Objective
Cross reference OpenShield scan findings against the MITRE NVD database in real time to surface known CVEs affecting Azure resource versions and configurations.
What needs to be built
- NVD API integration
- Match scan findings against relevant CVEs by resource type and configuration
- Surface CVSS score and exploit availability alongside findings
- This is the core differentiator as no other free CSPM tool does this today
Acceptance criteria
Priority
Phase 2
Objective
Cross reference OpenShield scan findings against the MITRE NVD database in real time to surface known CVEs affecting Azure resource versions and configurations.
What needs to be built
Acceptance criteria
Priority
Phase 2