kube-hunter
kube-hunter copied to clipboard
kube-hunter results display different severity values for the same checks
Severity value discrepancy in kube-hunter report and the vulnerability severity displayed in avd_reference URL(Aqua Vulnerability Database Doc)
Example: The vulnerability ID KHV002 is a high-severity vulnerability as per kubehunter result, however when we click on the link to collect more information about the severity of KHV002 the website Aqua Vulnerability Database shows the KHV002 as a low-severity vulnerability.
Similarly, we have found the discrepancy with below kube-hunter checks as well. Check KubeHunter Severity Vulnerability Database Severity KHV036 High Critical KHV052 Medium High KHV043 High Low
This behaviour can be same across many checks. Please do the needful.
Expected behaviour
The severity value should be same, both in the kube-hunter report and the value displayed in avd_reference url