Vulnerabilities · GraphQL enum

CVSSV3Scope enum

CVSSV3Scope describes whether a successful attack can impact resources beyond the vulnerable component in CVSS v3.x. NOT_DEFINED is valid only for modified (environmental) metric fields.

Values

Enum Value Description

UNCHANGED

Exploitation can only affect resources managed by the same authority as the vulnerable component.

CHANGED

Exploitation can affect resources beyond the authorization scope of the vulnerable component.

NOT_DEFINED

Assigning this value indicates insufficient information or the metric does not apply. Valid only for Modified Scope in environmental scoring.

Used by

  • CVSSMetricV30 type: Type CVSSMetricV30 contains detailed CVSS version 3.0 scoring attributes
  • CVSSMetricV31 type: Type CVSSMetricV31 contains detailed CVSS version 3.1 scoring attributes

Example

Example

"UNCHANGED"