Back to integrations
    SCA

    Endor Labs integration

    Add an exploitability verdict with evidence to Endor Labs SCA findings, on top of Endor's own reachability.

    Integration details

    Primary category

    Software Composition Analysis

    Sync direction

    Endor Labs → Konvu

    Konvu reads Endor Labs findings once a day and on demand with read-only credentials. Verdicts go out as fix pull requests, Slack alerts, and through the Konvu API.

    Status

    Available

    Reachable is not the same as exploitable

    Endor Labs tells you whether a vulnerable function is reachable. The vulnerability may still need a configuration, a runtime, or input an attacker cannot supply. Konvu reads Endor Labs findings with their reachability tags and checks those remaining conditions in your code, then returns a verdict with evidence. Exploitable findings can go straight to a fix pull request.

    Endor Labs findings Konvu analyzes

    SCA

    Endor Labs

    Open source dependency findings, with the reachability tags Endor Labs assigned.

    Not imported today

    • Endor Labs findings outside the SCA category

    Access and setup

    An Endor Labs API key and secret, created under Settings > API Keys, plus the namespace to import. One connection covers one namespace.

    To read findings

    • Read access to Projects
    • Read access to Findings

    To write back

    No write access is needed.

    • Konvu reads your code through your GitHub or GitLab connection, not through Endor Labs.

    How Konvu investigates Endor Labs findings

    What Konvu receives

    The Endor Labs finding: the package, version, advisory, and Endor's reachability tags.

    What Konvu checks

    • Whether the reachable function is called with input an attacker controls.
    • Whether your runtime, framework, and configuration match what the exploit needs.
    • Whether a safe API variant or validation sits between the input and the vulnerable call.

    What decides the verdict

    Konvu returns exploitable, false positive, or inconclusive, with the reasoning behind it: the code it read, the conditions it tested, and what settled the call. When the answer depends on something only your team knows, Konvu asks a question instead of guessing.

    Illustrative example

    A SnakeYAML finding from Endor Labs

    A made-up service, written to show how an investigation reads. Not a customer result.

    1. 1

      Scanner finding

      Endor Labs reports CVE-2022-1471 in SnakeYAML 1.33 for a Java service and tags the vulnerable constructor as reachable. SnakeYAML before 2.0 can create arbitrary types when it loads untrusted YAML with its default constructor.

    2. 2

      Application context

      The service accepts YAML workflow definitions through an authenticated API endpoint.

    3. 3

      Investigation

      Konvu follows the request body from the upload endpoint to new Yaml().load(), which uses the default constructor with no type restrictions. Any authenticated user can reach the endpoint, and no SafeConstructor or type allowlist sits in between.

    4. 4

      Verdict

      Exploitable. An authenticated user can send YAML that creates arbitrary classes on the classpath.

    5. 5

      Evidence

      The endpoint, the path from the request body to Yaml.load, and the constructor configuration Konvu checked.

    6. 6

      Where it ends up

      The finding is marked exploitable in Konvu with its evidence, and Konvu can propose the SnakeYAML upgrade as a pull request through your GitHub or GitLab connection.

    Writeback and controls

    Where results go

    • Exploitable dependency findings can become a fix pull request in GitHub or GitLab, opened automatically if you turn that on for the repository.
    • Exploitable findings can be posted to Slack, so the team hears about them without opening Konvu.
    • Every verdict and its evidence can be pulled into your own tools through the Konvu API or CLI.

    Who triggers it

    Konvu imports findings on its daily schedule and when you run a sync. What to do with a verdict is up to your team.

    What stays with your team

    • Dismissing or updating findings in Endor Labs.

    The technical detail