Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

LDAP Injection #367

Merged
merged 3 commits into from
Oct 27, 2023
Merged

LDAP Injection #367

merged 3 commits into from
Oct 27, 2023

Conversation

TimmyBugcrowd
Copy link
Contributor

Adding LDAP Injection as a new VRT entry.

@vortexau
Copy link

Approved for import into intermediate branch.

@TimmyBugcrowd
Copy link
Contributor Author

Imported to intermediate branch.

@TimmyBugcrowd TimmyBugcrowd changed the base branch from master to 1.20-stable October 27, 2023 14:27
@TimmyBugcrowd TimmyBugcrowd merged commit 0291cec into 1.20-stable Oct 27, 2023
1 check passed
@TimmyBugcrowd TimmyBugcrowd deleted the LDAP-Injection branch October 27, 2023 14:28
nnons pushed a commit that referenced this pull request Nov 13, 2023
* Updating the SSRF category

* Revert "Updating the SSRF category"

This reverts commit 785bd8b.

* Update SSRF classification from `Broken Access Control` to `Server Security Misconfiguration`

* Update SSRF mappings in CVSS V3, CWE, and Remediation Advice files

* Refactor SSRF category and split `External` variant into `GET Request Only` and `DNS Query Only`

* Update CVSS V3 mapping to include the updated mappings for the `External` SSRF variant

* PII-leakage-update

FROM:
P1 - Automotive Security Misconfiguration - Infotainment, Radio Head Unit - PII Leakage

TO:
P1 - Automotive Security Misconfiguration - Infotainment, Radio Head Unit - Sensitive data Leakage/Exposure
Varies - Sensitive Data Exposure - Disclosure of Secrets - PII Leakage/Exposure

* Update secure-code-warrior-links.json

* Update remediation_advice.json

* Update remediation_advice.json

* Update cwe.json

* Update cwe.json

* Update cwe.json

* Update cwe.json

* Update cwe.json

* Update cwe.json

* Update cwe.json

* Update remediation_advice.json

* HTTP Request Smuggling

Adding HTTP Request Smuggling as a new VRT entry.

* Update remediation_advice.json

* Update cvss_v3.json

* Failure to invalidate session on permission change

Adding Failure to invalidate session on permission change as a new VRT entry.

* Update cwe.json

* Update cwe.json

* Update remediation_advice.json

* Update cwe.json

* Deprecation of XSS on IE11

REMOVE: P4 - Cross-Site Scripting (XSS) - IE-Only - IE11

FROM: P5 - Cross-Site Scripting (XSS) - IE-Only - Older Version (< IE11)

TO: P5 - Cross-Site Scripting (XSS) - IE-Only

* Update remediation_advice.json

* LDAP Injection

Adding LDAP Injection as a new VRT entry.

* Update cwe.json

* Update remediation_advice.json

* Update cvss_v3.json

* HTML-Injection

Adding the category below to VRT:
P5 - Server-Side Injection - Content Spoofing - HTML Content Injection

* SSRF External Low Impact

* new IDOR variants

new IDOR variants

* LDAP Injection (#367)

* Update vulnerability-rating-taxonomy.json

* Update cvss_v3.json

* Update cvss_v3.json

* New Changes LDAP Injection

* Cryptographic Weakness Category #352

* New changes Cryptographic Weakness category

* json parse error fix (#380)

* hyphens to underscores in vrt items

* Update remediation_advice.json

* Update remediation_advice.json

---------

Co-authored-by: Amal Murali <amalmurali47@gmail.com>
Co-authored-by: Deepak Kumar Jha <Deepak.jha@bugcrowd.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

2 participants