Skip to content

Nessus Import Incorrect Severity #6992

@AmenoBars

Description

@AmenoBars

Hello,

We've been testing DefectDojo for managing Nessus imports. I've noticed that the Severity seems to be acting weird. It seems to take the values from the Nessus scan correctly, but not display them correctly. If I then go to edit the finding, it will have the right settings and then saving it without making changes it displays as it does according to the Nessus report. As an example, this finding is marked in Nessus as a 9.8 - Critical, but is showing in DefectDojo findings as a 9.8 High:

image

If I then go and edit it, it has critical as the severity rating:
image

And then saving that without making any changes to what was already there changes it to a critical:
image

Is this expected behaviour? It seems odd.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions