> For the complete documentation index, see [llms.txt](https://docs.whitespots.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.whitespots.io/appsec-portal/features/security-metrics/cvss/cvss-rule.md).

# CVSS Rule

Set up a rule to **automatically** rate your products by following the steps below.

1. Navigate to the CVSS section and click on the **Create Rule** button
2. In the window that opens, select the **products** to which you want the rules to apply, or leave the default setting to include all your products.

<figure><img src="https://3069717380-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M81VrXQrfSaYjNIFOtt%2Fuploads%2FOpWgVIHiGrtmg0Q4nTsr%2Fimage.png?alt=media&amp;token=2950867f-ce04-4411-b235-5facb44c5937" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3069717380-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M81VrXQrfSaYjNIFOtt%2Fuploads%2FekbleqF4ufuw7ySOqku9%2Fcvss2-1.png?alt=media&amp;token=8be085e2-70b4-47e4-bf78-8ed5a96bcd06" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3069717380-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M81VrXQrfSaYjNIFOtt%2Fuploads%2F4XuB6yZqozmJbtiaYaSO%2Fcvss2(1).png?alt=media&amp;token=119019fb-251b-4cb1-b6fe-354e68378c7e" alt=""><figcaption></figcaption></figure>

3. Add the CVSS vector value

<figure><img src="https://3069717380-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M81VrXQrfSaYjNIFOtt%2Fuploads%2Fg0Ql9ZA7CXIoOjWnBlMF%2Fcvss3.png?alt=media&amp;token=1d260ff2-3508-47af-8daa-7208b74fed11" alt=""><figcaption></figcaption></figure>

3.1 Select the **version** of the standard and the **values of the metrics** in groups by clicking on the corresponding fields

{% hint style="success" %}
For more information on the metrics of the [3.1](https://www.first.org/cvss/v3.1/specification-document) and [4.0](https://www.first.org/cvss/v4.0/specification-document) versions of the standard, please refer to the [official documentation](https://www.first.org/cvss/)
{% endhint %}

<figure><img src="https://3069717380-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M81VrXQrfSaYjNIFOtt%2Fuploads%2FZsNm0CcD7WsTm0d1HGDe%2Fcvss4.png?alt=media&amp;token=eddef526-2416-46c7-890b-1d0980978f0e" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
In version 3.1, users can **adjust** **all baseline metrics** within the Environmental metrics group to their modified counterparts. This feature allows for the customization of metric values based on a component's specific role within an organization's infrastructure.
{% endhint %}

4. Select a parameter(s) and enter its value. This rule will be applied to the findings corresponding to these parameters and their values.

Available parameters:

* title
* description&#x20;
* file path&#x20;
* branch
* scanner&#x20;
* dependency&#x20;
* vulnerable url&#x20;
* import source

5. Click Submit

<figure><img src="https://3069717380-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M81VrXQrfSaYjNIFOtt%2Fuploads%2FSbDHFxPVTPUw4FlTfMG7%2Fcvss6.png?alt=media&amp;token=52afa89c-a4fd-495e-a6cd-5d68dd00e508" alt=""><figcaption></figcaption></figure>

5. The rule will be created and the CVSS value will be automatically assigned to the corresponding findings when processing the scan results.&#x20;

You can disable the application of these rules at any time by toggling the Active slider.

<figure><img src="https://3069717380-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M81VrXQrfSaYjNIFOtt%2Fuploads%2FW3UUqiSBQOjvH2ycBXtU%2Fcvss6(1).png?alt=media&amp;token=30558b63-7465-498e-afb7-2d81b6975bf4" alt=""><figcaption></figcaption></figure>
