-
Bug
-
Resolution: Done
-
Undefined
-
None
-
None
-
None
-
Quality / Stability / Reliability
-
False
-
-
False
-
-
-
Rox Sprint 4.8G - Global
When an image is viewed in Vulnerability Management -> Results -> Workload CVEs, if the image contains CVEs that are listed as "Unknown" severity the counts above the CVE table will not match those listed in the summary cards above.
This is because the summary cards are building count data from the ResourceCountByCVESeverity resolver, which includes CVE counts broken down by critical, important, moderate, and low severities - but not 'unknown'.
This can be seen in staging https://staging.demo.stackrox.com/main/vulnerabilities/user-workloads/images/sha256:52478f8cd6a142fd462f0a7614a7bb064e969a4c083648235d6943c786df8cc7?vulnerabilityState=OBSERVED&detailsTab=Vulnerabilities&page=8 (data may change over time).