Updates CWE as per audit

This commit is contained in:
erwanlr 2022-07-29 11:17:48 +02:00
parent 83b620d0ea
commit 971b992528
28 changed files with 188 additions and 20 deletions

View File

@ -66,7 +66,7 @@
{
"description": [
{
"value": "CWE-284 Improper Access Control",
"value": "CWE-862 Missing Authorization",
"lang": "eng"
}
]
@ -82,4 +82,4 @@
"source": {
"discovery": "UNKNOWN"
}
}
}

View File

@ -66,7 +66,7 @@
{
"description": [
{
"value": "CWE-284 Improper Access Control",
"value": "CWE-862 Missing Authorization",
"lang": "eng"
}
]
@ -82,4 +82,4 @@
"source": {
"discovery": "UNKNOWN"
}
}
}

View File

@ -66,7 +66,7 @@
{
"description": [
{
"value": "CWE-284 Improper Access Control",
"value": "CWE-862 Missing Authorization",
"lang": "eng"
}
]
@ -82,4 +82,4 @@
"source": {
"discovery": "UNKNOWN"
}
}
}

View File

@ -66,7 +66,7 @@
{
"description": [
{
"value": "CWE-284 Improper Access Control",
"value": "CWE-862 Missing Authorization",
"lang": "eng"
}
]
@ -82,4 +82,4 @@
"source": {
"discovery": "UNKNOWN"
}
}
}

View File

@ -61,7 +61,7 @@
{
"description": [
{
"value": "CWE-668 Exposure of Resource to Wrong Sphere",
"value": "CWE-639 Authorization Bypass Through User-Controlled Key",
"lang": "eng"
}
]

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-352 Cross-Site Request Forgery (CSRF)",
"lang": "eng"
}
]
}
]
},

View File

@ -53,6 +53,14 @@
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
},
{
"description": [
{

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-352 Cross-Site Request Forgery (CSRF)",
"lang": "eng"
}
]
}
]
},
@ -72,4 +80,4 @@
"source": {
"discovery": "UNKNOWN"
}
}
}

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
}
]
},

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
}
]
},

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-352 Cross-Site Request Forgery (CSRF)",
"lang": "eng"
}
]
}
]
},

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
}
]
},

View File

@ -65,6 +65,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-352 Cross-Site Request Forgery (CSRF)",
"lang": "eng"
}
]
}
]
},
@ -77,4 +85,4 @@
"source": {
"discovery": "UNKNOWN"
}
}
}

View File

@ -65,6 +65,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
}
]
},
@ -77,4 +85,4 @@
"source": {
"discovery": "EXTERNAL"
}
}
}

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
}
]
},

View File

@ -56,7 +56,15 @@
{
"description": [
{
"value": "CWE-284 Improper Access Control",
"value": "CWE-352 Cross-Site Request Forgery (CSRF)",
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
}
]
},

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
}
]
},

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
}
]
},

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-352 Cross-Site Request Forgery (CSRF)",
"lang": "eng"
}
]
}
]
},

View File

@ -65,6 +65,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-352 Cross-Site Request Forgery (CSRF)",
"lang": "eng"
}
]
}
]
},
@ -77,4 +85,4 @@
"source": {
"discovery": "EXTERNAL"
}
}
}

View File

@ -56,7 +56,7 @@
{
"description": [
{
"value": "CWE-284 Improper Access Control",
"value": "CWE-862 Missing Authorization",
"lang": "eng"
}
]

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
}
]
},

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-203 Observable Discrepancy",
"lang": "eng"
}
]
}
]
},

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
}
]
},

View File

@ -60,6 +60,14 @@
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-79 Cross-site Scripting (XSS)",
"lang": "eng"
}
]
}
]
},
@ -72,4 +80,4 @@
"source": {
"discovery": "EXTERNAL"
}
}
}

View File

@ -56,7 +56,7 @@
{
"description": [
{
"value": "CWE-200 Information Exposure",
"value": "CWE-425 Direct Request ('Forced Browsing')",
"lang": "eng"
}
]
@ -72,4 +72,4 @@
"source": {
"discovery": "EXTERNAL"
}
}
}

View File

@ -56,7 +56,15 @@
{
"description": [
{
"value": "CWE-284 Improper Access Control",
"value": "CWE-862 Missing Authorization",
"lang": "eng"
}
]
},
{
"description": [
{
"value": "CWE-352 Cross-Site Request Forgery (CSRF)",
"lang": "eng"
}
]
@ -72,4 +80,4 @@
"source": {
"discovery": "EXTERNAL"
}
}
}