Update a vulnerability
Partially updates a finding by vulnerabilityId from list or get. The response is the same object as GET.
Writable fields are assigneeEmail, reportLink, and customFields.
assigneeEmail is applied through VM POST /bulkAssignee. reportLink through POST /third-party-finding/finding/update-report-link. customFields through POST /third-party-scans/finding/custom-field.
source cannot be changed. Idempotency-Key is required.
Requires scope vulnerability:write.
curl -X PATCH "https://api.scrut.io/v1/vulnerabilities/import%23CVE-2024-1234" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: 7c9e6679-7425-40de-944b-e07fc1f90ae7" \
-H "Authorization: Bearer YOUR_API_TOKEN (JWT)" \
-d '{
"assigneeEmail": "admin@example.com",
"reportLink": "https://example.com/report",
"customFields": [
{
"customFieldId": "e760f5cb-3de6-49b4-a0c9-425076e033a1",
"fieldValue": "production"
},
{
"value": "no",
"id": "8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b"
}
]
}'
import requests
import json
url = "https://api.scrut.io/v1/vulnerabilities/import%23CVE-2024-1234"
headers = {
"Content-Type": "application/json",
"Idempotency-Key": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
}
data = {
"assigneeEmail": "admin@example.com",
"reportLink": "https://example.com/report",
"customFields": [
{
"customFieldId": "e760f5cb-3de6-49b4-a0c9-425076e033a1",
"fieldValue": "production"
},
{
"value": "no",
"id": "8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b"
}
]
}
response = requests.patch(url, headers=headers, json=data)
print(response.json())
const response = await fetch("https://api.scrut.io/v1/vulnerabilities/import%23CVE-2024-1234", {
method: "PATCH",
headers: {
"Content-Type": "application/json",
"Idempotency-Key": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
},
body: JSON.stringify({
"assigneeEmail": "admin@example.com",
"reportLink": "https://example.com/report",
"customFields": [
{
"customFieldId": "e760f5cb-3de6-49b4-a0c9-425076e033a1",
"fieldValue": "production"
},
{
"value": "no",
"id": "8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b"
}
]
})
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
"bytes"
"encoding/json"
)
func main() {
data := []byte(`{
"assigneeEmail": "admin@example.com",
"reportLink": "https://example.com/report",
"customFields": [
{
"customFieldId": "e760f5cb-3de6-49b4-a0c9-425076e033a1",
"fieldValue": "production"
},
{
"value": "no",
"id": "8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b"
}
]
}`)
req, err := http.NewRequest("PATCH", "https://api.scrut.io/v1/vulnerabilities/import%23CVE-2024-1234", bytes.NewBuffer(data))
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Idempotency-Key", "7c9e6679-7425-40de-944b-e07fc1f90ae7")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN (JWT)")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://api.scrut.io/v1/vulnerabilities/import%23CVE-2024-1234')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(uri)
request['Content-Type'] = 'application/json'
request['Idempotency-Key'] = '7c9e6679-7425-40de-944b-e07fc1f90ae7'
request['Authorization'] = 'Bearer YOUR_API_TOKEN (JWT)'
request.body = '{
"assigneeEmail": "admin@example.com",
"reportLink": "https://example.com/report",
"customFields": [
{
"customFieldId": "e760f5cb-3de6-49b4-a0c9-425076e033a1",
"fieldValue": "production"
},
{
"value": "no",
"id": "8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b"
}
]
}'
response = http.request(request)
puts response.body
{
"data": {
"vulnerabilityId": "import%23CVE-2024-1234",
"title": "Public S3 bucket",
"description": "Bucket is world-readable.",
"status": "open",
"severity": "critical",
"source": "aws",
"assignees": [
{
"name": "Alex Rivera",
"email": "alex@example.com",
"isPrimary": true
}
],
"firstSeen": 1704067200000,
"lastScannedOn": 1704067200000,
"cveId": "CVE-2024-1234",
"cvssScore": 7.5,
"sla": 4,
"reportLink": "https://example.com/report",
"affectedResources": [
{
"name": "s3://bucket",
"type": "s3",
"tags": [
"public"
],
"firstSeen": 1704067200000,
"status": "open"
}
],
"remediation": "Block public ACLs.",
"stepsToReproduce": "Open the bucket URL.",
"addedBy": {
"name": "Alex Rivera",
"email": "alex@example.com"
},
"addedOn": 1704067200000,
"lastModifiedBy": {
"name": "Alex Rivera",
"email": "alex@example.com"
},
"modifiedOn": 1704067200000,
"customFields": [
{
"customFieldId": "e760f5cb-3de6-49b4-a0c9-425076e033a1",
"title": "Environment",
"fieldType": "text_box",
"options": [
{}
],
"fieldValue": "null"
}
],
"tickets": [
{
"id": "SEC-104",
"url": "https://jira.example/browse/SEC-104",
"source": "jira"
}
],
"mappedRisks": [
{
"riskId": "c3d4e5f6-a7b8-4901-8c2d-3e4f5a6b7c8d",
"riskName": "Unauthorized access to production systems"
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "validation_failed",
"message": "Request validation failed.",
"details": [
{
"field": "status",
"message": "status contains unknown value(s): unknown"
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "unauthorized",
"message": "Missing, malformed, or invalid Bearer token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_revoked",
"message": "The API credential was revoked.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_stale",
"message": "The access token is stale; obtain a new token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "forbidden",
"message": "Insufficient scope.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "not_found",
"message": "The requested resource was not found.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "idempotency_key_reused",
"message": "Idempotency key was reused with a different request body.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "idempotency_request_in_progress",
"message": "A request with this idempotency key is already being processed.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "rate_limit_exceeded",
"message": "Rate limit exceeded.",
"details": [
{
"retryAfterSec": 12
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "internal_error",
"message": "An unexpected error occurred.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "upstream_unavailable",
"message": "Upstream service is unavailable.",
"details": [
{
"dependency": "frameworks",
"issue": "Failed to process frameworks."
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
/v1/vulnerabilities/{vulnerabilityId}Target server for requests. Edit to use your own host.
Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.Use the vulnerabilityId returned by list or get. It is already URL-encoded, so paste it as the path segment: /v1/vulnerabilities/{vulnerabilityId}.
The media type of the request body
Client-generated key identifying one logical write. 1–128 characters; letters, numbers, and . _ ~ - only. Reuse the same key and body to retry safely. Reusing a key with a different body returns 409 idempotency_key_reused. Successful 2xx responses are replayed for 24 hours.
HTTPS or HTTP URL. Empty string clears the link.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
Path Parameters
Use the vulnerabilityId returned by list or get. It is already URL-encoded, so paste it as the path segment: /v1/vulnerabilities/{vulnerabilityId}.
import%23CVE-2024-1234Headers
Client-generated key identifying one logical write. 1–128 characters; letters, numbers, and . _ ~ - only. Reuse the same key and body to retry safely. Reusing a key with a different body returns 409 idempotency_key_reused. Successful 2xx responses are replayed for 24 hours.
7c9e6679-7425-40de-944b-e07fc1f90ae7Body
admin@example.com