CVE-2024-35255:
cvss:
- version: 3.1
score: 5.5
vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- version: 4
score: 6.8
vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
The version 4 cvss is not imported because the importer does not support version 4:
Given a sample Suse score https://ftp.suse.com/pub/projects/security/yaml/suse-cvss-scores.yaml:
The version 4 cvss is not imported because the importer does not support version 4:
vulnerablecode/vulnerabilities/importers/suse_scores.py
Lines 34 to 38 in ed17dbd
Additional questions:
Our VulnerableCode instance contains some weird values for this source:
https://public.vulnerablecode.io/vulnerabilities/VCID-p3vk-v2au-aaaa?search=CVE-2024-35255