Hacker News new | ask | show | jobs
by rfd4sgmk8u 1636 days ago
The CVSS score cannot be trusted? How so? I don't see why any of the log4j CVE's 'cant be trusted'?
1 comments

The third CVE arbitrarily had a score of ~7.5 despite requiring a non-standard configuration and only enabling a denial of service attack. The preceding CVE with the same outcome only warranted a 3.5, until it was shown to also potentially allow an RCE. CVSS is honestly pretty open to interpretation, since it's not a particularly objective set of measures.
Fair enough, I agree with you there. CVSS(v2/v3) can be subjective and can change when new information comes to light.