Skip to content

Severity Scoring and Informational results? #1381

Answered by jfagoagas
JArmandoG asked this question in Q&A
Discussion options

You must be logged in to vote

HI @JArmandoG, I'm going to answer your questions here below.

Hi, my question is about 2 markers of Prowler's results: CHECK_SEVERITY and CHECK_RESULT

What's the rationale for scoring (Critical, high, medium, etc.), or what is this based on?

We use a combination of the CVSS 3.0 (https://www.first.org/cvss/calculator/3.0) and the context of the check inside AWS to set the severity.

Also, why do I have results that are "INFO", but Critical/High, instead of "FAIL"?

This is because the check has three different status: INFO, PASS and FAIL. The INFO ones are used to show errors/information in the case Prowler cannot determine if the check is a PASS or a FAIL. For that reason, e.g. if you d…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jfagoagas
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants