View the vulnerabilities of all your projects across your entire organization. Quickly find projects affected by major vulnerabilities, and incorporate the dashboard into existing scheduled reports. Note that vulnerabilities are not detected in real-time, results are computed daily.
Access your dashboard from the Vulnerabilities (CVEs) tab of your organization page, and use the search field to find specific CVEs across your entire organization.
Each column on the dashboard provides important information about the vulnerabilities present in your organization’s projects.
The severity of the vulnerability (“critical”, “high”, “medium”, “low”, and “unscored”) is derived from the National Vulnerability Database (NVD) Common Vulnerability Scoring System (CVSS 3.x). By default, vulnerabilities are listed in descending severity, from “critical” to “not scored”.
Items in the Name field show the vulnerability as listed in the NVD. The link provided will go to the vulnerability details page on the NIST website, including the Description, and information like the current severity base score and known affected software configurations.
Multiple projects may be listed as the same vulnerabilities may occur in different projects.
Click the link in this column to go to the Configuration tab of the affected projects.
This column may include more than one package, as the same vulnerability may affect different packages.
More information about CVEs and how to remediate risks can be found here.
You can Filter the dashboard to show certain levels of threats and only view public or private projects. When a filter is applied, it removes the filtered items completely from the results. Reset Filter will revert the dashboard to the default state of all fields being active.
Filtering your results can help save time reviewing vulnerabilities. For example, if remediation is only required for “critical” CVEs you can filter the dashboard results to show all and only “critical”, high-severity CVEs.
Using the Search field will simultaneously search through the packages and dependencies of all projects in your organization to find a specific CVE. The search matches against all columns (severity, name, description, projects affected, and packages affected). This can be useful if there is a credible threat or vulnerability in the news, you can quickly search for projects affected in order to assess the impact.
At this time we do not support advanced searches (such as the use of “-” to denote NOT, parentheses for exact matches, etc)
Click Clear to clear your search
Your CVE organization security dashboard can be downloaded as a .csv
file by clicking the Download Report button on the Vulnerabilities (CVEs) tab of your organization’s page on the Platform. The report contains fields for
The .csv
file containing your report can be easily imported into existing workflows, or shared with others who may not have access to the organization’s Platform account.