POST
/v1/vulnerabilityUpdate a vulnerability
Updates an existing vulnerability record, including its identifiers, affected components, and scoring data. Supply uuid to identify the record and the required friendlyVulnId, source, and vulnId; you also need VULNERABILITY_MANAGEMENT or VULNERABILITY_MANAGEMENT_UPDATE permission.
- IdempotentThe SDK sends
Idempotency-Key, so a retried request is only applied once.
Vulnerability data to update. Include friendlyVulnId, source, uuid, and vulnId.
affectedActiveProjectCountintegeroptional
The number of active projects affected by the vulnerability.
affectedComponentsarray<object>optional
Component identities and version ranges affected by the vulnerability, with optional version attribution details.
affectedInactiveProjectCountintegeroptional
The number of inactive projects affected by the vulnerability.
affectedProjectCountintegeroptional
The total number of projects affected by the vulnerability.
aliasesarray<object>optional
Alternative vulnerability identifiers, including CVE, GHSA, OSV, Snyk, and other source identifiers.
componentsarray<object>optional
Component records associated with the vulnerability, including classifier, name, project, and UUID. The component `classifier` is constrained to the supported classifier values; hashes such as `blake2b_256`, `blake2b_384`, and `blake2b_512` must contain 64, 96, and 128 lowercase hexadecimal characters respectively.
createdstringoptional
The vulnerability creation timestamp in date-time format.
creditsstringoptional
Credit or attribution text for the vulnerability.
cvssV2BaseScorenumberoptional
The CVSS v2 base score.
cvssV2ExploitabilitySubScorenumberoptional
The CVSS v2 exploitability subscore.
cvssV2ImpactSubScorenumberoptional
The CVSS v2 impact subscore.
cvssV2Vectorstringoptional
The CVSS v2 vector string.
cvssV3BaseScorenumberoptional
The CVSS v3 base score.
cvssV3ExploitabilitySubScorenumberoptional
The CVSS v3 exploitability subscore.
cvssV3ImpactSubScorenumberoptional
The CVSS v3 impact subscore.
cvssV3Vectorstringoptional
cvssV4Scorenumberoptional
cvssV4Vectorstringoptional
cwesarray<object>optional
descriptionstringoptional
detailstringoptional
epssobjectoptional
epssPercentilenumberoptional
epssScorenumberoptional
friendlyVulnIdstringrequired
The human-readable identifier for the vulnerability.
isKevbooleanoptional
owaspRRBusinessImpactScorenumberoptional
owaspRRLikelihoodScorenumberoptional
owaspRRTechnicalImpactScorenumberoptional
owaspRRVectorstringoptional
patchedVersionsstringoptional
publishedstringoptional
recommendationstringoptional
referencesstringoptional
rejectedstringoptional
serviceComponentsarray<object>optional
severitystringoptional
sourcestringrequired
The source that supplies the vulnerability record.
subTitlestringoptional
tagsarray<object>optional
titlestringoptional
updatedstringoptional
uuidstringrequired
The vulnerability record's UUID.
vulnIdstringrequired
The vulnerability identifier assigned by its source.
vulnerableVersionsstringoptional
200Returns the updated vulnerability object, including its identifiers, affected projects and components, aliases, and scoring data.
affectedActiveProjectCountintegeroptional
affectedComponentsarray<object>optional
affectedInactiveProjectCountintegeroptional
affectedProjectCountintegeroptional
aliasesarray<object>optional
componentsarray<object>optional
createdstringoptional
creditsstringoptional
cvssV2BaseScorenumberoptional
cvssV2ExploitabilitySubScorenumberoptional
cvssV2ImpactSubScorenumberoptional
cvssV2Vectorstringoptional
cvssV3BaseScorenumberoptional
cvssV3ExploitabilitySubScorenumberoptional
cvssV3ImpactSubScorenumberoptional
cvssV3Vectorstringoptional
cvssV4Scorenumberoptional
cvssV4Vectorstringoptional
cwesarray<object>optional
descriptionstringoptional
detailstringoptional
epssobjectoptional
epssPercentilenumberoptional
epssScorenumberoptional
friendlyVulnIdstringrequired
isKevbooleanoptional
owaspRRBusinessImpactScorenumberoptional
owaspRRLikelihoodScorenumberoptional
owaspRRTechnicalImpactScorenumberoptional
owaspRRVectorstringoptional
patchedVersionsstringoptional
publishedstringoptional
recommendationstringoptional
referencesstringoptional
rejectedstringoptional
serviceComponentsarray<object>optional
severitystringoptional
sourcestringrequired
subTitlestringoptional
tagsarray<object>optional
titlestringoptional
updatedstringoptional
uuidstringrequired
vulnIdstringrequired
vulnerableVersionsstringoptional
401Returned when you lack the required vulnerability management permission.
404Returned when the vulnerability to update cannot be found.
406Returned when the request attempts to change the vulnerability's `vulnId`.
Error handling
A 401 is returned when you lack VULNERABILITY_MANAGEMENT or VULNERABILITY_MANAGEMENT_UPDATE permission. A 404 is returned when uuid does not identify an existing vulnerability. A 406 is returned if you attempt to change vulnId. The body must include friendlyVulnId, source, uuid, and vulnId.