npm.io
1.0.13 • Published 1 month ago

ae-cvss-calculator

Licence
Apache-2.0
Version
1.0.13
Deps
0
Size
307 kB
Vulns
0
Weekly
0
Stars
19

{metæffekt} CVSS Calculator

Weekly NPM downloads License Apache-2

The {metæffekt} CVSS Calculator supports all versions of the CVSS standard by FIRST to model CVSS vectors and calculate their scores. It consists of the following components:

TypeScript Library UI
Supports CVSS versions 2.0, 3.0, 3.1 and 4.0. Available on NPM as ae-cvss-calculator and installable via:
npm install ae-cvss-calculator

The calculator is available on our webpage for you to try out and link from your applications. The source code can be found in the site directory.

Installation

This project implements the following versions of the CVSS standard by FIRST:

Available on NPM as ae-cvss-calculator and installable via:

npm install ae-cvss-calculator

Usage

The library exports classes for CVSS versions 2.0 (Cvss2), 3.0 (Cvss3P0), 3.1 (Cvss3P1), and 4.0 (Cvss4P0), along with utility functions for parsing.

Dependency Graph of all Classes and Interfaces in the CVSS Calculator Library, see on GitHub if image is not rendering: https://github.com/org-metaeffekt/metaeffekt-universal-cvss-calculator/blob/master/ae-cvss-calculator/dependency-graph.png

Basic Usage (Specific Version)

If you know the specific CVSS version of your vector, you can instantiate the corresponding class directly.

// Initialize with a vector string
const cvss = new Cvss3P1('CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L');

// Calculate scores
const scores = cvss.calculateScores();
console.log(`Base Score: ${scores.base}`);
console.log(`Vector: ${scores.vector}`);

// Normalize scores to 0-10 scale (useful for visualization)
const normalized = cvss.calculateScores(true);
console.log(`Exploitability: ${normalized.exploitability}`);

Depending on the vector version, different scores are exposed via the returned object.

Generic Vector Parsing

Use fromVector to automatically detect the CVSS version and parse the string into the appropriate object instance.

const vectorString = 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L';
const cvss = fromVector(vectorString);

if (cvss) {
  console.log(`Detected: ${cvss.getVectorName()}`); // CVSS:3.1
  console.log(`Score: ${cvss.calculateScores().overall}`);
} else {
  console.error('Invalid or unsupported CVSS vector');
}
Modifying Components

You can modify vector components programmatically using applyComponentString.

const cvss = new Cvss4P0('CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N');

cvss.applyComponentString('AV', 'P');
cvss.applyComponent(Cvss4P0Components.AC, Cvss4P0Components.AC_VALUES.H);

Build

git clone https://github.com/org-metaeffekt/metaeffekt-universal-cvss-calculator
cd metaeffekt-universal-cvss-calculator/ae-cvss-calculator
npm install
npm run build

The minified ae-cvss-calculator.js can be found in the dist directory.

Otherwise, you can also build the packaged version by running npm pack.

To publish a new version:

  1. Preparation
    • Make sure that you pushed all the code related to the release, including the version bump to git, as npm will fetch that state for the release.
    • Increment the version in the package.json file.
    • Run npm install to sync the package-lock.json file.
  2. Publish Package
    • Run npm login and follow their authentication flow.
    • Optionally run the ./publish-package.sh script on the top level of the repository to perform a dry run first, inspecting the package contents on the command line from the logs.
    • Optionally try manually installing the package into a test project via npm i /path/to/metaeffekt-universal-cvss-calculator/ae-cvss-calculator/ae-cvss-calculator-x.x.x.tgz.
    • Finally, run ./publish-package.sh publish to publish the package.

Keywords