---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Container Vulnerability Response remediation task and container vulnerable item states

# Container Vulnerability Response remediation task and container vulnerable item states {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

With the Container Vulnerability Response application, you can use the state model to see the status of a remediation task, at any given time. Knowing how each state relates to and affects each other helps you to determine when and how to
remediate your container vulnerable items (CVITs).

## Remediation task states {#container-vulnerabillity-states__VulnGrpStates}

Complex use cases can sometimes result in a container vulnerable item being in a different state than its remediation task. Understanding how states work helps to explain this behavior and can help with creating remediation
tasks and creating or editing remediation task rules.  
Remediation tasks have many possible states as shown in the following diagram.Figure 1. Container Vulnerability Response state flow  
Note:  
* Container vulnerable items cannot be closed manually.
* Each task form contains Follow and Update buttons that are standard for ServiceNow tasks.
{#container-vulnerabillity-states__ul_v2m_mbp_dcc}

## Remediation task and CVIT state transition and precedence order {#container-vulnerabillity-states__section_fpg_rcx_dgc}

Remediation tasks and vulnerable items states can affect each other. Most of the time, a remediation task state updates the vulnerable item state, with the highest precedence task state used to update the vulnerable items in the
group.

From the creation to closure of a Container Remediation Task, it transitions through various states during the entire remediation process.

The state precedence is as follows:

ClosedDeferredResolvedIn ReviewAwaiting ImplementationUnder InvestigationOpen

The state transition happens as you perform various actions such as Defer, Open, Close, etc.

The actions you can perform on a Container Remediation Task at a specific state is similar to that of a Host Remediation Task. Hence, for more information, see the [Vulnerability Response remediation task states](https://servicenow-prod.fluidtopics.net/gfzl087_DD6DEMX2PTbn1g "Third-party integrations import vulnerable item detection data that create new vulnerability items (VITs) or update existing VITs. Detection states update VIT states in so far as they’re Open or Closed.") and [State roll-up and roll-down scenarios](https://servicenow-prod.fluidtopics.net/k6XJEdYCOayUDrr7kP93Xg "State roll-up and roll-down scenarios automatically sync the status of remediation tasks (RTs) and vulnerable items (VITs), ensuring real-time updates across both. This dynamic interaction reduces manual tracking, enhances accuracy, and provides users with an up-to-date view of progress, making vulnerability management more efficient and helping users make informed decisions quickly.") in the Vulnerability Response documentation.

*[\>]: and then


