Skip to content

Commit 5a3daa9

Browse files
committed
JS: Add CWE tags for ML-powered queries
- Cross-site scripting: CWE-79 - Path injection: CWE-22, CWE-23, CWE-36, CWE-73, CWE-99 - NoSQL injection: CWE-943 - SQL injection: CWE-89
1 parent 0108642 commit 5a3daa9

File tree

4 files changed

+8
-0
lines changed

4 files changed

+8
-0
lines changed

javascript/ql/experimental/adaptivethreatmodeling/src/NosqlInjectionATM.ql

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@
1010
* @security-severity 8.8
1111
* @id js/ml-powered/nosql-injection
1212
* @tags experimental security
13+
* external/cwe/cwe-943
1314
*/
1415

1516
import ATM::ResultsInfo

javascript/ql/experimental/adaptivethreatmodeling/src/SqlInjectionATM.ql

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@
1010
* @security-severity 8.8
1111
* @id js/ml-powered/sql-injection
1212
* @tags experimental security
13+
* external/cwe/cwe-089
1314
*/
1415

1516
import experimental.adaptivethreatmodeling.SqlInjectionATM

javascript/ql/experimental/adaptivethreatmodeling/src/TaintedPathATM.ql

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,11 @@
1010
* @security-severity 7.5
1111
* @id js/ml-powered/path-injection
1212
* @tags experimental security
13+
* external/cwe/cwe-022
14+
* external/cwe/cwe-023
15+
* external/cwe/cwe-036
16+
* external/cwe/cwe-073
17+
* external/cwe/cwe-099
1318
*/
1419

1520
import ATM::ResultsInfo

javascript/ql/experimental/adaptivethreatmodeling/src/XssATM.ql

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@
1010
* @security-severity 6.1
1111
* @id js/ml-powered/xss
1212
* @tags experimental security
13+
* external/cwe/cwe-079
1314
*/
1415

1516
import javascript

0 commit comments

Comments
 (0)