This issue was moved to a discussion.
You can continue the conversation there. Go to discussion →
cross check with CISA known exploited vulnerabilities catalog #2558
Labels
kind/feature
Categorizes issue or PR as related to a new feature.
lifecycle/stale
Denotes an issue or PR has remained open with no activity and will be auto-closed.
Hello
CISA agency maintains catalog of vulnerabilities that are known to be confirmed exploited https://www.cisa.gov/known-exploited-vulnerabilities-catalog and constantly updates it. It may look like majority is for desktop software and alike, but there are some vulnerabilities for software/libraries often found in containers.
Suggestion is to include this information in the vulnerability report, so reader can prioritize remediation. Perhaps it can be additional field, e.g. known_exploited=true/false.
Thank you.
The text was updated successfully, but these errors were encountered: