DependencyTrack / DependencyTrack/dependency-track
Edit
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior
Certain CPE components in our inventory are known to be affected by specific CVE vulnerabilities. However, upon analysis, these CVEs do not appear in the vulnerability list for the respective CPE components. I attempted to manually add the affected CPE components to the CVE's list of impacted components but found that this functionality is not available.

### Proposed Behavior
It would be highly beneficial if Dependency-Track allowed users to manually edit the list of affected components for CVE vulnerabilities. This feature would enable more accurate tracking and management of vulnerabilities, especially in cases where automatic associations are incomplete or missing.
### Checklist
- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this enhancement was already requested
Contributor guide
Assessment
This issue has not been assessed yet.