O
0
c/devsecopsthe_susanthe_susan18d agoProlific Poster

My CVE triage process was backwards for 2 years until a pentest report smacked me

I used to rank vulnerabilities by CVSS score alone, thought that was the whole job. Last month our pentester found a medium severity SSRF that let him hit our internal metadata endpoint in AWS, full creds in 20 minutes. That high severity SQLi I kept patching first? It was behind a WAF and basically useless to an attacker. The report literally said 'your scoring is fine, your business context is missing.' Now I map every finding to what data it touches and what systems it can pivot to, not just the number. Anyone else still triaging purely off CVSS and feeling exposed?
0 comments

Log in to join the discussion

Log In
0 Comments

No comments yet

Be the first to share your thoughts on this discussion.