-
Notifications
You must be signed in to change notification settings - Fork 47
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Divd-2024-00031 case #823
Divd-2024-00031 case #823
Conversation
Casefile for new ComfortKey
Divd 2024 00031
Ik mis de release van de CVE in dit PR, klopt dat? |
Verwerkt. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Er stonden nog review comments open.
end: | ||
event: "First version of this casefile." | ||
# ips: 0 | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ik mis de settings om dit een locale cve te maken zie template case 3000-1 of 3000-2
{ | ||
"lang": "en", | ||
"cweId": "CWE-200", | ||
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor", | ||
"type": "CWE" | ||
} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Volgens mij moet die CWE-98 zijn.
https://cwe.mitre.org/data/definitions/98.html
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Het was gewijzigd van CWE-98 naar deze omdat het PHP LFI was in overleg met Alwin, @MrSeccubus Vind je het handiger om dit alsnog te wijzigen?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
CWE-200 is wanneer gevoelige data "gewoon" wordt weergegeven, maar dit is een LFI, maar geen code execution.
Ik zou hem dan onder CWE-22 (path traversal) zetten. CWE-98 is idd LFI van PHP code, wat hier niet het geval is.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
CWE-41 is misschien een nog beter match https://cwe.mitre.org/data/definitions/41.html
Co-authored-by: Frank Breedijk <[email protected]>
Co-authored-by: Frank Breedijk <[email protected]>
Co-authored-by: Frank Breedijk <[email protected]>
Co-authored-by: Frank Breedijk <[email protected]>
Co-authored-by: Frank Breedijk <[email protected]>
Co-authored-by: Frank Breedijk <[email protected]>
Divd-2024-00031 case release