Hi Yan,
we had a longer discussion with the CVSS SIG facilitated by your implementation based on #2. As a result, the CVSS SIG removed the threatScore, threatSeverity, environmentalScore and environmentalSeverity from the JSON schema as they are not (clearly) defined in the spec. Also, they clarified that the baseScore (and baseSeverity) is actually the overallScore. (see oasis-tcs/csaf#1070)
Could you please update your implementation to remove the values from the JSON again?
Thank you for helping to clarify that!
Best wishes,
Thomas
Hi Yan,
we had a longer discussion with the CVSS SIG facilitated by your implementation based on #2. As a result, the CVSS SIG removed the
threatScore,threatSeverity,environmentalScoreandenvironmentalSeverityfrom the JSON schema as they are not (clearly) defined in the spec. Also, they clarified that thebaseScore(andbaseSeverity) is actually theoverallScore. (see oasis-tcs/csaf#1070)Could you please update your implementation to remove the values from the JSON again?
Thank you for helping to clarify that!
Best wishes,
Thomas