Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

A05:2021-Security Misconfiguration: Average incidence percentage mismatches from index.md to A05_2021-Security_Misconfiguration.md #697

Open
gerardocanedo opened this issue Apr 2, 2022 · 0 comments
Assignees

Comments

@gerardocanedo
Copy link
Contributor

gerardocanedo commented Apr 2, 2022

Hi

In the index.md A05:2021-Security Misconfiguration has this text:

[A05:2021-Security Misconfiguration](https://github.com/OWASP/Top10/blob/master/2021/docs/A05_2021-Security_Misconfiguration.md) moves up from https://github.com/OWASP/Top10/issues/6 in the previous edition; 90% of applications were tested for some form of misconfiguration, with an average incidence rate of 4.5%, and over 208k occurrences of CWEs mapped to this risk category. With more shifts into highly configurable software, it's not surprising to see this category move up. The former category for A4:2017-XML External Entities (XXE) is now part of this risk category.

In A05_2021-Security_Misconfiguration.md it saids 4.%

## Overview

Moving up from #6 in the previous edition, 90% of applications were tested for some form of misconfiguration, with an average incidence rate of 4.%,

Due to the dot, I think that the correct number is 4.5.
I Appreciate if this can be confirmed.

Thank you,
Gerardo Canedo

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants