Skip to content

AI entries revised #464

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 10 commits into from
Jun 20, 2025
Merged

AI entries revised #464

merged 10 commits into from
Jun 20, 2025

Conversation

TimmyBugcrowd
Copy link
Contributor

Adding:
P1 - AI Application Security - Training Data Poisoning - Backdoor Injection / Bias Manipulation
P1 - AI Application Security - Model Extraction - API Query-Based Model Reconstruction
P1 - AI Application Security - Sensitive Information Disclosure - Cross-Tenant PII Leakage/Exposure .
P1 - AI Application Security - Sensitive Information Disclosure - Key Leak
P1 - AI Application Security - Remote Code Execution - Full System Compromise
P2 - AI Application Security - Remote Code Execution - Sandboxed Container Code Execution
P2 - AI Application Security - Prompt Injection - System Prompt Leakage
P2 - AI Application Security - Vector and Embedding Weaknesses - Embedding Exfiltration / Model Extraction
P3 - AI Application Security - Vector and Embedding Weaknesses - Semantic Indexing
P2 - AI Application Security - Denial-of-Service (DoS) - Application-Wide
P4 - AI Application Security - AI Safety - Misinformation / Wrong Factual Data
P4 - AI Application Security - Insufficient Rate Limiting - Query Flooding / API Token Abuse
P4 - AI Application Security - Denial-of-Service (DoS) - Tenant-Scoped
P4 - AI Application Security - Adversarial Example Injection - AI Misclassification Attacks
P3 - AI Application Security - Improper Output Handling - Cross-Site Scripting (XSS)
P4 - AI Application Security - Improper Output Handling - Markdown/HTML Injection
P5 - AI Application Security - Improper Input Handling - ANSI Escape Codes
P5 - AI Application Security - Improper Input Handling - Unicode Confusables
P5 - AI Application Security - Improper Input Handling - RTL Overrides

Removing:
P1 - AI Application Security - Large Language Model (LLM) Security - LLM Output Handling
P1 - AI Application Security - Large Language Model (LLM) Security - Prompt Injection
P1 - AI Application Security - Large Language Model (LLM) Security - Training Data Poisoning
P2 - AI Application Security - Large Language Model (LLM) Security - Excessive Agency/Permission Manipulation

Adding:
P1 - AI Application Security - Training Data Poisoning - Backdoor Injection / Bias Manipulation
P1 - AI Application Security - Model Extraction - API Query-Based Model Reconstruction
P1 - AI Application Security - Sensitive Information Disclosure - Cross-Tenant PII Leakage/Exposure
P1 - AI Application Security - Remote Code Execution - Full System Compromise
P1 - AI Application Security - Sensitive Information Disclosure - Key Leak
P2 - AI Application Security - Remote Code Execution - Sandboxed Container Code Execution
P2 - AI Application Security - Prompt Injection - System Prompt Leakage
P2 - AI Application Security - Vector and Embedding Weaknesses - Embedding Exfiltration / Model Extraction
P2 - AI Application Security - Denial-of-Service (DoS) - Application-Wide
P3 - AI Application Security - Vector and Embedding Weaknesses - Semantic Indexing
P3 - AI Application Security - Improper Output Handling - Cross-Site Scripting (XSS)
P4 - AI Application Security - Improper Output Handling - Markdown/HTML Injection
P4 - AI Application Security - AI Safety - Misinformation / Wrong Factual Data
P4 - AI Application Security - Insufficient Rate Limiting - Query Flooding / API Token Abuse
P4 - AI Application Security - Denial-of-Service (DoS) - Tenant-Scoped
P4 - AI Application Security - Adversarial Example Injection - AI Misclassification Attacks
P5 - AI Application Security - Improper Input Handling - ANSI Escape Codes
P5 - AI Application Security - Improper Input Handling - Unicode Confusables
P5 - AI Application Security - Improper Input Handling - RTL Overrides
RRudder added a commit to bugcrowd/templates that referenced this pull request Jun 2, 2025
These updates are to match the VRT update - bugcrowd/vulnerability-rating-taxonomy#464

Adding:
P1 - AI Application Security - Training Data Poisoning - Backdoor Injection / Bias Manipulation
P1 - AI Application Security - Model Extraction - API Query-Based Model Reconstruction
P1 - AI Application Security - Sensitive Information Disclosure - Cross-Tenant PII Leakage/Exposure .
P1 - AI Application Security - Sensitive Information Disclosure - Key Leak
P1 - AI Application Security - Remote Code Execution - Full System Compromise
P2 - AI Application Security - Remote Code Execution - Sandboxed Container Code Execution
P2 - AI Application Security - Prompt Injection - System Prompt Leakage
P2 - AI Application Security - Vector and Embedding Weaknesses - Embedding Exfiltration / Model Extraction
P3 - AI Application Security - Vector and Embedding Weaknesses - Semantic Indexing
P2 - AI Application Security - Denial-of-Service (DoS) - Application-Wide
P4 - AI Application Security - AI Safety - Misinformation / Wrong Factual Data
P4 - AI Application Security - Insufficient Rate Limiting - Query Flooding / API Token Abuse
P4 - AI Application Security - Denial-of-Service (DoS) - Tenant-Scoped
P4 - AI Application Security - Adversarial Example Injection - AI Misclassification Attacks
P3 - AI Application Security - Improper Output Handling - Cross-Site Scripting (XSS)
P4 - AI Application Security - Improper Output Handling - Markdown/HTML Injection
P5 - AI Application Security - Improper Input Handling - ANSI Escape Codes
P5 - AI Application Security - Improper Input Handling - Unicode Confusables
P5 - AI Application Security - Improper Input Handling - RTL Overrides

