Ann Samuel
Articles
Recent activity by Ann Samuel
-
Do I need to install an agent to use CVE Shield?
Yes. CVE Shield uses the Contrast ADR agent, which installs once and then protects all covered CVEs automatically, with no code changes or restarts required after initial setup.See: Quickstart Guid...
- Updated
- 0 followers
- 0 comments
- 0 votes
-
What's the difference between observation mode and blocking?
Observation, included on Free, shows real exploitation attempts against your running application, including the route, the CVE, the timestamp, and the source IP. Blocking stops those attempts at ru...
- Updated
- 0 followers
- 0 comments
- 0 votes
-
Which languages does the free tier support?
Free Entry starts with Java only. Support is installed by direct download or Kubernetes container Helm Chart. Linux bare-metal install isn't available currently.See: Quickstart Guide: CVE Shield Fr...
- Updated
- 0 followers
- 0 comments
- 0 votes
-
I'm used to doing X in Contrast, why is it greyed out or missing on CVE Shield Free?
CVE Shield Free is read-only outside of setup and monitoring, so several actions available elsewhere in Contrast aren't available here yet. You can view incidents, including details, evidence, and...
- Updated
- 0 followers
- 0 comments
- 0 votes
-
What do Incident result values mean for CVE Shield Free?
Exploited means an attack reached the vulnerable code and succeeded, with the app in Monitor mode. Suspicious means an attack was detected at the perimeter only. Probed means an attack was detecte...
- Updated
- 0 followers
- 0 comments
- 0 votes
-
What do the CVE Shield status values mean?
Not seen means the CVE hasn't been detected in your application yet. Exposed means the CVE is present and the vulnerable code path is in use, but no attack has been detected. Exploited means an att...
- Updated
- 0 followers
- 0 comments
- 0 votes
-
Why does an incident say "Exploited" or "Blocked" when CVE Shield shows a different status for that CVE?
Incidents and CVE Shield track different things. An incident's result describes a single attack event, and it can be Exploited, Suspicious, Blocked, or Probed. CVE Shield's status describes a CVE'...
- Updated
- 0 followers
- 0 comments
- 0 votes
-
If a vulnerable library is in my app but that code path never runs, will CVE Shield flag it?
No, and that's expected. CVE Shield reports on code that actually executes, not everything sitting in your dependency tree. That's the difference between "reachable," meaning the library is present...
- Updated
- 0 followers
- 0 comments
- 0 votes
-
Accounts & Tiers FAQ
Q: How long does CVE Shield keep my attack history? A: 14 days on Free Entry. Paid tiers extend this window; check with support for exact retention on your plan.See: Data Retention PoliciesQ: How m...
- Updated
- 0 followers
- 0 comments
- 0 votes
-
Are we affected by this CVE
Contrast CVE Shield gives you this answer in under two minutes. It watches your running application and tells you whether a vulnerable location in the library is actually being reached and used, no...
- Updated
- 0 followers
- 0 comments
- 0 votes