Platform /Vulnerabilities
VULNERABILITIES

Understand your CVEs.
See what is at risk.

Connect each CVE to the package, version, and cloud workload it affects. Byrsa brings vulnerability details, resource context, and resolution history together so your team can prioritize the right work.

Vulnerabilities / Inside Byrsa
byrsa / Security Platform Search your workspaceD
ALL CONNECTED ACCOUNTS

Vulnerabilities

Example workspace
CriticalActive

CVE-2021-44228

Apache Log4j · Package vulnerability

Package details
Package
log4j-core
Detected version
2.14.1
Package manager
Maven
Fixed version
Consult the vendor advisory
Vendor advisory
Affected resource
payments-apiAmazon EC2
Account
Production
Region
eu-west-1
Environment
Production
Recorded history
First recorded
1 Oct 2026
Last updated
4 Oct 2026
Closure observed
Not observed
Illustrative data Explore the feature in your Byrsa workspace
Generated preview · Illustrative data
Vulnerabilities · Illustrative data
LOOK BEYOND THE CVE IDENTIFIER

Which package? Which workload?
What needs attention?

A CVE identifier is the starting point. Understand the vulnerable version, locate the affected workload, and use the available severity and fix information to plan the next step.

Understand the package

See the affected package and detected version. Compare it with the reported fixed version, when available, to scope the dependency update.

Keep the workload in view

Identify the affected resource, account, and region. Resource context helps the right team recognize where the issue belongs.

Prioritize the CVE

Review severity, available scoring, and CVE references. Investigate critical vulnerabilities alongside exposure and resource relationships in Attack Paths.

Check when it was observed

Distinguish the first recorded and last updated dates from an observed closure. The latest recorded state matters when discussing whether work is still outstanding.

START FROM THE WORKLOAD OR THE FINDING

One investigation.
Different AWS workloads.

Use Hosts to review resources with critical and high findings. Use Findings to search across the collected records and narrow the scope by account, region, severity, and package.

INSTANCES

Amazon EC2

Investigate CVEs affecting packages on an instance, then explore its resource details and potential attack-path context.

Instance → Affected package → CVE
CONTAINER IMAGES

Amazon ECR

Review CVEs associated with packages in a container image and coordinate dependency updates with the application team.

Image → Vulnerable dependency → CVE
FUNCTIONS

AWS Lambda

Trace dependency CVEs back to a function and keep the affected package visible during follow-up.

Function → Affected dependency → CVE

Workload visibility depends on the vulnerability coverage configured for your connected AWS accounts and the findings available to Byrsa.

TRACK THE CVE THROUGH RESOLUTION

See what changed.
Keep the history meaningful.

Follow the status of each CVE finding on an affected workload. Recorded dates help distinguish outstanding vulnerabilities from observed closures and support resolution reporting.

First recorded
The date associated with the finding’s first record.
Last updated
The latest recorded update to the finding.
Closure first observed
When Byrsa first collected the finding in a closed state.
Closed

A closure to include in the history.

Byrsa records a closing date when collection first observes the finding as closed. That date supports resolution reporting; it is not the exact time a package was patched.

Compare the recorded closure with the work your team completed.
Explore resolution trends
GIVE THE INVESTIGATION A NEXT STEP

Keep the finding connected
as the work moves forward.

A package update can involve several workloads and owners. Carry the investigation into the workspace that helps your team decide what to do next.

  1. CVE findingReview the vulnerability
  2. Workload contextUnderstand what is affected
  3. Byrsa taskAssign the follow-up
  4. Jira ticketContinue in your team’s project
Create a task from the finding, then use a connected Jira integration to create a linked ticket.

Find the shared dependency

Use Technologies to investigate a vulnerable package across the findings represented in your environment.

Explore technologies

Investigate potential impact

For EC2, inspect critical CVEs alongside exposure and resource relationships in the attack-path graph.

Explore attack paths

Give the work an owner

Create a linked task, assign responsibility, and create a Jira ticket through a connected integration.

Explore tasks
A CLOSER LOOK

Questions about
Vulnerabilities.

Read the user guide
What can I learn about a CVE in Byrsa?

Open a vulnerability finding to see its CVE identifier, severity, description, affected package and version, workload, and available fix guidance. Follow the resource link to investigate its wider cloud context.

Can the same CVE affect several workloads?

Yes. The same vulnerable dependency can appear on several instances, images, or functions. Use the package and resource filters to scope the affected workloads, and Technologies to explore shared dependencies.

What if a fixed version is not shown?

Version and remediation information depend on the source finding. If a fixed version is not reported, review the available references and guidance with the workload owner.

What does the closing date mean?

It is the first time Byrsa observed a finding as closed during collection. It supports resolution statistics, but does not establish the exact time a fix was applied.

Does completing a task close the finding?

No. A task records the team’s work. The finding’s state comes from collected security data, so confirm the next observation separately.

Put your CVEs in context.

Explore the investigation workflow with the Byrsa team.

Book a walkthrough