Skip to content

Allow environmental scores to be set for in-scope assets #16

Description

@jobertabma

Setting expectations around rewards is important to avoid confusion down the disclosure process. By providing the environmental scores (correcting scores for Confidentiality, Integrity, and Availability) help correct the CVSS per asset. Some assets simply don't have access to any confidential information or can be offline for no reason without impact anything. This should be allowed to be reflected not to set the correct expectations, but also direct hackers to the interesting assets that they can hack.

This should be an optional field, as some attack surfaces are too big or unknown to correctly assess the environmental scores.

With the current format it might be slightly harder to add this field, but it could look something like this:

In-Scope: gratipay.com (CVSS:3.0/CR:L/IR:L/AR:L)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions