All integrations

CSAF Integration with DefectDojo

CSAF Integration with DefectDojo

CSAF (Common Security Advisory Framework) is an OASIS standard for publishing security advisories in a machine-readable form. A CSAF 2.0 document is JSON: it describes a vendor's products in a product tree, lists vulnerabilities by CVE or vendor ID, and states each product's status (affected, not affected, fixed, or under investigation) along with CVSS scores, remediations, and references. Vendors including Red Hat, SUSE, Cisco, and Siemens publish their advisories as CSAF. Unlike a scanner report, a CSAF file is published by a vendor's product security team, not generated by scanning your environment.

CSAF Integration with DefectDojo

We import CSAF advisories into DefectDojo for the vendor software we run but cannot scan ourselves, such as appliances, commercial platforms, and packaged products. Reading advisories one at a time on vendor portals never scaled, and nothing tracked whether we acted on them. In DefectDojo, each vulnerability and product pair in an advisory becomes its own Finding, with the vendor's status deciding whether it is active, mitigated, or a confirmed non-issue. The affected ones get owners and SLAs like any scanner finding, and the vendor's "not affected" statements stay on record without turning into work.

Why CSAF Matters

Vendor advisories are often the only vulnerability data available for closed products, and CSAF makes them consistent enough to automate.

  • It is a published standard, so one parser covers advisories from every vendor that adopts it.
  • Product status is explicit. An advisory says which versions are affected, which are fixed, and which are not affected, instead of leaving that to prose.
  • Scores are scoped to products, so the same CVE can carry different severities for different products in one advisory.
  • Remediations are structured, with category, details, a link, and whether a restart is required.
  • Vendors publish feeds of CSAF documents, which makes collecting advisories something you can schedule.

Advantages of This Integration

What importing CSAF into DefectDojo gives us:

  • One Finding per vulnerability and product. A single advisory often covers many products in different states. Splitting them keeps each product's status accurate.
  • Vendor status respected. Products listed as known not affected are imported inactive and marked false positive. Fixed, first fixed, and recommended products are imported inactive and mitigated. Under investigation is active but not verified. Affected statuses, and any bucket a future revision adds, are active.
  • Sensible severity. Severity comes from the product's CVSS v3 base severity, or from the base score bands if only a score is given. An advisory with no score at all imports as Medium, so it is not hidden behind a minimum severity filter.
  • Deduplication across advisory revisions. Findings are hashed on the vulnerability ID, component name, and component version, so a revised advisory updates the same Findings instead of creating new ones.
  • Remediation in the Finding. Vendor fixes, workarounds, links, and restart requirements are written into Mitigation, so the owner has the next step without opening the advisory.
  • Same workflow as everything else. Affected findings get SLAs, assignment, risk acceptance, and Jira tickets, and show up in metrics next to scanner results.

How This Integration Works

DefectDojo imports CSAF documents with the CSAF Scan scan type. Only CSAF 2.0 JSON is supported. Documents in the older CSAF 1.x (CVRF) schema are rejected with a clear error rather than misread.

1. Collect advisories. Vendors that publish CSAF describe their feed in a provider-metadata.json file under /.well-known/csaf/. The reference Go implementation from the gocsaf project includes a downloader that mirrors a vendor's advisories:

csaf_downloader --directory ./advisories https://vendor.example.com

You can also download individual advisories from a vendor's security page. To check a document against the schema before import, run csaf_validator from the same project.

2. Import each advisory. In the UI, open the Engagement, choose Import Scan Results, select CSAF Scan, and upload the JSON file. To automate it, use the import API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=CSAF Scan" 
  -F "file=@example-2026-0001.json" 
  -F "product_name=vendor-appliance" 
  -F "engagement_name=Vendor Advisories" 
  -F "auto_create_context=true"

DefectDojo Pro users can do the same with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "CSAF Scan" 
  --report-path "./example-2026-0001.json" 
  --product-name "vendor-appliance" 
  --engagement-name "Vendor Advisories" 
  --auto-create-context

3. Product resolution. The parser builds product names and versions from all three CSAF mechanisms: the flat full_product_names list, the nested branches tree (where the version is carried down from its product_version branch), and relationships, which define combined products such as a library as a component of an application. When a leaf name repeats its version, the version is stripped from the name so the component name stays consistent between advisory styles.

Data Granularity: What Gets Imported

DefectDojo Field Source in CSAF Document Notes
Title Product name, version, and vulnerability ID Component name and version, then the CVE or vendor ID
Severity scores[].cvss_v3.baseSeverity for the product Score bands if only baseScore; Medium if no score
Description Status, vulnerability title, notes, CVSS, advisory title, publisher Inactive findings explain why
Mitigation remediations[] for the product Category, details, URL, restart required
References references[] Summary and URL per reference
Vulnerability IDs cve, plus ids[].text Vendor tracking ID used when no CVE (embargoed issues)
CWE cwe.id Numeric CWE
CVSS v3 vectorString, baseScore Per product
Component Name / Version Product tree Resolved from names, branches, or relationships
Date document.tracking.current_release_date Falls back to initial release date
Active / Mitigated / False Positive product_status bucket See status rules above
Unique ID from tool Product ID and vulnerability ID Collapses repeats within one file
Finding type Static All findings are marked static
Deduplication Hashcode vuln_id_from_tool, component_name, component_version

Use Cases

Tracking appliances and closed products: A team running network appliances from several vendors collects each vendor's CSAF feed weekly and imports advisories into an Asset per product line. Affected findings carry SLAs, and the not-affected records show which advisories were reviewed.

Responding to a high-profile CVE: When a widely reported CVE lands, vendors publish CSAF statements about which products are exposed. Importing those statements shows, in one place, which of your vendor products are affected, fixed in a newer release, or explicitly not affected.

Following advisory revisions: Vendors often revise an advisory as fixes ship, moving products from under investigation to affected or fixed. Reimporting the revised document updates the same findings, so status changes are tracked instead of duplicated.

Supporting audits: Vendor fixes and restart requirements are recorded on each Finding, which gives change and patch teams a documented path from advisory to remediation.

Operational Tips

  • An advisory can list many products you do not run. Review the imported Test and close findings for products outside your estate, so they do not count against SLAs.
  • Import each vendor product line into its own Asset, so ownership and SLAs follow the team that runs it.
  • Validate documents with csaf_validator before import if a feed has been unreliable. Invalid or CSAF 1.x documents fail the import.
  • Expect not-affected and fixed findings to appear inactive. They are kept on purpose as a record of what the vendor stated.
  • Under investigation findings are active and unverified. Revisit them when the vendor publishes a revision, and reimport the new version.
  • Tag imports with the vendor and advisory ID (for example tags=vendorname,EXAMPLE-2026-0001) to trace findings back to their source document.