1 point

I get why they’re doing it. But the truth is that there are still places using CVSS 2.0 to grade their vulnerabilities. The switch to CVSS 4.0 is going to take forever unless there’s some conversion logic from 3->4.

permalink
report
reply
1 point

That’s kind of legacy debt at some point. I understand why they still want to move towards evolving the standard

permalink
report
parent
reply

appsec

!appsec@infosec.pub

Create post

A community for all things related to application security.

Community stats

  • 1

    Monthly active users

  • 98

    Posts

  • 27

    Comments

Community moderators