Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-5890

RHACS: Not possible to find vulnerability in Node CVE pane with CVE id after RHxA is published (vulnerability fixable)

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • rhacs-4.4.0
    • RHACS, ui/ux
    • None
    • Future Sustainability
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None

      Business Problem:

      In Vulnerability Management (v1) -> Dashboard -> Node CVE pane, Until Red Hat provides an advisory for a particular CVE is possible using ACS UI to search a particular CVE using CVE Id. Vulnerability is known as not fixable. Whenever Red Hat provides an advisory to fix a vulnerability, this vulnerability is known as fixable and appears with RHSA Id but not with CVE Id. It is not possible to use the search field to find the CVE anymore.
       

      Use Cases:

      When working with Internal central teams CVE Id is the most common criteria. Since it is not possible to track vulnerabilities with this Id when is it fixable in Node CVE pane it introduces misunderstanding between our teams and possibly security issues due to lack of tracking on fixable CVE
       

      Key Functionality:

      Be able to track vulnerabilities in Node CVE pane using CVE Id as well and not only RHSA Id when vulnerability is known as fixable.
       

      Benefits:

      As a user or security auditor I track vulnerability with CVE Id (CVE-2024-xxx). I want to be able to track any CVE using the CVE Id since it is widely used a primary key to track vulnerabilities and preferred way to connect with Corporate Security Teams in almost all companies.

      Implementation Suggestions (optional):

      • Integration: Keep booth CVE Id and RHSA Id in the same table in Node CVE pane to be able to track booth.
      • Dependencies: None

      Timeline:

      Standard priority

       
       

       

        1. ACS-CVEvsRHSA.png
          1.01 MB
          Franck Grosjean
        2. Screenshot 2024-08-16 at 10.33.37 AM.png
          283 kB
          Shubha Badve
        3. Compliance_v2-CVE_replaced_with_RHSx-1.png
          319 kB
          Franck Grosjean
        4. Compliance_v2-CVE_replaced_with_RHSx-2.png
          373 kB
          Franck Grosjean

              sbadve@redhat.com Shubha Badve
              rh-support-fgrosjea Franck Grosjean
              None
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                None
                None