Skip to content

Severity logic? #4566

Answered by jfagoagas
esell asked this question in Q&A
Jul 29, 2024 · 1 comments · 6 replies
Discussion options

You must be logged in to vote

We determine the severity using a mix of CVSS, the maintainers knowledge about the provider, the affected resource and the security check and also the above severity definition. Mixing these three is how we define the check's severity. However, there are some cases where we override the severity to a higher one if the context of the resource indicates a higher risk.

Replies: 1 comment 6 replies

Comment options

You must be logged in to vote
6 replies
@esell
Comment options

@jfagoagas
Comment options

Answer selected by esell
@esell
Comment options

@jfagoagas
Comment options

@esell
Comment options

@jfagoagas
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants