Skip to content

framework

Stakeholder-Specific Vulnerability Categorization

Vulnerability management prioritization framework that factors exploitation status, for which the KEV catalog is cited as the authoritative repository.

Known aliases

  • SSVC
  • SSVCv2
  • Stakeholder-Specific Vulnerability Categorization

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

vm2's prefix allowlist let one approved module load its unapproved siblings

vm2's maintainer patched a CVSS 9.5 flaw in 3.12.2 where the module allowlist matched an approved path as a bare prefix and cleared a neighboring package. With NodeVM's default host context, the unapproved sibling ran with full Node authority.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives
Insufficient
Confidence58