Skip to content

OWASP grouping not working correctly at instance level

As noted here in VulnerabilitiesRead::Finder we are limiting the filtering option to only project and group level and therefore the results displayed in the group by owasp option are without the owasp filter being applied in the query.

Screenshot_2024-08-20_at_6.42.01_PM

Verification steps:

  1. On the security center, add project https://gitlab.com/gitlab-org/govern/threat-insights-demos/verification-projects/verify-identifier-name-injestion

  2. Visit the instance security dashboard and OWASP top 10 2017 grouping should show counts and list the vulnerabilities for every category.

Edited by Bala Kumar