Skip to content

Puhti and Mahti computing services have been decommissioned. Puhti and Mahti login nodes and storage services will remain available until 15 October 2026, but are no longer covered by service contracts. Please clean up and migrate your data to Roihu ASAP. See Roihu data migration guide for instructions.

CVE Allowlist

A CVE Allowlist is used to ignore specific vulnerabilities that are known but accepted temporarily.

Sometimes vulnerabilities cannot be fixed immediately because:

  • No patch is available
  • The vulnerability is not exploitable in your environment
  • It does not affect the application functionality

In these cases, administrators can add the vulnerability to the CVE Allowlist. This allows certain vulnerabilities to be ignored for this project.

You have two options:

  • System allowlist Uses the global allowlist defined by Satama administrators
  • Project allowlist uses defined custom CVEs specific to this project.

You can click ADD to add CVE IDs manually. Click COPY FROM SYSTEM to copy global allowlist entries and set expiration date or choose "Never expires".

Warning

Allowlisted CVEs are excluded from vulnerability scan results, so they will no longer block scans or appear as findings for this project. Only add vulnerabilities you have reviewed and accepted, and set an expiration date so the entry is reassessed instead of being ignored indefinitely.