Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Divd-2024-00031 case #823

Merged
merged 13 commits into from
Dec 15, 2024
Merged

Divd-2024-00031 case #823

merged 13 commits into from
Dec 15, 2024

Conversation

vcartman
Copy link
Collaborator

@vcartman vcartman commented Aug 8, 2024

Divd-2024-00031 case release

Pasman and others added 3 commits August 5, 2024 20:31
@MrSeccubus
Copy link
Contributor

Ik mis de release van de CVE in dit PR, klopt dat?
Gaan we zo niet naar public but reserved?

@vcartman
Copy link
Collaborator Author

Ik mis de release van de CVE in dit PR, klopt dat? Gaan we zo niet naar public but reserved?

Verwerkt.

Copy link
Contributor

@MrSeccubus MrSeccubus left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Er stonden nog review comments open.

_cases/2024/DIVD-2024-00031.md Outdated Show resolved Hide resolved
end:
event: "First version of this casefile."
# ips: 0

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ik mis de settings om dit een locale cve te maken zie template case 3000-1 of 3000-2

_cases/2024/DIVD-2024-00031.md Outdated Show resolved Hide resolved
_cases/2024/DIVD-2024-00031.md Outdated Show resolved Hide resolved
_cases/2024/DIVD-2024-00031.md Outdated Show resolved Hide resolved
_cases/2024/DIVD-2024-00031.md Outdated Show resolved Hide resolved
Comment on lines +20 to +25
{
"lang": "en",
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"type": "CWE"
}
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Volgens mij moet die CWE-98 zijn.
https://cwe.mitre.org/data/definitions/98.html

Copy link
Collaborator Author

@vcartman vcartman Sep 12, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Het was gewijzigd van CWE-98 naar deze omdat het PHP LFI was in overleg met Alwin, @MrSeccubus Vind je het handiger om dit alsnog te wijzigen?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CWE-200 is wanneer gevoelige data "gewoon" wordt weergegeven, maar dit is een LFI, maar geen code execution.

Ik zou hem dan onder CWE-22 (path traversal) zetten. CWE-98 is idd LFI van PHP code, wat hier niet het geval is.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CWE-41 is misschien een nog beter match https://cwe.mitre.org/data/definitions/41.html

_data/cves/2024/CVE-2024-27120.json Outdated Show resolved Hide resolved
@Lennaert89 Lennaert89 merged commit b8354c0 into DIVD-NL:main Dec 15, 2024
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants