Retrieves one published CVE (Common Vulnerabilities and Exposures) record by its id, with its description, severity, and EPSS (Exploit Prediction Scoring System) score. CVE data is global and the same for every organization. Returns a not-found error for an unknown id, and an error when the vulnerability service is not available; check vulnerabilityStatus.
Response
Returns a CVE!
Arguments
| Name | Description |
|---|---|
orgId - OrganizationId!
|
The id of the Organization. |
cveId - ID!
|
The unique Common Vulnerabilities and Exposures identifier (e.g., CVE-2024-1234). |
Example
Query
query vulnerabilityFetchCVE(
$orgId: OrganizationId!,
$cveId: ID!
) {
vulnerabilityFetchCVE(
orgId: $orgId,
cveId: $cveId
) {
id
source
vulnerabilityStatus
published
lastModified
evaluator {
comment
solution
impact
}
cisa {
exploitAdd
actionDue
requiredAction
vulnerabilityName
}
tags {
sourceIdentifier
tags
}
descriptions {
language
value
}
references {
url
source
tags
}
metrics {
source
type
}
weaknesses {
type
source
descriptions {
...CVEDescriptionFragment
}
}
configurations {
operator
negate
nodes {
...CVEConfigurationNodeFragment
}
}
vendorComments {
organization
comment
lastModified
}
severity
epss {
probability
percentile
modelVersion
scoreDate
}
}
}
Variables
{
"orgId": "615f3b3b28284380e28a7342",
"cveId": "4"
}
Response
{
"data": {
"vulnerabilityFetchCVE": {
"id": 4,
"source": "xyz789",
"vulnerabilityStatus": "ANALYZED",
"published": "2021-10-07T18:23:25.829Z",
"lastModified": "2021-10-07T18:23:25.829Z",
"evaluator": CVEEvaluator,
"cisa": CVECISA,
"tags": [CVESourceTag],
"descriptions": [CVEDescription],
"references": [CVEReference],
"metrics": [CVSSMetric],
"weaknesses": [CVEWeakness],
"configurations": [CVEConfiguration],
"vendorComments": [CVEVendorComment],
"severity": "NONE",
"epss": CVEEPSS
}
}
}