5 ways to fix misleading vulnerability severities with policy
Blog post from GitLab
Enterprise vulnerability reports often contain numerous findings ranked using the Common Vulnerability Scoring System (CVSS), which may not accurately reflect the actual risk within a specific environment. GitLab's vulnerability management policies now allow for automatic overrides of these default CVSS severity levels based on user-defined conditions, ensuring that vulnerability reports align with an organization's unique risk model. Severity override policies can adjust vulnerability severity levels on every default-branch pipeline through rules that define match criteria and an override action, such as increasing, decreasing, or setting severity levels. For instance, internal service vulnerabilities can be downgraded due to lower exposure risk, while injection vulnerabilities in production code might be upgraded to Critical. Additionally, these policies can normalize severity across different scanners, align severity with exploitation intelligence, and apply organization-wide risk models at the group level. All automated changes are logged for audit purposes, and manual overrides by authorized users always take precedence, preserving a comprehensive record of changes and ensuring accurate risk assessment.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.