Skip to main content

Vulnerabilities

The Vulnerabilities page (/vulnerabilities in the app) helps you investigate CVEs affecting your AWS resources. Start with the impacted resource, review its vulnerable packages, and follow each finding through resolution.

Byrsa collects vulnerability findings from Amazon Inspector for EC2 instances, Lambda functions, and ECR container images where coverage is enabled. Misconfigurations remain a separate view for cloud configuration checks.

Coverage required

Enable Amazon Inspector for the workloads you want to assess in your connected AWS accounts. Findings appear after collection. See Prerequisites.

Start with impacted resources​

The default view groups open CVEs by resource so you can see which workloads need attention. Review severity counts, search for a resource, and use the account, region, and resource-type filters to narrow your scope.

Expand a resource to see its CVEs. Click a CVE row to open the shared vulnerability detail dialog.

Explore all findings​

Choose All findings to search collected vulnerability records across resources. Filter by severity, account, region, package, fix availability, and other available attributes. Open a finding to inspect the affected package and resource together.

Understand a vulnerability​

Depending on the source data, the details include:

  • CVE identifier and severity — identify the issue and its assessed impact.
  • Affected resource — the workload, AWS account, and region.
  • Package versions — the installed version and a fixed version when reported.
  • Scores and references — available CVSS information and advisory links.
  • Recorded dates — when the finding was observed, updated, or closed.

You can open the full detail page, create a task, or record a risk exception using the available actions.

Follow resolution​

An Active finding still requires review. Closed means the source reported it as closed; Byrsa records when it first observed that closure for resolution statistics. Suppressed means the finding was suppressed and should not be interpreted as fixed.

Use recorded closure dates in reports to follow progress. Findings linked only to resources that disappear from a successful inventory scan are removed with those resources; their absence is not evidence of a patch being applied.