Assessment Bug -- states modifying severity when they should not be

name: Assessment states modifying severity incorrectly
about: Multiple valid states for an assessment should not modify the severity but do

Is your feature request related to a problem? Please describe

In HopprCop 1.3.0, the assessment logic is downgrading the vulnerability severity to low for every state. The severity should not be downgraded for exploitable and in_triage as these two states are not disregarding the vulnerability.

Example output --

CVE-2019-10744 severity:'high' changed to 'low' based Assessment of Impact state : exploitable. Ref: npm:lodash-es:4.17.5 in analysis.assessment.yml
CVE-2023-46233 severity:'high' changed to 'low' based Assessment of Impact state : in_triage. Ref: npm:crypto-js:4.1.1 in analysis.assessment.yml
CVE-2021-3918 severity:'medium' changed to 'low' based Assessment of Impact state : exploitable. Ref: npm:json-schema:0.2.3 in analysis.assessment.yml
future generated an Assessment exception: '' is not a valid ImpactAnalysisJustification
CVE-2021-44906 severity:'medium' changed to 'low' based Assessment of Impact state : exploitable. Ref: npm:minimist:1.2.5 in analysis.assessment.yml
future generated an Assessment exception: '' is not a valid ImpactAnalysisJustification

Describe the solution you'd like

exploitable and in_triage should not be downgrading the severity to low. The severity should remain unchanged.

Describe alternatives you've considered