Get the latest tech news
Curl Project and Go Security Teams Reject CVSS as Broken
cURL and Go security teams are publicly rejecting CVSS as flawed for assessing vulnerabilities and are calling for more accurate, context-aware approa...
While CVSS is designed to assign a severity score to vulnerabilities, its one-size-fits-all approach often produces misleading results, particularly for projects like cURL, which operates across diverse environments and billions of installations. “But when you’re unpaid, and 9/10 of the emails are about trivial vulns in method calls from dependencies that you’ve proven none of your code paths touch, and where patching would require a breaking change that means you are now fixing compatibility in ANOTHER open source project… well, it can get frustrating,” he said. Security teams that depend on accurate and timely data are often left grappling with outdated or incorrect scores, compounding the challenges of managing vulnerabilities effectively.
Or read this on Hacker News