Customize protection by CVE
With Contrast CVE Shield, you can use an override when a specific CVE needs different handling than your organization's default. An override replaces the default protection level for that specific CVE, in the environments you specify, across your entire organization. For example, if you can't patch a vulnerable library yet but want to block it in Production while monitoring it in Development.
Before you begin
An agent must be installed and configured on a service.
Any authenticated member of your organization who can reach Policies > CVE shield can change default protection levels.
Create an override
Overrides apply organization-wide. You can't currently scope an override to specific applications. Every application in the affected environment uses the override's protection level for that CVE. Like global default protection levels, override changes can take up to 5 minutes to take effect.
In Northstar, in the left navigation, go to Policies > CVE shield.
Under CVE Shields Overrides, select Create override.
In the search box, enter a full or partial CVE ID (for example,
CVE-2021-44228) and select it from the results.If the CVE already has an override, select View existing override instead of creating a new one.
Review the CVE's title and description to confirm you've selected the right one.
For each environment, select a protection mode: Off, Monitor, or Block.
If your organization is on the CVE Shield Free tier, Block won't appear as an option. Choose Off or Monitor.
Optionally, enter a reason for the override, such as: "Legacy service cannot be patched until Q3." A reason helps your team understand the override later.
Select Create override.
Note
For Contrast CVE Shield Free tier organizations, override changes aren't recorded in the audit log. If you need a change history, a paid tier license is required. See View audit log (hosted customers) for details.
Manage overrides
Under CVE Shields Overrides, find the CVE using the search box or by sorting the table.
Select the CVE to open its override details.
To change the protection level, update the protection mode for the affected environment and select Save.
To remove the override entirely, select Delete. The CVE reverts to your organization's default protection level.
See also
Set global default protection levels
View your CVE Shields in Explorer