Files
2026-01-27 17:35:45 -05:00

2.5 KiB

Vulnerability Remediation Guide

Triage Process

1. Assess Impact

  • Is the vulnerability exploitable in your context?
  • Is the vulnerable component reachable?
  • What's the potential business impact?

2. Prioritize

Priority Matrix:
                    Exploitable
                    Yes         No
Impact  High        P1-Critical P2-High
        Medium      P2-High     P3-Medium
        Low         P3-Medium   P4-Low

3. Remediation Options

Option When to Use
Upgrade Fix available, no breaking changes
Patch Apply security patch
Workaround Mitigate until fix available
Accept Risk accepted with documentation
Remove Dependency not needed

Common Remediation Steps

Container Base Images

# Before: Vulnerable base
FROM ubuntu:20.04

# After: Updated base
FROM ubuntu:22.04

# Better: Minimal base
FROM gcr.io/distroless/base-debian12

JavaScript Dependencies

# View outdated packages
npm outdated

# Update specific package
npm update lodash

# Update all (careful!)
npm update

# Force resolution
npm audit fix --force

# Check for updates
npx npm-check-updates

Python Dependencies

# Update specific package
pip install --upgrade requests

# Update with constraints
pip install 'requests>=2.28.0,<3.0.0'

# Using pip-tools
pip-compile --upgrade requirements.in

Terraform Providers

# Pin to secure version
terraform {
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 5.0"  # Update to latest minor
    }
  }
}

False Positive Handling

Trivy Ignore

# .trivyignore
CVE-2022-12345  # Reason: Not exploitable in our context
CVE-2022-67890  # Reason: Component not exposed

Grype Ignore

# .grype.yaml
ignore:
  - vulnerability: CVE-2022-12345
    reason: "Not applicable - component not used"

Documentation Template

## Vulnerability Assessment: CVE-XXXX-XXXXX

**Severity:** High (CVSS 7.5)
**Component:** package-name v1.2.3
**Status:** [Remediated/Accepted/Pending]

### Description
Brief description of the vulnerability.

### Impact Assessment
- Exploitability in our environment: [Yes/No/Partial]
- Affected systems: [List systems]
- Business impact: [Description]

### Remediation
- Action taken: Upgraded to v1.2.4
- Date: YYYY-MM-DD
- Verified by: [Name]

### If Accepted
- Reason for acceptance:
- Compensating controls:
- Review date:
- Approved by: