Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update - PII Leakage updated to Sensitive Information Leak #351

Closed
evildaemond opened this issue May 1, 2023 · 3 comments
Closed

Update - PII Leakage updated to Sensitive Information Leak #351

evildaemond opened this issue May 1, 2023 · 3 comments

Comments

@evildaemond
Copy link

Description

The Bugcrowd VRT variant Automotive Security Misconfiguration > Infotainment, Radio Head Unit > PII Leakage has been brought up on occasion, as the variant is not used properly due to the terminology of the submission title. We have seen PII leakage being miscategorised due to the term PII inside of it's name.

We want to provide a solution to this which gives people an option to categorise their submissions properly, this would be a new category called PII Leakage/Exposure with the intent that a researcher would select this submission when they identify information such as exposed data for a user or group where a class such as IDOR does not match the way this information was identified.

Recommendations

  1. Update the title of the variant Automotive Security Misconfiguration > Infotainment, Radio Head Unit > PII Leakage to Sensitive Data Leakage. (This is a temporary measure until the Automotive Security Misconfiguration can properly be overhauled)
  2. Create a new variant under Sensitive Data Exposure called PII Leakage/Exposure which has the impact of Varies.
@TimmyBugcrowd
Copy link
Contributor

TimmyBugcrowd commented May 1, 2023

I totally agree with this. Don't you think that Sensitive Data Leakage should be Sensitive Data Leakage/Exposure as in Varies?

@amalmurali47
Copy link
Contributor

I agree with the recommendations. For additional clarity, these are the changes being proposed:

  • Remove:
    • (P1) Automotive Security Misconfiguration > Infotainment, Radio Head Unit > PII Leakage
  • Add:
    • (Varies) Automotive Security Misconfiguration > Infotainment, Radio Head Unit PII Leakage > Sensitive Data Leakage
  • Add:
    • (Varies) Sensitive Data Exposure > Disclosure of Secrets > PII Leakage

I've modified PII Leakage/Exposure to PII Leakage so it's consistent with the other entries.

@TimmyBugcrowd
Copy link
Contributor

Closing the issue since the PR for this has been submitted: #361

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

3 participants