? / Alert IDs and Confidence/Severity

14 views
Skip to first unread message

James L

unread,
Mar 24, 2025, 4:33:53 PMMar 24
to ZAP User Group
Greetings,

I am working on a KB to help developers triage zap alerts. I'm still in early stages...

My question is: Do alertIDs have static attributes like severity/confidence or are those set dynamically? I don't need to keep track of the reported severity if its going to stay the same every time an alert id is reported. Also, all of this excludes manually changing mappings away from default.

I *think* they are static... Thank you for any help/insight you can provide.

-James L

Simon Bennetts

unread,
Mar 24, 2025, 5:25:48 PMMar 24
to ZAP User Group
Hi James,

They are _mostly_ static :/
Some rules set different severity or confidence levels depending on what they find.
We have extensive documentation here https://www.zaproxy.org/docs/alerts/ but I'm afraid we dont flag which rules use static values and which ones use dynamic ones :/
Sorry about that.

Simon
Reply all
Reply to author
Forward
0 new messages