DependencyTrack / DependencyTrack/dependency-track

Edit

Open
#4,780 0 comments 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

Certain CPE components in our inventory are known to be affected by specific CVE vulnerabilities. However, upon analysis, these CVEs do not appear in the vulnerability list for the respective CPE components. I attempted to manually add the affected CPE components to the CVE's list of impacted components but found that this functionality is not available.
![Image](https://github.com/user-attachments/assets/f0378186-63a4-4ab0-b75b-955854df7be5)

### Proposed Behavior

It would be highly beneficial if Dependency-Track allowed users to manually edit the list of affected components for CVE vulnerabilities. This feature would enable more accurate tracking and management of vulnerabilities, especially in cases where automatic associations are incomplete or missing.

### Checklist

- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this enhancement was already requested

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.