Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

5 ways to fix misleading vulnerability severities with policy

Blog post from GitLab

Post Details
Company
Date Published
Author
Grant Hickman
Word Count
1,625
Company Posts That Month
21
Language
English
Hacker News Points
-
Post removed?
No
Summary

Enterprise vulnerability reports often contain numerous findings ranked using the Common Vulnerability Scoring System (CVSS), which may not accurately reflect the actual risk within a specific environment. GitLab's vulnerability management policies now allow for automatic overrides of these default CVSS severity levels based on user-defined conditions, ensuring that vulnerability reports align with an organization's unique risk model. Severity override policies can adjust vulnerability severity levels on every default-branch pipeline through rules that define match criteria and an override action, such as increasing, decreasing, or setting severity levels. For instance, internal service vulnerabilities can be downgraded due to lower exposure risk, while injection vulnerabilities in production code might be upgraded to Critical. Additionally, these policies can normalize severity across different scanners, align severity with exploitation intelligence, and apply organization-wide risk models at the group level. All automated changes are logged for audit purposes, and manual overrides by authorized users always take precedence, preserving a comprehensive record of changes and ensuring accurate risk assessment.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.