Container Vulnerability Response release notes
Summarize
Summary of Container Vulnerability Response release notes
The ServiceNow® Container Vulnerability Response application integrates security and IT operations to help remediate critical container vulnerabilities efficiently. The Australia release introduces several enhancements and integrations to improve vulnerability management for container environments.
Show less
Key Features
- AWS Integration for Security Exposure Management: Supports AWS Inspector and AWS Security Hub, enabling import of vulnerability findings from EC2, ECR container images, Lambda functions, and centralized AWS security checks.
- Wiz Scanner Integration: Import container image vulnerability data from Wiz into Container Vulnerable Items (CVITs) with flexible configuration that no longer requires specifying resource types, simplifying setup.
- Manual Remediation Tasks: Users with specific roles can manually create container remediation tasks via Vulnerability Manager Workspace or IT Remediation Workspace.
- Enhanced Data Import and Format Alignment: Updated image repository naming aligns with discovery formats across third-party integrations, facilitating better visibility and tracking of container images and vulnerabilities.
- Unified Microsoft Defender Integration: Combines Microsoft Defender for Cloud and Threat and Vulnerability Management plugins into a single integration with container image vulnerability ingestion capabilities and guided migration.
- Configurable Image Vulnerability Keys: Allows configuration of keys that generate CVITs, supporting UUID mapping for Wiz and accommodating AWS ECS and EKS environments with customizable data sources (scanner or discovery).
Important Information for Customers
- Container Vulnerability Response is available through the ServiceNow Store and requires installation via the store.
- Upgrading to Unified Security Exposure Management (USEM) is recommended for enhanced capabilities; guidance is available in the USEM release notes.
- Now Assist for Vulnerability Response is being deprecated and replaced by the ServiceNow Otto brand, but entitlements remain unchanged.
- Perform a full import after upgrading to activate new features on discovered container image records and vulnerability findings.
- Deprecated features include the Path column on the Container Image Package table (moved to Container Image Finding table) and the Missing Assets table for Wiz integration; customers must adjust accordingly.
- For Wiz integration, after upgrading to version 1.1, backdate existing primary integrations by three days and rerun them to ensure data consistency.
Activation and Upgrade Recommendations
Customers should install Container Vulnerability Response and related third-party integrations from the ServiceNow Store. Before upgrading, review compatibility matrices and release schema changes documented in the Now Support Knowledge Base. Configure scheduled jobs appropriately, especially if using discovery as a data source, to ensure timely data import and relationship mapping.
Benefits for ServiceNow Customers
- Improved integration with leading cloud security services (AWS, Microsoft Defender, Wiz) for comprehensive container vulnerability management.
- Streamlined configuration and enhanced data visibility enable faster and more accurate remediation of container vulnerabilities.
- Manual remediation task creation supports operational flexibility within established workflows.
- Future-proofing through migration to Unified Security Exposure Management and alignment with ServiceNow’s new AI branding ensures ongoing support and innovation.
The ServiceNow® Container Vulnerability Response application brings security and IT together to enable you to remediate your most critical vulnerabilities more quickly and efficiently. Container Vulnerability Response was enhanced and updated in the Australia release.
Container Vulnerability Response highlights for the Australia release
- The AWS Integration for Security Exposure Management supports integrations with AWS Inspector and AWS Security Hub.
- If you're currently using Container Vulnerability Response and you want to upgrade to Unified Security Exposure Management (USEM), see Unified Security Exposure Management (USEM) release notes for more information about USEM and the Unified Security Exposure Management migration.
- Import container image vulnerability data from the Wiz scanners into container vulnerable items (CVITs) with the Vulnerability Response Integration with Wiz.
- With the sn_vul_container.vulnerability_analyst or sn_vul_container.vulnerability_admin role, create container remediation tasks manually in the Vulnerability Manager Workspace.
- With the role sn_vul_container.remediation_owner, create container remediation tasks manually in the IT Remediation Workspace.
See Container Vulnerability Response for more information.
Important information for upgrading Container Vulnerability Response to Australia
Starting with Australia Patch 5, Now Assist for Vulnerability Response is being prepared for future deprecation. It will be hidden and no longer installed on new instances but will continue to be supported. For details, see the Deprecation Process [KB0867184] article in the Now Support Knowledge Base.
ServiceNow Otto® is the new AI experience brand. This change is reflected in the name of ServiceNow products, including the Now Assist for Vulnerability Response product name, which will be replaced with ServiceNow Otto for Unified Security Exposure Management. Your product entitlements remain unchanged. Check your entitlements to determine your access to specific features.
Enhancements to Container Vulnerability Response permit you to see enriched container vulnerability data on data imports from your third-party scanners. After you upgrade, perform a full import to view the features on discovered container image, container image finding, and container vulnerable item records that are described in the following New in the Australia release section.
If you're currently using Container Vulnerability Response, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Container Vulnerability Response and for upgrades to supported third-party integration applications.
For more information about the released versions of the Container Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Australia release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base.
New in the Australia release
- Activate the Wiz Asset Integration and identify resource types for import
- Enhancements to the Wiz integration include:
- A link lets you navigate from the Wiz configuration module directly to the Configure VI Granularity module where you can configure the keys that generate Container Vulnerability Response findings.
-
Starting with version 32.1 (USEM) and version 4.1 (non-USEM), the Asset integration is deactivated by default and is not a mandatory prerequisite for the other Wiz integration imports.
If you choose to activate it, the Asset integration will retrieve assets for all resource types if you don't specify the ones you want on the Asset Integration Configuration tab. To avoid importing vulnerability data you don't need, identify only the resources (assets) that you want to import with this integration.
- Resource Type is no longer a mandatory field for configuring the Vulnerability Response Integration with Wiz. You can now save Wiz configurations for the integrations without specifying a Resource Type, simplifying setup for use cases where specifying a Resource Type isn't appropriate.
- Enhancements to Container Vulnerability Response
-
The image repository name format for new and existing discovered container images in the Container Vulnerability Response application has been updated to align with the discovery format. Perform a complete import to view the registry/repository enhancements on existing and new records.
- The registry/repository format is supported for all third-party integrations including the Vulnerability Response integration with Palo Alto Networks Prisma Cloud Compute and Vulnerability Response Integration with Wiz third-party integrations.
- Appended all repositories that are associated with an image to the Repository field on records on the Discovered Container Image [sn_vul_container_image] table, which can help you see images from specific repositories.
- The default integration instance parameter for configuring finding keys for the Container Vulnerability Integration includes src_ci, vulnerability, package, image_layer, and image_repository.
Added the source_id column to the Container Image Finding [sn_vul_container_image_findings] table. Mapped the id attribute from imports to the Source id field on findings records for all third-party integrations including the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute and Vulnerability Response Integration with Wiz third-party integrations.
- AWS Integration for Security Exposure Management
- The AWS Integration for Security Exposure Management supports integrations with the following AWS services:
- AWS Inspector is an automated vulnerability management service that continuously scans EC2 instances, ECR container images, and Lambda functions for software vulnerabilities (CVEs) and unintended network exposure. The Vulnerability Response integration with AWS Inspector imports host and container vulnerability findings from AWS Inspector.
- AWS Security Hub is a security service that is used to centralize and update security checks across AWS accounts. It provides a unified view of security alerts and compliance status by integrating with various AWS services. The Vulnerability Response integration with AWS Security Hub imports host, container vulnerabilities, and misconfigurations from AWS Security Hub.
- Unified Microsoft Defender Integration for Security Exposure Management
- The Microsoft Defender for Cloud and Microsoft Defender Threat and Vulnerability Management (MS TVM) plugins are now consolidated into a single plugin: Microsoft Defender Integration for Security Exposure Management. This consolidation deprecates the standalone Microsoft Defender for Cloud plugin. The unified plugin also introduces container image vulnerability ingestion from Microsoft Defender for Cloud, creating Container Vulnerable Items on your instance. A guided migration path is available to transfer existing data from the deprecated applications to the unified plugin.
- Configure Image Vulnerability keys for Container Vulnerability Response CVIT creation
- Configure records on the Configure Image Vulnerability Keys [sn_vul_container_image_vulnerability_keys] table in your ServiceNow AI Platform® instance for the Image Vulnerability Keys that create container vulnerable items (CVIT)s.
- The Universally Unique Identifier (UUID) provided by Wiz is now mapped as the detection key for the Wiz Host Vulnerability integration.
- AWS ECS (Elastic Container Service) and AWS EKS (Elastic Kubernetes Service) environments are supported.
- Cluster and Service are supported for AWS ECS environments.
- Namespace, Registry, and Service are supported for AWS EKS environments.
- Choose either Scanner (third-party scanners) or Discovery (Configuration Management Database (CMDB)) as sources for data import for AWS ECS and AWS EKS.Note:
If you choose Discovery as the data source, the Populate image relationships scheduled job runs daily to pre-import cluster and service details, and you should schedule your third-party integration runs at least 4 hours after this scheduled job is completed to verify that the pre-import data is available. This job is activated by default, but you must set the schedule so it runs before your scheduled third-party integration runs.
For new customers only: The system property, sn_vul_container.image_relationship_mapping_months sets the number of previous months (1-12) that you want your third-party integration to look for container image updates when processing relationship mappings. This data is used to filter images by the sys_updated_on field. The default setting is three months. After you configure the integration run, relationship mapping is created for images which have been scanned in the last 90 days and present in discovered container images.
- Column labels on the Container Vulnerable item [sn_vul_container_image_vulnerable_item] table are updated to support the scanner and discovery options, depending on your choice on the Configure Image Vulnerability Keys
configuration page:
- Cluster (Scanner) Namespace (scanner), and Service (scanner) for scanner data
- Cluster (Discovery), Namespace (Discovery) and Service (Discovery) for Discovery
Deprecated features
- The Path Column in the Container Image Package [sn_vul_container_image_package] table for the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute and Vulnerability Response Integration with Wiz third-party integrations. Path tracking has been moved to the Path Column on the Container Image Finding
[sn_vul_container_image_findings] table to support accurate and consistent path and image association.
If you use these integrations you must refer to the Path column available on the Container Image Finding [sn_vul_container_image_findings] table.
- The Missing Assets [sn_vul_wiz_missing_asset] table used for storing assets imported by the backfill integrations for the Vulnerability Response Integration with Wiz is deprecated. If you're currently using the Vulnerability Response with Wiz integrations, after updating to version 1.1, you must backdate any of your existing Wiz primary integrations by three days and run them. See more information about the Wiz integration at SecOps articles on the Security Operations Community.
Activation information
Install Container Vulnerability Response and third-party integrations by requesting them from the ServiceNow Store. Visit the ServiceNow Store to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.