Files
llm-wiki/raw/official-docs/vuln-severity-cvss-v31-spec-first-official.md
T

9.1 KiB
Raw Blame History

title, source_type, url, archive_url, vendor, related_branches, related_projects, tags, created
title source_type url archive_url vendor related_branches related_projects tags created
CVSS v3.1 Specification Document — FIRST.org (Official Standard) official-doc https://www.first.org/cvss/v3.1/specification-document FIRST (Forum of Incident Response and Security Teams)
feature-dependency-vulnerability-management-contract
feature-build-release-supply-chain-contract
official-doc
security
2026-06-15

CVSS v3.1 Specification Document — FIRST.org (Official Standard)

Layer: raw/ — 외부 자료(공식 문서 / 대기업 기술 블로그)의 원문 발췌·출처 기록. 검증된 요약은 /ingestwiki/concepts/source-summary-template 형식으로 별도 작성. 원본은 raw에 영구 보관.

Parent / 활용 branch (필수)

Branch 이 자료가 정당화하는 결정
raw/branch-notes/feature-dependency-vulnerability-management-contract 릴리즈 차단 심각도 기준 = CVSS v3.1 base score, High(≥7.0)/Critical(≥9.0) 차단. FIRST.org CVSS v3.1 명세가 권위 표준.
raw/branch-notes/feature-build-release-supply-chain-contract Decision D2 — "high/critical vulnerability는 기본 release-blocking"의 CVSS severity classification 표준 근거 (FIRST.org CVSS v3.1 §5 severity bands). Claims C1(등급 구간 경계값), C2(optional 선언), C3(Base Score intrinsic/worst-case 정의).

출처 / Source

  • 원본 URL: https://www.first.org/cvss/v3.1/specification-document
  • 아카이브 URL: (미등록)
  • 저자 / 조직: FIRST (Forum of Incident Response and Security Teams)
  • 발행일: CVSS v3.1 — 2019년 공개 (FIRST.org 명세 페이지)
  • 마지막 확인일: 2026-06-15

왜 저장했는지 / Why archived

CVSS v3.1 은 vulnerability 심각도를 정량화하는 산업 표준이며, FIRST.org 가 명세의 권위 있는 출처다. feature-dependency-vulnerability-management-contract 브랜치에서 릴리즈 차단 임계값(High ≥7.0 / Critical ≥9.0)을 정성적 등급 구간(Table 14)과 Base Score 책임 분리 원칙에 근거해 정당화하기 위해 보관한다.

핵심 인용 / Key quotes (verbatim, 5개)

[§5, Table 14] "Table 14: Qualitative severity rating scale"

Rating CVSS Score
None 0.0
Low 0.1 - 3.9
Medium 4.0 - 6.9
High 7.0 - 8.9
Critical 9.0 - 10.0

[§5] "The use of these qualitative severity ratings is optional, and there is no requirement to include them when publishing CVSS scores. They are intended to help organizations properly assess and prioritize their vulnerability management processes."

[§1 Introduction] "The Base Score reflects the severity of a vulnerability according to its intrinsic characteristics which are constant over time and assumes the reasonable worst case impact across different deployed environments."

[§1 Introduction] "Consumers of CVSS should supplement the Base Score with Temporal and Environmental Scores specific to their use of the vulnerable product to produce a severity more accurate for their organizational environment."

[§1 Introduction] "Consumers may use CVSS information as input to an organizational vulnerability management process that also considers factors that are not part of CVSS in order to rank the threats to their technology infrastructure and make informed remediation decisions."

Claims Extracted / 추출된 주장

이 자료가 직접 말하는 것만 claim 으로 분리한다. 내 프로젝트에 적용한 결론은 여기 쓰지 않는다.

Claim ID Claim (이 자료가 직접 말하는 것) Evidence quote Strength Applies to Does not prove
C1 CVSS v3.1 정성적 등급은 None(0.0) / Low(0.13.9) / Medium(4.06.9) / High(7.08.9) / Critical(9.010.0) 5단계이며, 각 구간의 경계값은 명세가 직접 정의한다. [§5, Table 14] "Table 14: Qualitative severity rating scale" (None 0.0 / Low 0.13.9 / Medium 4.06.9 / High 7.08.9 / Critical 9.010.0) official-standard CVSS v3.1 Base/Temporal/Environmental 점수 모두에 적용 가능 ("All scores can be mapped to the qualitative ratings defined in Table 14") 특정 점수가 실제로 특정 취약점에 할당된다는 것을 증명하지 않음. 채점자의 metric 값 선택에 따라 점수가 달라질 수 있음
C2 정성적 등급 사용은 optional이며, CVSS 점수 공개 시 이를 포함할 의무가 없다. 조직의 vulnerability management 프로세스 입력으로 활용하도록 의도된 것이다. [§5] "The use of these qualitative severity ratings is optional, and there is no requirement to include them when publishing CVSS scores. They are intended to help organizations properly assess and prioritize their vulnerability management processes." official-standard CVSS 점수를 공개하거나 정책에 활용하는 모든 조직 정성 등급이 없어도 CVSS 점수 공개가 규격 위반이 아님을 증명. 그러나 조직 내부 정책에서 등급을 강제할 수 없다는 뜻은 아님
C3 Base Score는 시간이 지나도 변하지 않는 취약점 고유 특성(intrinsic characteristics)에 따른 심각도를 반영하며, 다양한 배포 환경 전반의 합리적 최악 영향을 가정한다. [§1] "The Base Score reflects the severity of a vulnerability according to its intrinsic characteristics which are constant over time and assumes the reasonable worst case impact across different deployed environments." official-standard Base Score를 릴리즈 차단 임계값 기준으로 채택하는 경우 Base Score가 내 특정 환경에서의 실제 위험을 직접 나타내지는 않음. 환경 특화 위험은 Environmental Score로 별도 계산 필요
C4 CVSS 소비자(Consumers)는 자신의 환경에 더 정확한 심각도를 도출하기 위해 Base Score를 Temporal 및 Environmental Score로 보완해야 한다. [§1] "Consumers of CVSS should supplement the Base Score with Temporal and Environmental Scores specific to their use of the vulnerable product to produce a severity more accurate for their organizational environment." official-standard Base Score만으로 조직 내 위험을 평가하려는 경우 Base Score만 사용하는 것이 명세 위반이라는 뜻은 아님(권고 표현 "should"). Temporal/Environmental 적용이 선택적임을 의미
C5 소비자는 CVSS 정보를 organizational vulnerability management 프로세스의 입력으로 사용할 수 있으며, 기술 인프라 위협 순위 결정 및 정보에 입각한 remediaton 결정을 위해 CVSS 범위 밖의 요소도 함께 고려할 수 있다. [§1] "Consumers may use CVSS information as input to an organizational vulnerability management process that also considers factors that are not part of CVSS in order to rank the threats to their technology infrastructure and make informed remediation decisions." official-standard 조직 내 vulnerability management 정책 수립 CVSS만으로 모든 위험 우선순위를 결정해야 한다는 의미가 아님. CVSS 외 비즈니스 요소(고객 수, 금전 손실 등) 병행 고려를 명시적으로 허용함

Usage Boundaries / 적용 경계

  • 이 자료가 직접 증명하는 것:
    • C1: CVSS v3.1 정성 등급 5단계와 정확한 점수 구간 경계값 (None/Low/Medium/High/Critical)
    • C2: 정성 등급 사용이 optional이며, 조직 vulnerability management 입력으로 활용 의도
    • C3: Base Score가 intrinsic characteristics 기반으로, worst-case 가정 하에 산출됨
    • C4: CVSS 소비자는 Temporal/Environmental Score로 Base Score를 보완해야 함(should)
    • C5: CVSS를 조직 취약점 관리 프로세스 입력으로 사용하며, CVSS 범위 밖 요소 병행 고려 허용
  • 이 자료가 증명하지 않는 것:
    • 특정 취약점 라이브러리의 실제 CVSS 점수 (점수는 NVD 등 채점 기관이 별도 할당)
    • High ≥7.0 / Critical ≥9.0 임계값이 모든 조직에서 릴리즈 차단 기준으로 '최적'이라는 것 (명세는 구간을 정의할 뿐, 차단 임계값 선택은 조직 정책)
    • Temporal/Environmental Score 미사용이 명세 위반이라는 것
  • 내 프로젝트에 적용하려면 추가 확인이 필요한 것:
    • 실제 dependency scan 도구(예: Trivy, Grype, OWASP Dependency-Check)가 CVSS v3.1 Base Score를 사용하는지, v2/v4 혼용 여부
    • CI 파이프라인에서 High/Critical 임계값 설정 방법 (도구별 flag/config)

메모 / Notes

  • 명세는 Qualitative Severity Rating Scale을 §5에서 단독 섹션으로 독립적으로 정의함. "All scores can be mapped" — Base, Temporal, Environmental 모두 동일 등급표 적용.
  • §1 Introduction의 Base Score 설명 문장(C3)은 명세 도입부이므로 CVSS v3.1 전체에 걸쳐 가장 권위 있는 정의로 볼 수 있음.
  • C4의 "should"는 RFC 2119 의미가 명시되지 않았으나, 강한 권고로 해석하는 것이 문맥상 자연스러움 (미검증 해석).
  • 같은 주제 다른 official-doc / company-tech-blog: (미등록)
  • 이 자료를 인용한 wiki 요약: [[wiki/concepts/cvss-vulnerability-scoring]] (생성 시)