---
title: "Put Service Vulnerability Dismissal"
url: "https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8/operations/put-service-vulnerability-dismissal"
---

> Full API specification: https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8.md

# Put Service Vulnerability Dismissal

`PUT` `/catalog-services/{serviceId}/vulnerabilities/{vulnerabilityId}/dismissal`

Operation ID: `put-service-vulnerability-dismissal`

Dismisses a vulnerability for a given service.

## Path parameters

- `serviceId` (string, required) - ID of the service.
- `vulnerabilityId` (string, uuid, required) - ID of the vulnerability.

## Request body (required)

Content types: `application/json`

## Responses

- `200` - Response object containing a single vulnerability.
- `400` - Bad Request
- `401` - Unauthorized
- `403` - Forbidden
- `404` - Not Found

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.3.0
servers:
  - url: https://us.api.konghq.com/v1
    description: United-States Production region
  - url: https://eu.api.konghq.com/v1
    description: Europe Production region
  - url: https://au.api.konghq.com/v1
    description: Australia Production region
  - url: https://me.api.konghq.com/v1
    description: Middle-East Production region
  - url: https://in.api.konghq.com/v1
    description: India Production region
  - url: https://sg.api.konghq.com/v1
    description: Singapore Production region
paths:
  /catalog-services/{serviceId}/vulnerabilities/{vulnerabilityId}/dismissal:
    parameters:
      - schema:
          type: string
        name: serviceId
        in: path
        required: true
        description: ID of the service.
      - schema:
          type: string
          format: uuid
        name: vulnerabilityId
        in: path
        required: true
        description: ID of the vulnerability.
    put:
      x-unstable: true
      x-internal: true
      summary: Put Service Vulnerability Dismissal
      operationId: put-service-vulnerability-dismissal
      description: Dismisses a vulnerability for a given service.
      requestBody:
        $ref: "#/components/requestBodies/PutVulnerabilityDismissalBody"
      responses:
        "200":
          $ref: "#/components/responses/VulnerabilityResponse"
        "400":
          $ref: "#/components/responses/BadRequest"
        "401":
          $ref: "#/components/responses/Unauthorized"
        "403":
          $ref: "#/components/responses/Forbidden"
        "404":
          $ref: "#/components/responses/NotFound"
      tags:
        - Vulnerabilities
security:
  - konnectAccessToken: []
  - personalAccessToken: []
  - systemAccountAccessToken: []
components:
  requestBodies:
    PutVulnerabilityDismissalBody:
      description: Request body schema for dismissing a vulnerability.
      required: true
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/PutVulnerabilityDismissal"
  responses:
    VulnerabilityResponse:
      description: Response object containing a single vulnerability.
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/Vulnerability"
    BadRequest:
      description: Bad Request
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/BadRequestError"
    Unauthorized:
      description: Unauthorized
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/UnauthorizedError"
          examples:
            UnauthorizedExample:
              $ref: "#/components/examples/UnauthorizedExample"
    Forbidden:
      description: Forbidden
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/ForbiddenError"
          examples:
            UnauthorizedExample:
              $ref: "#/components/examples/ForbiddenExample"
    NotFound:
      description: Not Found
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/NotFoundError"
          examples:
            NotFoundExample:
              $ref: "#/components/examples/NotFoundExample"
  schemas:
    PutVulnerabilityDismissal:
      title: PutVulnerabilityDismissal
      type: object
      additionalProperties: false
      properties:
        comment:
          type: string
          description: >
            A human-readable comment associated with the vulnerability
            dismissal, to add further context and description.
          nullable: true
          example: Acceptable risk.
        reason:
          type: string
          description: The reason the vulnerability was dismissed.
          nullable: true
          example: acceptable_risk
      required:
        - comment
        - reason
    Vulnerability:
      title: Vulnerability
      type: object
      additionalProperties: false
      allOf:
        - $ref: "#/components/schemas/BaseVulnerability"
        - type: object
          properties:
            state:
              $ref: "#/components/schemas/VulnerabilityState"
            service:
              $ref: "#/components/schemas/ServiceReference"
          required:
            - state
            - service
    BadRequestError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          required:
            - invalid_parameters
