{% extends "base.html" %} {% load humanize %} {% load widget_tweaks %} {% load static %} {% load show_cvss %} {% load url_filters %} {% block title %} VulnerableCode Vulnerability Details - {{ vulnerability.vulnerability_id }} {% endblock %} {% block content %}
{% include "vulnerability_search_box.html" %}
{% if vulnerability %}
Vulnerability details: {{ vulnerability.vulnerability_id }}
{% if severity_score_range %} {% endif %}
Vulnerability ID {{ vulnerability.vulnerability_id }}
Aliases {% for alias in aliases %} {% if alias.url %} {{ alias }} {% else %} {{ alias }} {% endif %}
{% endfor %}
Summary {{ vulnerability.summary }}
Severity score range {{ severity_score_range }}
Status {{ status }}
Exploitability {{ vulnerability.exploitability }}
Weighted Severity {{ vulnerability.weighted_severity }}
Risk {{ vulnerability.risk_score }}
Affected and Fixed Packages Package Details
Weaknesses ({{ weaknesses|length }})
{% for weakness in weaknesses %} {% empty %} {% endfor %}
CWE-{{ weakness.cwe_id }} {{ weakness.name }}
There are no known CWE.
{% for severity in severities %} {% empty %} {% endfor %}
System Score Found at
{{ severity.scoring_system }} {{ severity.value }} {{ severity.url }}
There are no known severity scores.
{% for ref in references %} {% if ref.reference_id %} {% else %} {% endif %} {% if ref.reference_type %} {% else %} {% endif %} {% empty %} {% endfor %}
Reference id Reference type URL
{{ ref.reference_id }}{{ ref.get_reference_type_display }}{{ ref.url }}
There are no known references.
{% for exploit in vulnerability.exploits.all %} {% if exploit.date_added %} {% endif %} {% if exploit.description %} {% endif %} {% if exploit.required_action %} {% endif %} {% if exploit.due_date %} {% endif %} {% if exploit.notes %} {% endif %} {% if exploit.known_ransomware_campaign_use is not None %} {% endif %} {% if exploit.source_date_published %} {% endif %} {% if exploit.exploit_type %} {% endif %} {% if exploit.platform %} {% endif %} {% if exploit.source_date_updated %} {% endif %} {% if exploit.source_url %} {% endif %}
Data source {{ exploit.data_source }}
Date added {{ exploit.date_added }}
Description {{ exploit.description }}
Required action {{ exploit.required_action }}
Due date {{ exploit.due_date }}
Note
{{ exploit.notes }}
Ransomware campaign use {{ exploit.known_ransomware_campaign_use|yesno:"Known,Unknown" }}
Source publication date {{ exploit.source_date_published }}
Exploit type {{ exploit.exploit_type }}
Platform {{ exploit.platform }}
Source update date {{ exploit.source_date_updated }}
Source URL {{ exploit.source_url }}
{% empty %} No exploits are available. {% endfor %}
{% for severity_vector in severity_vectors %} {% if severity_vector.vector.version == '2.0' %} Vector: {{ severity_vector.vector.vectorString }} Found at {{ severity_vector.origin }}
Exploitability (E) Access Vector (AV) Access Complexity (AC) Authentication (Au) Confidentiality Impact (C) Integrity Impact (I) Availability Impact (A)
{{ severity_vector.vector.exploitability|cvss_printer:"high,functional,unproven,proof_of_concept,not_defined" }} {{ severity_vector.vector.accessVector|cvss_printer:"local,adjacent_network,network" }} {{ severity_vector.vector.accessComplexity|cvss_printer:"high,medium,low" }} {{ severity_vector.vector.authentication|cvss_printer:"multiple,single,none" }} {{ severity_vector.vector.confidentialityImpact|cvss_printer:"none,partial,complete" }} {{ severity_vector.vector.integrityImpact|cvss_printer:"none,partial,complete" }} {{ severity_vector.vector.availabilityImpact|cvss_printer:"none,partial,complete" }}
{% elif severity_vector.vector.version == '3.1' or severity_vector.vector.version == '3.0'%} Vector: {{ severity_vector.vector.vectorString }} Found at {{ severity_vector.origin }}
Attack Vector (AV) Attack Complexity (AC) Privileges Required (PR) User Interaction (UI) Scope (S) Confidentiality Impact (C) Integrity Impact (I) Availability Impact (A)
{{ severity_vector.vector.attackVector|cvss_printer:"network,adjacent_network,local,physical"}} {{ severity_vector.vector.attackComplexity|cvss_printer:"low,high" }} {{ severity_vector.vector.privilegesRequired|cvss_printer:"none,low,high" }} {{ severity_vector.vector.userInteraction|cvss_printer:"none,required"}} {{ severity_vector.vector.scope|cvss_printer:"unchanged,changed" }} {{ severity_vector.vector.confidentialityImpact|cvss_printer:"high,low,none" }} {{ severity_vector.vector.integrityImpact|cvss_printer:"high,low,none" }} {{ severity_vector.vector.availabilityImpact|cvss_printer:"high,low,none" }}
{% elif severity_vector.vector.version == '4' %} Vector: {{ severity_vector.vector.vectorString }} Found at {{ severity_vector.origin }}
Attack Vector (AV) Attack Complexity (AC) Attack Requirements (AT) Privileges Required (PR) User Interaction (UI) Vulnerable System Impact Confidentiality (VC) Vulnerable System Impact Integrity (VI) Vulnerable System Impact Availability (VA) Subsequent System Impact Confidentiality (SC) Subsequent System Impact Integrity (SI) Subsequent System Impact Availability (SA)
{{ severity_vector.vector.attackVector|cvss_printer:"network,adjacent,local,physical"}} {{ severity_vector.vector.attackComplexity|cvss_printer:"low,high" }} {{ severity_vector.vector.attackRequirement|cvss_printer:"none,present" }} {{ severity_vector.vector.privilegesRequired|cvss_printer:"none,low,high" }} {{ severity_vector.vector.userInteraction|cvss_printer:"none,passive,active"}} {{ severity_vector.vector.vulnerableSystemImpactConfidentiality|cvss_printer:"high,low,none" }} {{ severity_vector.vector.vulnerableSystemImpactIntegrity|cvss_printer:"high,low,none" }} {{ severity_vector.vector.vulnerableSystemImpactAvailability|cvss_printer:"high,low,none" }} {{ severity_vector.vector.subsequentSystemImpactConfidentiality|cvss_printer:"high,low,none" }} {{ severity_vector.vector.subsequentSystemImpactIntegrity|cvss_printer:"high,low,none" }} {{ severity_vector.vector.subsequentSystemImpactAvailability|cvss_printer:"high,low,none" }}
{% elif severity_vector.vector.version == 'ssvc' %}
Vector: {{ severity_vector.vector.vectorString }} Found at {{ severity_vector.origin }}
{% endif %} {% empty %} There are no known vectors. {% endfor %}
{% if epss_data %}
Exploit Prediction Scoring System (EPSS)
{% if epss_data.published_at %} {% endif %}
Percentile {{ epss_data.percentile }}
EPSS Score {{ epss_data.score }}
Published At {{ epss_data.published_at }}
{% else %}

No EPSS data available for this vulnerability.

{% endif %}
{% for log in history %} {% empty %} {% endfor %}
Date Actor Action Source VulnerableCode Version
{{ log.get_iso_time }} {{ log.actor_name }} {{ log.get_action_type_label }} {{log.source_url }} {{ log.software_version }}
There are no relevant records.
{% endif %} {% endblock %}