openapi: 3.2.0 info: title: Dependency Track Vulns API version: 2.0.0 contact: name: The Dependency-Track Authors url: https://github.com/DependencyTrack/dependency-track email: dependencytrack@owasp.org license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html description: 'Operations tagged Vulns across 2 of this provider''s published API definitions: dependency-track-openapi-v2.yaml, dependency-track-v2-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: /api/v2 security: - apiKeyAuth: [] - bearerAuth: [] tags: - name: Vulns description: Endpoints related to vulnerabilities paths: /vulns/{source}/{vuln_id}/kev-assertions: get: tags: - Vulns summary: Lists KEV assertions for a vulnerability description: 'Returns all Known Exploited Vulnerability (KEV) assertions for the given vulnerability, including those asserted for any of its aliases. Requires permission `VIEW_VULNERABILITY`.' operationId: listVulnKevAssertions parameters: - name: source in: path description: Source of the vulnerability (e.g. `NVD`, `GITHUB`, `OSV`). required: true schema: type: string - name: vuln_id in: path description: Identifier of the vulnerability (e.g. `CVE-2021-44228`). required: true schema: type: string responses: '200': description: A list of KEV assertions for the vulnerability content: application/json: schema: $ref: '#/components/schemas/list-vuln-kev-assertions-response' '401': $ref: '#/components/responses/generic-unauthorized-error' '403': $ref: '#/components/responses/generic-forbidden-error' '404': $ref: '#/components/responses/generic-not-found-error' default: $ref: '#/components/responses/generic-error' servers: - url: /api/v2 components: schemas: paginated-response: required: - total type: object properties: next_page_token: type: string description: Token to retrieve the next page. Absent when no more items exist. total: $ref: '#/components/schemas/total-count' x-parent: true list-vuln-kev-assertions-response: required: - items type: object properties: items: type: array items: $ref: '#/components/schemas/kev-assertion' allOf: - $ref: '#/components/schemas/paginated-response' kev-assertion: required: - asserter - asserter_display_name - created_at - updated_at - vuln_id - vuln_source type: object properties: asserter: type: string description: The entity that asserted the vulnerability is known to be exploited (e.g. `cisa`, `enisa`). asserter_display_name: type: string description: Human-readable name of the asserting entity (e.g. `CISA KEV`). vuln_source: type: string description: Source of the asserted vulnerability identifier (e.g. `NVD`). vuln_id: type: string description: The asserted vulnerability identifier (e.g. `CVE-2021-44228`). published_at: $ref: '#/components/schemas/timestamp' required_action: type: string description: Free-form remediation guidance provided by the source, if any. known_ransomware: type: boolean description: Whether the vulnerability is known to be used in ransomware campaigns. Absent when the source does not report this signal, which is distinct from an explicit `false`. description: type: string description: Short description provided by the source, if any. created_at: $ref: '#/components/schemas/timestamp' updated_at: $ref: '#/components/schemas/timestamp' description: A single assertion that a vulnerability is known to be exploited. problem-details: required: - detail - title - type type: object properties: type: type: string description: A URI reference that identifies the problem type format: uri-reference default: about:blank status: maximum: 599 minimum: 400 type: integer description: HTTP status code generated by the origin server for this occurrence of the problem format: int32 example: 500 title: maxLength: 255 type: string description: Short, human-readable summary of the problem type detail: maxLength: 1024 type: string description: Human-readable explanation specific to this occurrence of the problem instance: type: string description: Reference URI that identifies the specific occurrence of the problem format: uri-reference description: An RFC 9457 problem object. externalDocs: url: https://www.rfc-editor.org/rfc/rfc9457.html x-parent: true total-count: required: - count - type type: object properties: count: minimum: 0 type: integer description: The total number of records across all pages. Might be an exact count, or a lower bound. Refer to the `type` field for the applicable semantics. format: int64 type: $ref: '#/components/schemas/total-count-type' timestamp: type: integer description: Epoch timestamp in milliseconds since January 1, 1970 UTC. format: int64 example: 1752209050377 total-count-type: type: string enum: - AT_LEAST - EXACT responses: generic-error: description: Unexpected error content: application/problem+json: schema: $ref: '#/components/schemas/problem-details' generic-not-found-error: description: Not found content: application/problem+json: schema: $ref: '#/components/schemas/problem-details' example: type: about:blank status: 404 title: Not Found detail: The requested resource could not be found. generic-unauthorized-error: description: Unauthorized content: application/problem+json: schema: $ref: '#/components/schemas/problem-details' example: type: about:blank status: 401 title: Unauthorized detail: Not authorized to access the requested resource. generic-forbidden-error: description: Forbidden content: application/problem+json: schema: $ref: '#/components/schemas/problem-details' example: type: about:blank status: 403 title: Forbidden detail: Not permitted to access the requested resource. securitySchemes: apiKeyAuth: type: apiKey description: Authentication via API key. name: X-Api-Key in: header bearerAuth: type: http description: 'Authentication via opaque server-issued session token. Tokens are obtained from `POST /api/v1/user/login`, `POST /api/v1/user/oidc/login`, or `POST /api/v2/oauth/token`.' scheme: bearer bearerFormat: Opaque x-refined-from: - dependency-track-openapi-v2.yaml - dependency-track-v2-openapi.yml