          properties:
            invalid_parameters:
              $ref: "#/components/schemas/InvalidParameters"
    UnauthorizedError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 401
            title:
              example: Unauthorized
            type:
              example: https://httpstatuses.com/401
            instance:
              example: kong:trace:1234567890
            detail:
              example: Invalid credentials
    ForbiddenError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 403
            title:
              example: Forbidden
            type:
              example: https://httpstatuses.com/403
            instance:
              example: kong:trace:1234567890
            detail:
              example: Forbidden
    NotFoundError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 404
            title:
              example: Not Found
            type:
              example: https://httpstatuses.com/404
            instance:
              example: kong:trace:1234567890
            detail:
              example: Not found
    BaseVulnerability:
      title: BaseVulnerability
      type: object
      properties:
        id:
          type: string
          format: uuid
          example: 9932dcab-ec65-46a1-9871-df0aae8e1e8e
        cve_id:
          type: string
          nullable: true
          example: CVE-2025-1000
        fixed_versions:
          type: array
          items:
            type: string
          nullable: true
          example:
            - 1.0.1
            - 2.0.0
        title:
          type: string
          example: Summary of CVE finding.
        description:
          type: string
          nullable: true
          example: Further description text of CVE finding.
        severity:
          $ref: "#/components/schemas/VulnerabilitySeverity"
        severity_score:
          type: integer
          example: 1
          description: numeric representation of severity
        type:
          $ref: "#/components/schemas/VulnerabilityType"
        raw_finding:
          type: object
          additionalProperties: true
        opened_at:
          type: string
          format: date-time
          readOnly: true
          example: 2025-01-01T20:41:45.068Z
        reopened_at:
          type: string
          format: date-time
          nullable: true
          readOnly: true
          example: 2025-01-02T20:41:45.068Z
        last_opened_at:
          type: string
          format: date-time
          readOnly: true
          example: 2025-01-02T20:41:45.068Z
        dismissed_at:
          type: string
          format: date-time
          nullable: true
          readOnly: true
          example: 2025-01-01T21:41:45.068Z
        dismissed_reason:
          type: string
          nullable: true
          example: no_bandwidth
        fixed_at:
          type: string
          format: date-time
          nullable: true
          readOnly: true
          example: 2025-01-01T22:41:45.068Z
        instance_count:
          type: integer
          example: 1
          readOnly: true
        package:
          $ref: "#/components/schemas/VulnerabilityPackage"
        sources:
          type: array
          items:
            type: string
        created_at:
          $ref: "#/components/schemas/CreatedAt"
        updated_at:
          $ref: "#/components/schemas/UpdatedAt"
      required:
        - id
        - cve_id
        - title
        - description
        - severity
        - severity_score
        - type
        - raw_finding
        - opened_at
        - reopened_at
        - last_opened_at
        - dismissed_at
        - dismissed_reason
        - fixed_at
        - fixed_versions
        - instance_count
        - package
        - sources
        - created_at
        - updated_at
    VulnerabilityState:
      type: string
      enum:
        - open
        - fixed
        - dismissed
      example: dismissed
    ServiceReference:
      title: ServiceReference
      type: object
      description: Reference object containing information about a related service.
      properties:
        id:
          type: string
          format: uuid
          example: 7f9fd312-a987-4628-b4c5-bb4f4fddd5f7
          description: The service ID.
          readOnly: true
        name:
          type: string
          description: The name of the Service.
          minLength: 1
          maxLength: 120
          pattern: ^[0-9a-z.-]+$
          example: user-svc
        display_name:
          type: string
          description: The display name of the Service.
          minLength: 1
          maxLength: 120
          example: User Service
      required:
        - id
        - name
        - display_name
    BaseError:
      type: object
      title: Error
      description: standard error
      required:
        - status
        - title
        - instance
        - detail
      properties:
        status:
          type: integer
          description: >
            The HTTP status code of the error. Useful when passing the response

