
CVE Program
Threat Intelligence- Overview
- Setup
- Data & mappings
- Operations & API
- Changelog
The CVE Program connector brings the official CVE List into Brinqa. The CVE List is published by the CVE Program in the CVEProject/cvelistV5 repository in CVE JSON 5.x format. Each record is the authoritative CVE entry as written by the assigning CVE Numbering Authority (CNA), together with the data added by Authorized Data Publishers (ADPs), such as CISA's Vulnrichment program.
The connector synchronizes:
- CVE Records: one record per CVE, including rejected CVEs. Each record carries the CNA's description, CWE and CAPEC classifications, references, and CVSS v2.0, v3.x and v4.0 scores. It also carries CISA-ADP enrichment: SSVC decision points, Known Exploited Vulnerabilities (KEV) status, and CVSS and CWE backfill.
- Affected Products: one record per entry of a CVE's affected-products list, with the vendor, product, package, CPEs and affected version ranges. This covers the CNA's own list and ADP additions.
This complements NVD: it carries the CNA's own affected-version ranges and CISA Vulnrichment data, which NVD does not always carry, and it includes CVEs that NVD has not yet analyzed.
Data retrieved from CVE Program
| Connector Object | Required | Maps to Data Model |
|---|---|---|
| CVE Record | Yes | Cve Record |
| Affected Product | Yes | Affected Product |
Model relationships
For detailed steps on how to view the data retrieved from CVE Program in the Brinqa Platform, see How to view your data.
Connection settings
When setting up a data integration, select CVE Program from the Connector dropdown and provide the following:
| Setting | Required | Default | Description |
|---|---|---|---|
| API URL | Yes | https://api.github.com/repos/CVEProject/cvelistV5 | GitHub API URL of the CVE List repository (CVEProject/cvelistV5). The connector reads its releases to locate the daily baseline and delta files. |
| Full sync threshold (days) | No | 7 | When the last sync is older than this many days, the connector downloads the full CVE List baseline (about 600 MB) instead of applying daily delta files. Default is 7 |
| Maximum retries | No | 3 | Maximum number of times a failed request is retried before the sync fails. Default is 3 |
| Request timeout (secs) | No | 300 | The maximum seconds allotted before a request will time out. Maximum allowed value 1800. Default is 300 |
Authentication
No authentication is required. The CVE List is public and free to redistribute under the CVE Terms of Use.
The connector calls the public GitHub REST API once per sync to list the latest releases, and then downloads the release files from their public download URLs. Unauthenticated GitHub API requests are limited to 60 per hour per IP address; downloads do not count against that limit.
Request Headers
| Header | Value |
|---|---|
Accept | application/vnd.github+json |
X-GitHub-Api-Version | 2022-11-28 |
How to obtain CVE Program credentials
Obtain the required credentials (url) from your CVE Program administrator or the CVE Program admin console, then enter them in the connection settings above.
Attribute mappings
Expand the sections below to view the mappings between the source and the Brinqa data model attributes:
CVE Record
| Source Field Name | SDM Attribute |
|---|---|
| - | LAST_CAPTURED |
CISA-ADP KEV content.dateAdded | CISA_ADDED_DATE |
CISA-ADP KEV content.reference | CISA_KEV_REFERENCE |
CISA-ADP metrics[].cvssV3_1.baseScore | CISA_ADP_CVSS_V3_BASE_SCORE |
CISA-ADP metrics[].cvssV3_1.baseSeverity | CISA_ADP_CVSS_V3_SEVERITY |
CISA-ADP metrics[].cvssV3_1.vectorString | CISA_ADP_CVSS_V3_VECTOR |
