VulnerabilitiesUpdate a vulnerability

Update a vulnerability

Partially updates a finding by vulnerabilityId from list or get. The response is the same object as GET. Writable fields are assigneeEmail, reportLink, and customFields. assigneeEmail is applied through VM POST /bulkAssignee. reportLink through POST /third-party-finding/finding/update-report-link. customFields through POST /third-party-scans/finding/custom-field. source cannot be changed. Idempotency-Key is required. Requires scope vulnerability:write.

curl -X PATCH "https://api.scrut.io/v1/vulnerabilities/import%23CVE-2024-1234" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 7c9e6679-7425-40de-944b-e07fc1f90ae7" \
  -H "Authorization: Bearer YOUR_API_TOKEN (JWT)" \
  -d '{
  "assigneeEmail": "admin@example.com",
  "reportLink": "https://example.com/report",
  "customFields": [
    {
      "customFieldId": "e760f5cb-3de6-49b4-a0c9-425076e033a1",
      "fieldValue": "production"
    },
    {
      "value": "no",
      "id": "8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b"
    }
  ]
}'
{
  "data": {
    "vulnerabilityId": "import%23CVE-2024-1234",
    "title": "Public S3 bucket",
    "description": "Bucket is world-readable.",
    "status": "open",
    "severity": "critical",
    "source": "aws",
    "assignees": [
      {
        "name": "Alex Rivera",
        "email": "alex@example.com",
        "isPrimary": true
      }
    ],
    "firstSeen": 1704067200000,
    "lastScannedOn": 1704067200000,
    "cveId": "CVE-2024-1234",
    "cvssScore": 7.5,
    "sla": 4,
    "reportLink": "https://example.com/report",
    "affectedResources": [
      {
        "name": "s3://bucket",
        "type": "s3",
        "tags": [
          "public"
        ],
        "firstSeen": 1704067200000,
        "status": "open"
      }
    ],
    "remediation": "Block public ACLs.",
    "stepsToReproduce": "Open the bucket URL.",
    "addedBy": {
      "name": "Alex Rivera",
      "email": "alex@example.com"
    },
    "addedOn": 1704067200000,
    "lastModifiedBy": {
      "name": "Alex Rivera",
      "email": "alex@example.com"
    },
    "modifiedOn": 1704067200000,
    "customFields": [
      {
        "customFieldId": "e760f5cb-3de6-49b4-a0c9-425076e033a1",
        "title": "Environment",
        "fieldType": "text_box",
        "options": [
          {}
        ],
        "fieldValue": "null"
      }
    ],
    "tickets": [
      {
        "id": "SEC-104",
        "url": "https://jira.example/browse/SEC-104",
        "source": "jira"
      }
    ],
    "mappedRisks": [
      {
        "riskId": "c3d4e5f6-a7b8-4901-8c2d-3e4f5a6b7c8d",
        "riskName": "Unauthorized access to production systems"
      }
    ]
  },
  "meta": {
    "requestId": "550e8400-e29b-41d4-a716-446655440000"
  }
}
PATCH
/v1/vulnerabilities/{vulnerabilityId}
PATCH
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token (JWT)
Bearer Tokenstring
Required

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
path
vulnerabilityIdstring
Required

Use the vulnerabilityId returned by list or get. It is already URL-encoded, so paste it as the path segment: /v1/vulnerabilities/{vulnerabilityId}.

Content-Typestring
Required

The media type of the request body

Options: application/json
header
Idempotency-Keystring
Required

Client-generated key identifying one logical write. 1–128 characters; letters, numbers, and . _ ~ - only. Reuse the same key and body to retry safely. Reusing a key with a different body returns 409 idempotency_key_reused. Successful 2xx responses are replayed for 24 hours.

Min length: 1 • Max length: 128 • Pattern: ^[A-Za-z0-9._~-]{1,128}$
assigneeEmailstring
Format: email
Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Path Parameters

vulnerabilityIdstring
Required

Use the vulnerabilityId returned by list or get. It is already URL-encoded, so paste it as the path segment: /v1/vulnerabilities/{vulnerabilityId}.

Example:
import%23CVE-2024-1234

Headers

Idempotency-Keystring
Required

Client-generated key identifying one logical write. 1–128 characters; letters, numbers, and . _ ~ - only. Reuse the same key and body to retry safely. Reusing a key with a different body returns 409 idempotency_key_reused. Successful 2xx responses are replayed for 24 hours.

Example:
7c9e6679-7425-40de-944b-e07fc1f90ae7

Body

application/json
assigneeEmailstring
Example:
admin@example.com

Responses

dataobject
Required
metaobject
Required