            body to child properties in a frontend UI. Must be returned as an
            integer.
          readOnly: true
        title:
          type: string
          description: |
            A short, human-readable summary of the problem. It should not
            change between occurences of a problem, except for localization.
            Should be provided as "Sentence case" for direct use in the UI.
          readOnly: true
        type:
          type: string
          description: The error type.
          readOnly: true
        instance:
          type: string
          description: |
            Used to return the correlation ID back to the user, in the format
            kong:trace:<correlation_id>. This helps us find the relevant logs
            when a customer reports an issue.
          readOnly: true
        detail:
          type: string
          description: >
            A human readable explanation specific to this occurence of the
            problem.

            This field may contain request/entity data to help the user
            understand

            what went wrong. Enclose variable values in square brackets. Should
            be

            provided as "Sentence case" for direct use in the UI.
          readOnly: true
    InvalidParameters:
      type: array
      nullable: false
      uniqueItems: true
      minItems: 1
      description: invalid parameters
      items:
        oneOf:
          - $ref: "#/components/schemas/InvalidParameterStandard"
          - $ref: "#/components/schemas/InvalidParameterMinimumLength"
          - $ref: "#/components/schemas/InvalidParameterMaximumLength"
          - $ref: "#/components/schemas/InvalidParameterChoiceItem"
          - $ref: "#/components/schemas/InvalidParameterDependentItem"
    VulnerabilitySeverity:
      type: string
      enum:
        - low
        - medium
        - high
        - critical
      example: low
    VulnerabilityType:
      type: string
      enum:
        - container_image
        - library
      readOnly: true
      example: container_image
    VulnerabilityPackage:
      type: object
      description: |
        Details about the package that is affected by vulnerability
      additionalProperties: false
      nullable: true
      properties:
        name:
          type: string
          nullable: true
          description: Name of the vulnerable package
          example: apt
        version:
          type: string
          nullable: true
          description: Version of the vulnerable package
          example: 1.4.11
    CreatedAt:
      type: string
      format: date-time
      example: 2022-11-04T20:10:06.927Z
      description: An ISO-8601 timestamp representation of entity creation date.
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    UpdatedAt:
      type: string
      format: date-time
      example: 2022-11-04T20:10:06.927Z
      description: An ISO-8601 timestamp representation of entity update date.
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    InvalidParameterStandard:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          $ref: "#/components/schemas/InvalidRules"
        source:
          type: string
          example: body
        reason:
          type: string
          example: is a required field
          readOnly: true
      required:
        - field
        - reason
    InvalidParameterMinimumLength:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - min_length
            - min_digits
            - min_lowercase
            - min_uppercase
            - min_symbols
            - min_items
            - min
        minimum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must have at least 8 characters
          readOnly: true
      required:
        - field
        - reason
        - rule
        - minimum
    InvalidParameterMaximumLength:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - max_length
            - max_items
            - max
        maximum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must not have more than 8 characters
          readOnly: true
      required:
        - field
        - reason
        - rule
        - maximum
    InvalidParameterChoiceItem:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - enum
        reason:
          type: string
          example: is a required field
          readOnly: true
        choices:
          type: array
          uniqueItems: true
          readOnly: true
          nullable: false
          minItems: 1
          items: {}
        source:
          type: string
          example: body
      required:
        - field
        - reason
        - rule
        - choices
    InvalidParameterDependentItem:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: true
          enum:
            - dependent_fields
        reason:
          type: string
          example: is a required field
          readOnly: true
        dependents:
          type: array
          uniqueItems: true
          nullable: true
          items: {}
          readOnly: true
        source:
          type: string
          example: body
      required:
        - field
        - rule
        - reason
        - dependents
    InvalidRules:
      description: invalid parameters rules
      type: string
      readOnly: true
      nullable: true
      enum:
        - required
        - is_array
        - is_base64
        - is_boolean
        - is_date_time
        - is_integer
        - is_null
        - is_number
        - is_object
        - is_string
        - is_uuid
        - is_fqdn
        - is_arn
        - unknown_property
        - missing_reference
        - is_label
        - matches_regex
        - invalid
        - is_supported_network_availability_zone_list
        - is_supported_network_cidr_block
        - is_supported_provider_region
        - type
  examples:
    UnauthorizedExample:
      value:
        status: 401
        title: Unauthorized
        instance: kong:trace:8347343766220159418
        detail: Unauthorized
    ForbiddenExample:
      value:
        status: 403
        title: Forbidden
        instance: kong:trace:2723154947768991354
        detail: You do not have permission to perform this action
    NotFoundExample:
      value:
        status: 404
        title: Not Found
        instance: kong:trace:6816496025408232265
        detail: Not Found
  securitySchemes:
    konnectAccessToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        The Konnect access token is meant to be used by the Konnect dashboard
        and the decK CLI authenticate with.
    personalAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: >
        The personal access token is meant to be used as an alternative to
        basic-auth when accessing Konnect via APIs.

        You can generate a Personal Access Token (PAT) from the [personal access
        token page](https://cloud.konghq.com/global/account/tokens/) in the
        Konnect dashboard.

        The PAT token must be passed in the header of a request, for example:

        `curl -X GET 'https://global.api.konghq.com/v2/users/' --header
        'Authorization: Bearer kpat_xgfT...'`
    systemAccountAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: >
        The system account access token is meant for automations and
        integrations that are not directly associated with a human identity.

        You can generate a system account Access Token by creating a system
        account and then obtaining a system account access token for that
        account.

        The access token must be passed in the header of a request, for example:

        `curl -X GET 'https://global.api.konghq.com/v2/users/' --header
        'Authorization: Bearer spat_i2Ej...'`
```
