Skip to content

Severity logic? #4566

Answered by jfagoagas
esell asked this question in Q&A
Jul 29, 2024 · 1 comments · 6 replies

You must be logged in to vote

We determine the severity using a mix of CVSS, the maintainers knowledge about the provider, the affected resource and the security check and also the above severity definition. Mixing these three is how we define the check's severity. However, there are some cases where we override the severity to a higher one if the context of the resource indicates a higher risk.

Replies: 1 comment 6 replies

You must be logged in to vote
6 replies
@esell

@jfagoagas

Answer selected by esell
@esell

@jfagoagas

@esell

@jfagoagas

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants