Integrating Netsparker Standard with Bugzilla
Bugzilla is an open-source, web-based bug tracking and testing tool. Its purpose is to help developers manage defects in software development. Developers can use it to keep track of outstanding bugs, problems, issues, enhancements and other product change requests.
This topic explains how to configure Netsparker Standard to send a detected vulnerability to Bugzilla.
For further information, see Configuring the User Interface for Custom Send To Actions in Netsparker Standard and Configuring Auto Send To Actions in Netsparker Standard and What Systems Does Netsparker Integrate With?.
Bugzilla Fields
This table lists and explains the Bugzilla fields in the Send to Actions tab.
Button/Section/Field |
Description |
Add |
Click to add an integration. |
Delete |
Click to delete the integration and clear all fields. |
Configure Send To |
Click to configure the integration using the Settings Wizard instead of doing it manually. |
Create Sample Issue |
Once all relevant fields have been configured, click to create a sample issue. |
Action |
This section contains general fields about the Send to Action. |
Display Name |
This is the name of the configuration that will be shown in menus. |
Mandatory |
This section contains fields that must be completed. |
URL |
This is the Bugzilla instance URL. |
API Key |
This is the API Access Key for authentication. |
Product |
This is the product name. |
Component |
This is the name of a component. |
Version |
This is the product version in which the issue was found. |
Platform |
This is the type of hardware in which the bug was experiences. |
Operating System |
This is the operating system in which the bug was discovered. |
Vulnerability |
This section contains fields with vulnerability details. |
Body Template |
This is the template file that is used to create description fields. |
Title Format |
This is the string format that is used to create the vulnerability title. |
Optional |
This section contains the optional fields. |
Status |
This is the status from which this bug starts. |
Priority |
This is the priority of the bug. |
Assigned To |
This is the user name to whom to assign issues. |
Severity |
This is the severity of the bug. |
Milestone |
This is a valid target milestone for the product. |
Due Days |
This is the number of days between the date the issue was created to the date it’s due. |
Custom Fields |
These are the custom fields that are defined for the project. Click the ellipsis ( In the Edit Custom Field Value field, enter the value. Click OK. |
How to Integrate Netsparker Standard with Bugzilla
- Open Netsparker Standard.
- From the Home tab on the ribbon, click Options. The Options dialog is displayed.
- Click Send To Actions. The Send To Actions dialog is displayed.
- From the Add dropdown, select Bugzilla. The Bugzilla fields are displayed.
- In the Mandatory section, complete the connection details:
- URL
- API Key
- Product
- Component
- Version
- Platform
- Operating System
- Open Bugzilla.
- From the main menu, click Preferences, then API Keys. The existing API Key is displayed.
- Copy and paste the API Key from Bugzilla to the API Key field in Netsparker Standard.
- In Bugzilla, click Administration for details of the remaining connection details and enter them in the relevant Mandatory fields in Netsparker Standard.
To learn about field values in Bugzilla, read Field Values.
- In the Vulnerability section, you can specify the Body Template and Title Format.
Body templates are stored in %userprofile%\Documents\Netsparker\Resources\Send To Templates. If you use your own custom templates, store them in this location.
- In the Optional section you can specify:
- Status
- Priority
- Assigned To
- Severity
- Milestone
- Due Days
- Custom Fields
To learn about Custom fields in Bugzilla, read Custom Fields.
- To set the custom field values, in the Custom Fields field, click the ellipsis button.
- In the Edit Custom Field Value field, enter the relevant value.
- Click OK.
- Click Create Sample Issue to confirm that Netsparker Standard can connect to the configured system. The Send To Action Test confirmation dialog is displayed.
- In the Send To Action Test dialog, click the Issue number link to open the issue in Bugzilla in the default browser.
How to Export Reported Vulnerabilities to Projects in Bugzilla
Please ensure that you have first configured Bugzilla integration. See How to Integrate Netsparker Standard with Bugzilla.
- Open Netsparker Standard.
- From the ribbon, select the File tab. Local Scans are displayed. Double-click the relevant scan to display its results.
- In the Issues panel, right click the vulnerability you want to export and select Send to Bugzilla. (Alternatively, from the ribbon, click the Vulnerability tab, then Send to Bugzilla.) A confirmation message and link is displayed at the bottom of the screen.
- Click the Bugzilla Send to Action is executed for the selected vulnerability link to view the newly-created issue in Bugzilla.
- The vulnerability is now automatically exported to Bugzilla. You can view it in the relevant Bugzilla bug tab.