With today, the TYPO3 Security Teams has published a CVSS rating in a pre-announcement.
We have learned that our current severity ratings (low, medium, high, critical) in security bulletins are not that useful. That's why we searched for a solution to provide detailed information on a bulletin.
CVSS is an open framework for communicating the characteristics and impacts of vulnerabilities in Information Technology. It allows vulnerability bulletin analysts to understand and proper communicate disclosed vulnerabilities. In addition, it allows customers to prioritize risks.
Several vendors are already using CVSS. This enables you to compare vulnerabilities of applications from different scopes.
An extensive guide on CVSS is available online and in form of a PDF. We hereby encourage TYPO3 users, agencies and webhosting companies to get familiar with CVSS.
The CVSS v2.0 data of the upcoming security bulletin TYPO3-SA-2010-008 is following:
Base AV:N/AC:H/Au:N/C:C/I:C/A:C | Temporal E:F/RL:OF/RC:C
You could either use above mentioned guide to understand the scoring or feed a calculator with this data (DE, FR, ES, JP).
From today, the TYPO3 Security Team intends to publish CVSS data with every security bulletin on TYPO3 Core vulnerabilities.
We would like to hear your opinion on this new "feature"!
I very much welcome the addition of the more detailed data though! Maybe the low/medium/high rating can be based on the overall score the calculator puts out. In addition the CVSS string should always be linked to that calculator as I think it's a great tool to help to easily understand the somewhat cryptic string (and what it is at all!) for many more people.