Skip to content

EPSS Support #6878

@justin-lf

Description

@justin-lf

Display exploitable CVE information EPSS values in Defect Dojo. EPSS in a column so CVEs can be sorted by.

Solutions:
Preferred: Cross reference CVE with EPSS database https://www.first.org/epss/data_stats.html so that any CVE imported gets updated with EPSS.

Minimum: Parse this information from reports ingested for example Dependency Track now provides epss values in the FFE
DependencyTrack/dependency-track#1178

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions