denimgroup / threadfix

ThreadFix is a software vulnerability management platform. This GitHub site is far out of date. Please go to www.threadfix.it for up-to-date information.
339 stars 127 forks source link

Plugin ID as VulnerabilityType in REST API Output #1757

Open naranek opened 8 years ago

naranek commented 8 years ago

I uploaded a Nessus scan with a CRIME vulnerability, but in the Finding details page the Scanner Vulnerability field shows the plugin ID (62565) instead of the vulnerability name. This is a problem, because apparently the REST API shows this field as vulnerabilityType. When we get data from Threadfix using the API, we now get the plugin ID instead of title for this vulnerability.

I've uploaded the Raw Finding in case it helps. RawFinding.txt

Threadfix version is 2.2.9.

kylepippin commented 8 years ago

Thank you for the feedback. Our Enterprise team identified this issue recently and we will be updating the next release of ThreadFix Enterprise to include the fix. The open source code base receives bug fixes on a trailing schedule compared to Enterprise, but it should be included in future updates.

Thank you for your involvement in our project, and please let us know if you have any other issues! For non-technical questions or requests, please contact us at our new website: http://www.threadfix.it/contact