CVSS and impact
Findings include normalized severity, score, and CVSS vector when enough evidence exists to derive one.
Every ZeroQuarry finding can carry severity, CVSS, PoC artifacts, source references, adversarial review history, confidence, human validation, patch context, and exports for the people who need to act.
A user-controlled tenant value reaches invoice update without an ownership check. The red-team agent proved write impact; vendor review challenged scope; rebuttal sustained with a file-line trace.
Findings include normalized severity, score, and CVSS vector when enough evidence exists to derive one.
Artifacts can include proof-of-concept code, request streams, notes, or deployment packages for review.
Source findings link back to files and lines; remote findings preserve the URL or request chain that triggered the issue.
Vendor challenges, red-team rebuttals, revisions, and retractions remain visible in the report.
Confidence is recomputed from review outcomes, repeated appearances, and human validation or invalidation signals.
Patch proposals, GitHub PRs, Jira issues, and ServiceNow records link back to the original finding.
Export executive summaries, finding overviews, per-asset lists, and branded report covers.
Move detailed findings into internal docs, disclosure packages, or engineering review notes.
Share a self-contained report view without giving recipients access to the full workspace.
Create issues from findings and preserve a deep link back to ZeroQuarry evidence.
Create enterprise records on the configured table for vulnerability operations teams.
Send password-protected, expiring finding bundles to vendors, auditors, customers, or external reviewers.
Track queued, running, failed, completed, and batch-finalized scan states.
Record vendor verdict, rebuttal result, retractions, revisions, and confidence.
Accept or invalidate findings with reason codes and notes for later review.
Connect patch versions, PR links, ticket records, and disclosure state to the finding.