2026-04-23 19:05 UTC
>most of the results are technically correct, but, within the context of the project, not something anyone’s going to take the time to fix.
I don't mind leaving "technically correct" vulnerabilities in place while there's no known way to create an exploit. If you've got a vuln with a known exploit and are relying on "but nobody is ever going to actually try that on us" - then you're part of the problem, a big part.
Replies (2)
-
@frongt@lemmy.zip 2026-04-24 01:55
This is why CVE scoring is used for severity. A vuln that doesn't really give you anything, that you can only exploit locally, when already having elevated privileges? That's going to be low priority for a fix.
-
@Whelks_chance@lemmy.world 2026-04-24 08:34
It might be a config thing, but pretty often these scans will find issues which are only relevant on e.g. windows, when building a Linux container. Or the issue is in some XML parsing library in the base OS but the service never receives XML and isn't public facing anyway. Context matters.