Bug 2158403
| Summary: | [RFE] To have the CVSS score-based filtering in the content-view filter | ||
|---|---|---|---|
| Product: | Red Hat Satellite | Reporter: | aurankar |
| Component: | Content Views | Assignee: | satellite6-bugs <satellite6-bugs> |
| Status: | CLOSED NOTABUG | QA Contact: | Satellite QE Team <sat-qe-bz-list> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 6.12.0 | CC: | ahumbe, dsinglet, jangerrit.kootstra, saydas |
| Target Milestone: | Unspecified | Keywords: | FutureFeature |
| Target Release: | Unused | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-05-31 12:10:33 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
aurankar
2023-01-05 10:36:02 UTC
To clarify a bit more about the request, We understand that There is no way we can filter\search for errata in Satellite UI based on the CVSS score of related CVEs. We can use the CVE ID but not anything else. It is probably because Satellite stores no data about CVEs and it redirects to Red Hat Portal whenever we click on any CVE name inside an ERRATA. However, The requirement proposed by the end user is to be able to add certain ERRATAs incrementally to an existing CV, which has CVEs with 9.9+ CVSS scores. I think we can get ERRATAs using their own severity definitions e.g. "severity = Critical", but the Critical ERRATAs could be having CVEs with CVSS score 8.8 or 8.5 as well (which are < 9.9 ). So either allows searching for ERRATAs using the CVSS score of associated CVEs or has some severity level available for errata i.e. 'Day zero' or any appropriate name for it, to search them based on having a CVSS score of 9.9+ ( minimum ). Alternative to creating such filter, you might also create a new severity level for both Security fixes and Bugs: e.g. zero day. For Bugs that might mean: we found a stability endangering isssue. for security issues: CVSS score 9.9+ or 9.8+, fix as soon as possible Is there any progress to be expected on this bugzilla? Any update? Thank you for your interest in Satellite 6. We have evaluated this request, and while we recognize that it is a valid request, we do not expect this to be implemented in the product in the foreseeable future. This is due to other priorities for the product, and not a reflection on the request itself. We are therefore closing this out as WONTFIX. If you have any concerns about this, please do not reopen. Instead, feel free to contact Red Hat Technical Support. Thank you. |