Vulnerability BI — sidebar hides with the toggle

Decision Compression

Four queues derived from the published metrics, each with the rule that placed a record there. Team ownership is not automated.

Mode: Global CVE catalogue
0 CVEs in scope
Global CVE catalogue
Supports action
Investigate if present — not detected exposure.

Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.

Data sources, exact rule, and what is unknown

Powered by: public.canonical_findings (state, severity, verification completeness) · public.canonical_finding_remediations (persisted work items, SLA and owner fields)

Rule: Queue = Immediate patch when Priority ≥ 0.72; Infrastructure review when attack vector is network and CIA impact ≥ 0.6; Software review when a software-class CWE is present; otherwise Watch, which always states its reason and review date.

Not known by this lens:
  • Owner and team assignment: Unknown — not collected — ownership routing is not automated.
  • Medium and low findings do not auto-create work items; they stay manual candidates.

Immediate patch

0

Review with infra team

0

Review with software team

0

Watch only

0
How this works — definitions, thresholds, and what to doShow

Queue rule, applied in this order:

  • Immediate patch — priority ≥ 0.72.
  • Review with infra team — attack vector is network or adjacent and CIA impact ≥ 0.6.
  • Review with software team — the record carries a software-class CWE (injection, deserialisation, authentication, hard-coded credentials).
  • Watch only — no rule above matched. Reason: nothing in the published metrics placed it in an action queue; revisit at the next quarterly review or when its KEV or EPSS status changes.

Owner and team assignment: Unknown — not collected — ownership routing is not automated, so a queue name describes the kind of review needed, not an assigned team. Medium and low findings do not auto-create work items; they stay manual candidates.