1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
|
package cvss
import (
// "encoding/json"
"regexp"
"strings"
)
// CVSS 2.0 vector.
type v2Vector []v2Metric
// Convert vector to string.
func (v v2Vector) String() string {
// convert to slice of metrics
metrics := []v2Metric(v)
// build vector
r := make([]string, len(metrics))
for i, m := range(metrics) {
r[i] = m.String()
}
// build and return string
return strings.Join(r, "/")
}
// Return CVSS version.
func (v2Vector) Version() Version {
return V20
}
// Return metrics in this vector.
func (v v2Vector) Metrics() []Metric {
// build result
r := make([]Metric, len(v))
for i, m := range(v) {
r[i] = m
}
// return result
return r
}
// Create CVSS 2.0 vector from string.
func newV2Vector(s string) (v2Vector, error) {
strs := strings.Split(s, "/")
r := make([]v2Metric, len(strs))
// walk metric strings
for i, ms := range(strs) {
// convert string to vector
m, err := getV2Metric(ms)
if err != nil {
return nil, err
}
// add to results
r[i] = m
}
// build and return vector
return v2Vector(r), nil
}
// // Unmarshal CVSS 2.0 vector from JSON string.
// func (me *v2Vector) UnmarshalJSON(b []byte) error {
// // decode string, check for error
// var s string
// if err := json.Unmarshal(b, &s); err != nil {
// return err
// }
//
// // parse vector, check for error
// r, err := newV2Vector(s)
// if err != nil {
// // return error
// return err
// }
//
// // save result, return success
// *me = r
// return nil
// }
var v2MetricRe = "(?:" + strings.Join([]string {
"(?:AV:[NAL])",
"(?:AC:[LMH])",
"(?:Au:[MSN])",
"(?:C:[NPC])",
"(?:I:[NPC])",
"(?:A:[NPC])",
"(?:E:(?:ND|U|POC|F|H))",
"(?:RL:(?:OF|TF|W|U|ND))",
"(?:RC:(?:UC|UR|C|ND))",
"(?:CDP:(?:N|L|LM|MH|H|ND))",
"(?:TD:(?:N|L|M|H|ND))",
"(?:CR:(?:L|M|H|ND))",
"(?:IR:(?:L|M|H|ND))",
}, "|") + ")"
var v2VecRe = regexp.MustCompile(
"\\A" + v2MetricRe + "(?:/" + v2MetricRe + ")*\\z",
)
// Is the given string a CVSS v2 vector string?
func isV2VectorString(s string) bool {
return len(s) > 0 && v2VecRe.MatchString(s)
}
|