Skip to content

Commit

Permalink
Added CWE infos to common and dockerfile queries Checkmarx#6373
Browse files Browse the repository at this point in the history
  • Loading branch information
Jeeppler committed Dec 28, 2023
1 parent 2afa90f commit e8bfcfd
Show file tree
Hide file tree
Showing 50 changed files with 51 additions and 51 deletions.
2 changes: 1 addition & 1 deletion assets/queries/common/passwords_and_secrets/metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"platform": "Common",
"descriptionID": "d69d8a89",
"cloudProvider": "common",
"cwe": ""
"cwe": "798"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#add",
"platform": "Dockerfile",
"descriptionID": "0aedd324",
"cwe": ""
"cwe": "610"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#run",
"platform": "Dockerfile",
"descriptionID": "d44503b8",
"cwe": ""
"cwe": "459"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
"platform": "Dockerfile",
"descriptionID": "4236a50c",
"cwe": ""
"cwe": "459"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
"platform": "Dockerfile",
"descriptionID": "e0e1edad",
"cwe": ""
"cwe": "1357"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#run",
"platform": "Dockerfile",
"descriptionID": "2064113b",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#run",
"platform": "Dockerfile",
"descriptionID": "2e92d18c",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#shell",
"platform": "Dockerfile",
"descriptionID": "d859b2eb",
"cwe": ""
"cwe": "710"
}
2 changes: 1 addition & 1 deletion assets/queries/dockerfile/chown_flag_exists/metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
"platform": "Dockerfile",
"descriptionID": "ba0a34dc",
"cwe": ""
"cwe": "282"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/multistage-build/",
"platform": "Dockerfile",
"descriptionID": "a248d89e",
"cwe": ""
"cwe": "706"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#copy",
"platform": "Dockerfile",
"descriptionID": "bab38efd",
"cwe": ""
"cwe": "628"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
"platform": "Dockerfile",
"descriptionID": "29e8216b",
"cwe": ""
"cwe": "610"
}
2 changes: 1 addition & 1 deletion assets/queries/dockerfile/exposing_port_22/metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://sysdig.com/blog/dockerfile-best-practices/",
"platform": "Dockerfile",
"descriptionID": "79731185",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#run",
"platform": "Dockerfile",
"descriptionID": "0586ed55",
"cwe": ""
"cwe": "1357"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#healthcheck",
"platform": "Dockerfile",
"descriptionID": "426121ee",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#from",
"platform": "Dockerfile",
"descriptionID": "4f469f06",
"cwe": ""
"cwe": "1357"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/dev-best-practices/",
"platform": "Dockerfile",
"descriptionID": "22f535ec",
"cwe": ""
"cwe": "1357"
}
2 changes: 1 addition & 1 deletion assets/queries/dockerfile/last_user_is_root/metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#user",
"platform": "Dockerfile",
"descriptionID": "f445bd25",
"cwe": ""
"cwe": "250"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#maintainer-deprecated",
"platform": "Dockerfile",
"descriptionID": "9d9cbf83",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
"platform": "Dockerfile",
"descriptionID": "8f8497d7",
"cwe": ""
"cwe": "459"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#run",
"platform": "Dockerfile",
"descriptionID": "efc680ea",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#user",
"platform": "Dockerfile",
"descriptionID": "eb49caf6",
"cwe": ""
"cwe": "250"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
"platform": "Dockerfile",
"descriptionID": "0ab4ed7e",
"cwe": ""
"cwe": "1357"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#run",
"platform": "Dockerfile",
"descriptionID": "a95b2646",
"cwe": ""
"cwe": "459"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#run",
"platform": "Dockerfile",
"descriptionID": "b3efa689",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#cmd",
"platform": "Dockerfile",
"descriptionID": "96f59ca3",
"cwe": ""
"cwe": "1041"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#entrypoint",
"platform": "Dockerfile",
"descriptionID": "03be1867",
"cwe": ""
"cwe": "1041"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://sysdig.com/blog/dockerfile-best-practices/",
"platform": "Dockerfile",
"descriptionID": "29bd3a34",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#entrypoint",
"platform": "Dockerfile",
"descriptionID": "070b84da",
"cwe": ""
"cwe": "573"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#run",
"platform": "Dockerfile",
"descriptionID": "8bd60033",
"cwe": ""
"cwe": "1357"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
"platform": "Dockerfile",
"descriptionID": "a6eb5f34",
"cwe": ""
"cwe": "459"
}
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,8 @@
"severity": "MEDIUM",
"category": "Build Process",
"descriptionText": "When using RUN command 'cd' should only be used for full path. For relative path make use of WORKDIR command instead.",
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#workdir",
"descriptionUrl": "https://docs.docker.com/develop/develop-images/instructions/#workdir",
"platform": "Dockerfile",
"descriptionID": "edd9f7d3",
"cwe": ""
"cwe": "710"
}
2 changes: 1 addition & 1 deletion assets/queries/dockerfile/run_using_apt/metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#run",
"platform": "Dockerfile",
"descriptionID": "6cb53718",
"cwe": ""
"cwe": "758"
}
2 changes: 1 addition & 1 deletion assets/queries/dockerfile/run_using_sudo/metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#run",
"platform": "Dockerfile",
"descriptionID": "c4f2e24a",
"cwe": ""
"cwe": "440"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#run",
"platform": "Dockerfile",
"descriptionID": "22261deb",
"cwe": ""
"cwe": "1041"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#run",
"platform": "Dockerfile",
"descriptionID": "677fa9a6",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/multistage-build/",
"platform": "Dockerfile",
"descriptionID": "c923ad4b",
"cwe": ""
"cwe": "694"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#run",
"platform": "Dockerfile",
"descriptionID": "26810b44",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#expose",
"platform": "Dockerfile",
"descriptionID": "fed3d812",
"cwe": ""
"cwe": "682"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
"platform": "Dockerfile",
"descriptionID": "adb9d5d5",
"cwe": ""
"cwe": "1357"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/",
"platform": "Dockerfile",
"descriptionID": "37db3a53",
"cwe": ""
"cwe": "1357"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#run",
"platform": "Dockerfile",
"descriptionID": "3785203d",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#from",
"platform": "Dockerfile",
"descriptionID": "5bd0baab",
"cwe": ""
"cwe": "695"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/multistage-build/",
"platform": "Dockerfile",
"descriptionID": "dea09829",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html",
"platform": "Dockerfile",
"descriptionID": "e0d6ef5e",
"cwe": ""
"cwe": "1395"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#workdir",
"platform": "Dockerfile",
"descriptionID": "bfe0be8b",
"cwe": ""
"cwe": "665"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#run",
"platform": "Dockerfile",
"descriptionID": "714267a2",
"cwe": ""
"cwe": "459"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/engine/reference/builder/#run",
"platform": "Dockerfile",
"descriptionID": "f17a245a",
"cwe": ""
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,5 @@
"descriptionUrl": "https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#run",
"platform": "Dockerfile",
"descriptionID": "19d4cfc7",
"cwe": ""
"cwe": "1357"
}
Loading

0 comments on commit e8bfcfd

Please sign in to comment.