CISA-ADP metrics[].other (type: kev) | CISA_EXPLOITED |
CISA-ADP metrics[].other (type: ssvc) content.options[].Exploitation | SSVC_EXPLOITATION |
CISA-ADP SSVC content.options[]."Technical Impact" | SSVC_TECHNICAL_IMPACT |
CISA-ADP SSVC content.options[].Automatable | SSVC_AUTOMATABLE |
CISA-ADP SSVC content.timestamp | SSVC_TIMESTAMP |
CISA-ADP SSVC content.version | SSVC_VERSION |
containers.*.affected[].cpes[], containers.cna.cpeApplicability[].nodes[].cpeMatch[].criteria | CPE_RECORDS |
containers.*.metrics[].other | SEVERITY_RATINGS |
containers.*.references[] tagged exploit | EXPLOITS |
containers.adp[].providerMetadata.shortName | ADP_PROVIDERS |
containers.cna.affected[].vendor, .product | AFFECTED |
containers.cna.configurations[].value | CONFIGURATIONS |
containers.cna.credits[] | CREDITS |
containers.cna.dateAssigned | DATE_ASSIGNED |
containers.cna.datePublic | DISCLOSED_DATE |
containers.cna.descriptions[].value | DESCRIPTION |
containers.cna.exploits[].value | EXPLOIT_DESCRIPTION |
containers.cna.impacts[].capecId | CAPEC_IDS |
containers.cna.metrics[], containers.adp[].metrics[] | SEVERITY |
containers.cna.metrics[].cvssV2_0.* | CVSS_V2_ACCESS_VECTOR, CVSS_V2_ACCESS_COMPLEXITY, CVSS_V2_AUTHENTICATION, CVSS_V2_CONFIDENTIALITY_IMPACT, CVSS_V2_INTEGRITY_IMPACT, CVSS_V2_AVAILABILITY_IMPACT, CVSS_V2_EXPLOITABILITY, CVSS_V2_REMEDIATION_LEVEL, CVSS_V2_REPORT_CONFIDENCE |
containers.cna.metrics[].cvssV2_0.baseScore | CVSS_V2_BASE_SCORE |
containers.cna.metrics[].cvssV2_0.temporalScore | CVSS_V2_TEMPORAL_SCORE |
containers.cna.metrics[].cvssV2_0.vectorString | CVSS_V2_VECTOR |
containers.cna.metrics[].cvssV3_1.* (or cvssV3_0) | CVSS_V3_ATTACK_VECTOR, CVSS_V3_ATTACK_COMPLEXITY, CVSS_V3_PRIVILEGES_REQUIRED, CVSS_V3_USER_INTERACTION, CVSS_V3_SCOPE, CVSS_V3_CONFIDENTIALITY_IMPACT, CVSS_V3_INTEGRITY_IMPACT, CVSS_V3_AVAILABILITY_IMPACT, CVSS_V3_EXPLOIT_CODE_MATURITY, CVSS_V3_REMEDIATION_LEVEL, CVSS_V3_REPORT_CONFIDENCE |
containers.cna.metrics[].cvssV3_1.baseScore (or cvssV3_0) | CVSS_V3_BASE_SCORE |
containers.cna.metrics[].cvssV3_1.baseSeverity (or cvssV3_0) | CVSS_V3_SEVERITY |
containers.cna.metrics[].cvssV3_1.temporalScore (or cvssV3_0) | CVSS_V3_TEMPORAL_SCORE |
containers.cna.metrics[].cvssV3_1.vectorString (or cvssV3_0) | CVSS_V3_VECTOR |
containers.cna.metrics[].cvssV4_0.* | CVSS_V4_ATTACK_VECTOR, CVSS_V4_ATTACK_COMPLEXITY, CVSS_V4_ATTACK_REQUIREMENTS, CVSS_V4_PRIVILEGES_REQUIRED, CVSS_V4_USER_INTERACTION, CVSS_V4_VULNERABLE_SYSTEM_CONFIDENTIALITY_IMPACT, CVSS_V4_VULNERABLE_SYSTEM_INTEGRITY_IMPACT, CVSS_V4_VULNERABLE_SYSTEM_AVAILABILITY_IMPACT, CVSS_V4_SUBSEQUENT_SYSTEM_CONFIDENTIALITY_IMPACT, CVSS_V4_SUBSEQUENT_SYSTEM_INTEGRITY_IMPACT, CVSS_V4_SUBSEQUENT_SYSTEM_AVAILABILITY_IMPACT, CVSS_V4_EXPLOIT_MATURITY, CVSS_V4_SAFETY, CVSS_V4_AUTOMATABLE, CVSS_V4_RECOVERY, CVSS_V4_VALUE_DENSITY, CVSS_V4_VULNERABILITY_RESPONSE_EFFORT, CVSS_V4_PROVIDER_URGENCY |
containers.cna.metrics[].cvssV4_0.baseScore | CVSS_V4_BASE_SCORE |
containers.cna.metrics[].cvssV4_0.baseSeverity | CVSS_V4_SEVERITY |
containers.cna.metrics[].cvssV4_0.environmentalScore | CVSS_V4_ENVIRONMENTAL_SCORE |
containers.cna.metrics[].cvssV4_0.threatScore | CVSS_V4_THREAT_SCORE |
containers.cna.metrics[].cvssV4_0.vectorString | CVSS_V4_VECTOR |
containers.cna.problemTypes[].descriptions[].cweId, containers.adp[].problemTypes[]... | CWE_IDS |
containers.cna.references[].url, containers.adp[].references[].url | REFERENCES |
containers.cna.rejectedReasons[].value | REJECTED_REASON |
containers.cna.replacedBy[] | REPLACED_BY |
containers.cna.solutions[].value | RECOMMENDATION |
containers.cna.source.advisory | ADVISORY_ID |
containers.cna.source.defect[] | DEFECT_IDS |
containers.cna.source.discovery | DISCOVERY |
containers.cna.tags[] | TAGS |
containers.cna.timeline[] | TIMELINE |
containers.cna.title | SUMMARY |
containers.cna.workarounds[].value | WORKAROUNDS |
cveMetadata.assignerOrgId | ASSIGNER_ORG_ID |
cveMetadata.assignerShortName | ASSIGNER |
cveMetadata.cveId | UID |
cveMetadata.cveId | NAME |
cveMetadata.datePublished | PUBLISHED_DATE |
cveMetadata.dateRejected | DATE_REJECTED |
cveMetadata.dateReserved | DATE_RESERVED |
cveMetadata.dateUpdated | SOURCE_LAST_MODIFIED |
cveMetadata.state | SOURCE_STATUS |
dataVersion | DATA_VERSION |
| same as CWE_IDS | WEAKNESSES |
Affected Product
| Source Field Name | SDM Attribute |
|---|---|
| - | LAST_CAPTURED |
affected[].collectionURL | COLLECTION_URL |
affected[].cpes[] | CPE_RECORDS |
affected[].defaultStatus | DEFAULT_STATUS |
affected[].modules[] | MODULES |
affected[].packageName | PACKAGE_NAME |
affected[].packageURL | PACKAGE_URL |
affected[].platforms[] | PLATFORMS |
affected[].product | PRODUCT |
affected[].programFiles[] | PROGRAM_FILES |
affected[].programRoutines[].name | PROGRAM_ROUTINES |
affected[].repo | REPO |
affected[].vendor | VENDOR |
affected[].vendor, affected[].product, cveMetadata.cveId | NAME |
affected[].versions[] | VERSION_RANGES |
affected[].versions[] with status: affected | AFFECTED_VERSION |
| CNA or ADP container | PROVIDER_ROLE |
cveMetadata.cveId | CVE_RECORDS |
cveMetadata.cveId, providerMetadata.shortName, affected[].vendor, affected[].product, entry position | UID |
providerMetadata.shortName | PROVIDER |
Operations & API
Expand each connector object to see its operation options, delta-sync behavior, and the API it uses. See connector operation options for how to apply operation options (keys and values are case-sensitive).
CVE Record
Operation options
This object does not support any operation options.
Delta sync
Supported. The connector performs an incremental (delta) sync via the since sync token, filtering on dateUpdated.
API
- Type: REST (GitHub Releases API) and file download
- The one-day overlap between syncs covers the usual delay (up to about an hour) between a CVE change and the next CVE List release. If CVE List releases stop being published for more than a day, run a full sync after publishing resumes by clearing the sync token.
- Rejected CVEs are emitted with
SOURCE_STATUSset toREJECTED, so records that were rejected after an earlier sync are updated. - A CVE file that cannot be parsed is skipped and logged as a warning; the rest of the sync continues.
Affected Product
Operation options
This object does not support any operation options.
Delta sync
Supported. The connector performs an incremental (delta) sync via the since sync token, filtering on dateUpdated.
API
- Type: REST (GitHub Releases API) and file download
- Version ranges are written in the direction of the CVE record:
lessThanbecomes<andlessThanOrEqualbecomes<=. A lower bound of0,*orn/ameans "from the first version" and is left out, e.g.v < 2.0.
Changelog
The CVE Program connector has undergone the following changes:
| Version | Description | Migration Steps |
|---|---|---|
| 3.0.0 | Overview The CVE Program connector integrates with the official CVE List published by the CVE Program to synchronize CVE records as written by the assigning CNA, enriched with CISA Vulnrichment data (SSVC, Known Exploited Vulnerabilities status, and CVSS and CWE backfill), and the products and version ranges each CVE affects. Category: Threat Intelligence Models | N/A |