Removing:
P1 - AI Application Security - Large Language Model (LLM) Security - LLM Output Handling
P1 - AI Application Security - Large Language Model (LLM) Security - Prompt Injection
P1 - AI Application Security - Large Language Model (LLM) Security - Training Data Poisoning
P2 - AI Application Security - Large Language Model (LLM) Security - Excessive Agency/Permission Manipulation
@abhinav-nain abhinav-nain changed the base branch from master to q2-25-release-mapping June 20, 2025 08:57
@abhinav-nain abhinav-nain merged commit 2bbf360 into q2-25-release-mapping Jun 20, 2025
3 checks passed
@abhinav-nain abhinav-nain deleted the q2-25-release-AI branch June 20, 2025 08:57
nnons pushed a commit that referenced this pull request Jun 20, 2025
* GraphQL Introspection Enabled - P5

#450

* Bypass of Password Confirmation on Password Change

Add:
Broken Access Control – Bypass of Password Confirmation – Change Password

* Revert "Bypass of Password Confirmation on Password Change"

This reverts commit a6e415a.

* Bypass of Password Confirmation on Password Change

Add:
Broken Access Control – Bypass of Password Confirmation – Change Password

* Revert "Bypass of Password Confirmation on Password Change"

This reverts commit 3418212.

* Broken Access Control (BAC) - Bypass of Password Confirmation - Change Password (#462)

* Revert "Bypass of Password Confirmation on Password Change"

This reverts commit 3418212.

* Bypass of Password Confirmation on Password Change

Add:
Broken Access Control – Bypass of Password Confirmation – Change Password

* AI entries revised (#464)

* AI entries revised

Adding:
P1 - AI Application Security - Training Data Poisoning - Backdoor Injection / Bias Manipulation
P1 - AI Application Security - Model Extraction - API Query-Based Model Reconstruction
P1 - AI Application Security - Sensitive Information Disclosure - Cross-Tenant PII Leakage/Exposure
P1 - AI Application Security - Remote Code Execution - Full System Compromise
P1 - AI Application Security - Sensitive Information Disclosure - Key Leak
P2 - AI Application Security - Remote Code Execution - Sandboxed Container Code Execution
P2 - AI Application Security - Prompt Injection - System Prompt Leakage
P2 - AI Application Security - Vector and Embedding Weaknesses - Embedding Exfiltration / Model Extraction
P2 - AI Application Security - Denial-of-Service (DoS) - Application-Wide
P3 - AI Application Security - Vector and Embedding Weaknesses - Semantic Indexing
P3 - AI Application Security - Improper Output Handling - Cross-Site Scripting (XSS)
P4 - AI Application Security - Improper Output Handling - Markdown/HTML Injection
P4 - AI Application Security - AI Safety - Misinformation / Wrong Factual Data
P4 - AI Application Security - Insufficient Rate Limiting - Query Flooding / API Token Abuse
P4 - AI Application Security - Denial-of-Service (DoS) - Tenant-Scoped
P4 - AI Application Security - Adversarial Example Injection - AI Misclassification Attacks
P5 - AI Application Security - Improper Input Handling - ANSI Escape Codes
P5 - AI Application Security - Improper Input Handling - Unicode Confusables
P5 - AI Application Security - Improper Input Handling - RTL Overrides

* Update vulnerability-rating-taxonomy.json

* Fixing errors

* Fixing errors2

* Update vulnerability-rating-taxonomy.json

* Update vulnerability-rating-taxonomy.json

* Update vulnerability-rating-taxonomy.json

* Update vulnerability-rating-taxonomy.json

* Update vulnerability-rating-taxonomy.json

* Update cvss_v3.json

* Fixed deprecated node mapping (#457)

* Updated varies to default and removed redundant entries (#461)

* Updated varies to default and removed redundant entries

* Reverting some changes

---------

Co-authored-by: Abhinav Nain <abhinav.nain@bugcrowd.com>

* Final Changes - Adding Changelog + deprecated-node-mappings + ALL JSON Sorting + SCW

---------

Co-authored-by: SamAtBugcrowd <100110742+SamAtBugcrowd@users.noreply.github.com>
Co-authored-by: Abhinav Nain <abhinav.nain@bugcrowd.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants