ExploitCatalogVulnAssessmentRelationship
Summary
Provides an exploit assessment of a vulnerability.
Description
An ExploitCatalogVulnAssessmentRelationship describes if a vulnerability is listed in any exploit catalog such as the CISA Known Exploited Vulnerabilities Catalog (KEV) https://www.cisa.gov/known-exploited-vulnerabilities-catalog.
Constraints
- The relationship type must be set to hasAssessmentFor.
Syntax
{
"@type": "ExploitCatalogVulnAssessmentRelationship",
"@id": "urn:spdx.dev:exploit-catalog-1",
"relationshipType": "hasAssessmentFor",
"catalogType": "kev",
"locator": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"exploited": "true",
"from": "urn:spdx.dev:vuln-cve-2023-2136",
"to": ["urn:product-google-chrome-112.0.5615.136"],
"suppliedBy": ["urn:spdx.dev:agent-jane-doe"],
"publishedTime": "2021-03-09T11:04:53Z"
}
Metadata
https://spdx.org/rdf/3.0.0/terms/Security/ExploitCatalogVulnAssessmentRelationship
Name | ExploitCatalogVulnAssessmentRelationship |
Instantiability | Concrete |
SubclassOf | VulnAssessmentRelationship |
Properties
Property | Type | minCount | maxCount |
---|---|---|---|
catalogType | ExploitCatalogType | 1 | 1 |
exploited | xsd:boolean | 1 | 1 |
locator | xsd:anyURI | 1 | 1 |