3.severity # 'High'
cvss = CvssSuite.new('AV:A/AC:M/Au:S/C:P/I:P/A:P/E:POC/RL:TF/RC:UC/CDP:L/TD:M/CR:M/IR:M/AR:M')
vector = cvss.vector # 'AV:A/AC:M/Au:S/C:P/I:P/A:P/E:POC/RL:TF/RC:UC/CDP:L/TD:M/CR:M/IR:M/AR:M'
version = cvss.version # 2
valid = cvss.valid? # true
severity = cvss.severity # 'Low'
# Scores
score = cvss4.overall_score # 9.3, cvss4 only has overall score
base_score = cvss.base_score # 4.9
temporal_score = cvss.temporal_score # 3.6
environmental_score = cvss.environmental_score # 3.2
overall_score = cvss.overall_score # 3.2
# Available options
access_vector = cvss.base.access_vector.name # 'Access Vector'
remediation_level = cvss.temporal.remediation_level.name # 'Remediation Level'
access_vector.values.each do |value|
value[:name] # 'Local', 'Adjacent Network', 'Network'
value[:abbreviation] # 'L', 'A', 'N'
value[:selected] # false, true, false
end
# Selected options
cvss.base.access_vector.selected_value[:name] # Adjacent Network
cvss.temporal.remediation_level.selected_value[:name] # Temporary Fix
# Exceptions
cvss = CvssSuite.new('random_string') # invalid vector
valid = cvss.valid? # false
version = cvss.version # will throw CvssSuite::Errors::InvalidVector: Vector is not valid!
cvss.base_score # will throw CvssSuite::Errors::InvalidVector: Vector is not valid!
cvss = CvssSuite.new(1337) # invalid vector
valid = cvss.valid? # false
version = cvss.version # will throw CvssSuite::Errors::InvalidVector: Vector is not valid!
cvss.base_score # will throw CvssSuite::Errors::InvalidVector: Vector is not valid!
CvssSuite.new() # will throw a ArgumentError
cvss = CvssSuite.new('AV:N/AC:P/C:P/AV:U/RL:OF/RC:C') # invalid vector, authentication is missing
version = cvss.version # 2
valid = cvss.valid? # false
cvss.base_score # will throw CvssSuite::Errors::InvalidVector: Vector is not valid!
There is a possibility of implementations generating different scores (+/- 0,1) due to small floating-point inaccuracies. This can happen due to differences in floating point arithmetic between different languages and hardware platforms.
Click here to see all changes.
Bug reports and pull requests are welcome on GitHub at https://github.com/0llirocks/cvss-suite. This project is intended to be a safe, welcoming space for collaboration.