
Ranger Danger (Community Member) asked a question.
Question about inputting a Risk Exception in for a High/Critical Vulnerability within Veracode.
Say for instance. We have a High and or a Critical Vulnerability in the Veracode Platform and the team is not able to fix the vulnerability within the allotted time frame.
Is there a solution for this? Or is there a way the Product team can load in an option/Radio Button/ under the Mitigations area in Veracode for a Risk Exception Option with these expirations (30 days Critical / 60 Day High) to allow the application to go green?
Once the Developers correct the Vulnerability then I can go in manually, or an automatic action will detect that the vulnerability has been fixed and then the application will stay in the green status instead of going back into the red if the vulnerability is not corrected in the allotted time frame.
Thanks, Shawn Ranger
.png)
Hello @Ranger Danger (Community Member),
Thank you for reaching out to the Community.
I would recommend that you go to the Idea in the Community. The more community support an Idea receives, the more likely it will be considered or prioritized for implementation.
Please review the ideas below to submit alike. The more you get the more it may get reviewed for approval.
https://community.veracode.com/s/idea/0873n000000TjprAAC/detail
https://community.veracode.com/s/idea/0873n000000kG3mAAE/view
https://community.veracode.com/s/idea/0873n000000PcPCAA0/view
Kind regards,
Steven
Veracode Support Engineer
this would be a great enhancement especially for Software Composition Analysis findings.