Company
Date Published
Author
Ryan Black
Word count
440
Language
English
Hacker News points
None

Summary

This week we have some exciting news related to our latest Vulnerability Rating Taxonomy (VRT) release! Our VRT is a dynamic resource outlining Bugcrowd's baseline priority rating for the vulnerabilities most often seen within the vulnerability assessment space. We've decided to partner with the security community at large to help provide a more diverse perspective and keep the VRT current and reflective of market needs by releasing it as an open source tool through GitHub. This will empower the community to take part in a full dialogue with our team and influence the way we shape and expand our taxonomy to address vulnerabilities beyond web applications. To submit a suggested change, one can go to github.com/bugcrowd/vulnerability-rating-taxonomy and provide detailed information around their suggestion, which will be valuable in shaping the VRT. Our latest version, VRT 1.1, introduces substantial revisions including additions to server security misconfigurations, XSS, and CSRF, some priority changes, and a few minor subtractions.