Skip to main content

Integrating Invicti Standard with Bugzilla

This document is for:
Invicti Standard

Bugzilla is an open-source, web-based bug tracking and testing tool. Its purpose is to help developers manage defects in software development. Developers can use it to keep track of outstanding bugs, problems, issues, enhancements, and other product change requests.

This topic explains how to configure Invicti Standard to send a detected vulnerability to Bugzilla, enabling seamless integration with your defect management and software development workflow for efficient vulnerability tracking and remediation.

Bugzilla Fields

The following table lists and explains the Bugzilla fields available in the Send to Actions configuration:

Button/Section/FieldDescription
AddSelect to add an integration.
DeleteSelect to delete the integration and clear all fields.
Configure Send ToSelect to configure the integration using the Settings Wizard instead of doing it manually.
Create Sample IssueOnce all relevant fields have been configured, click to create a sample issue.
ActionThis section contains general fields about the Send to Action.
Display NameThis is the name of the configuration that will be shown in menus.
MandatoryThis section contains fields that must be completed.
URLThis is the Bugzilla instance URL.
API KeyThis is the API Access Key for authentication.
ProductThis is the product name.
ComponentThis is the name of a component.
VersionThis is the product version in which the issue was found.
PlatformThis is the type of hardware in which the bug was experienced.
Operating SystemThis is the operating system in which the bug was discovered.
VulnerabilityThis section contains fields with vulnerability details.
Body TemplateThis is the template file that is used to create description fields.
Title FormatThis is the string format that is used to create the vulnerability title.
OptionalThis section contains the optional fields.
StatusThis is the status from which this bug starts.
PriorityThis is the priority of the bug.
Assigned ToThis is the user name to whom to assign issues.
SeverityThis is the severity of the bug.
MilestoneThis is a valid target milestone for the product.
Due DaysThis is the number of days between the date the issue was created to the date it's due.
Custom FieldsThese are the custom fields that are defined for the project. Select the ellipsis(...) to open the Custom Fields Editor dialog. In the Edit Custom Field Value field, enter the value. Select OK.
Bugzilla custom field menu

How to Integrate Invicti Standard with Bugzilla

Follow these steps to configure Bugzilla integration for automated vulnerability tracking:

  1. Open Invicti Standard

  2. From the Home tab on the ribbon, select Options > Send To Actions

  3. From the Add drop-down, select Bugzilla

  4. In the Mandatory section, complete the connection details:

    • URL
    • API Key
    • Product
    • Component
    • Version
    • Platform
    • Operating System
  5. In the Vulnerability section, you can specify the Body Template and Title Format

Template Location

Body templates are stored in %userprofile%\Documents\Invicti\Resources\Send To Templates. If you use your own custom templates, store them in this location.

  1. In the Optional section you can specify:

    • Status
    • Priority
    • Assigned To
    • Severity
    • Milestone
    • Due Days
    • Custom Fields
  2. Select Create Sample Issue to confirm that Invicti Standard can connect to the configured system. In the Send To Action Test dialog, select the Issue number link to open the issue in Bugzilla in the default browser

  3. Select Apply or OK to save the integration

Additional Resources

To learn more about field values in Bugzilla, see Field Values. Looking for API Keys in Bugzilla? See User Preference in Bugzilla. For further information about the connection details, check your administrator page in Bugzilla.

How to Delete the Bugzilla Integration

To remove the Bugzilla integration:

  1. Open Invicti Standard
  2. From the Home tab on the ribbon, select Options > Send to Actions
  3. Select Bugzilla
  4. Select Delete

How to Export Reported Vulnerabilities to Projects in Bugzilla

After configuring the Bugzilla integration, follow these steps to export specific vulnerabilities:

Prerequisites

Please ensure that you have first configured Bugzilla integration. See How to Integrate Invicti Standard with Bugzilla.

  1. Open Invicti Standard
  2. From the ribbon, select the File tab. Local Scans are displayed. Double-click the relevant scan to display its results
  3. In the Issues panel, right-click the vulnerability you want to export and select Send to Bugzilla. (Alternatively, from the ribbon, click the Vulnerability tab, then Send to Bugzilla.) A confirmation message and link are displayed at the bottom of the screen
  4. Select the Bugzilla Send to Action is executed for the selected vulnerability link to view the newly-created issue in Bugzilla

Need help?

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?