diff --git a/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C5/explanation.md b/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C5/explanation.md index bfc5a1332..2688ba60d 100644 --- a/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C5/explanation.md +++ b/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C5/explanation.md @@ -20,15 +20,22 @@ This scenario is about exploiting trust for malicious gain, typically referred t ### What can go wrong? -Such manipulation can lead to significant breaches of user trust, unauthorized access to sensitive information, and exploitation of interconnected systems. Abuse of trust attacks include: Clickjacking, Phishing, Pharming, SSL downgrade/misconfiguration. +Such manipulation can lead to significant breaches of user trust, unauthorized access to sensitive information, and exploitation of interconnected systems. Abuse of trust attacks include: Clickjacking, Phishing, Pharming, SSL downgrade/misconfiguration, Session Hijacking, Cross-Site Request Forgery (CSRF) and Session Credential Falsification through Forging. For more things that can go wrong, see the [Common Attack Patterns related to this card](#mapping 'Common Attack Patterns related to this card [internal]') in the table below. ### What are we going to do about it? 1. Implement robust verification and authentication measures to prevent misuse of the application’s trusted status. -2. Educate users about the risks of phishing and other trust exploitation tactics. +2. Educate users about the risks of phishing and other trust exploitation tactics. 3. Monitor and control how the application’s APIs and services interact with other systems, ensuring secure and verified connections. 4. Establish strict guidelines and security protocols for third-party applications or services that integrate with the application. +5. Implement Content Security Policy (CSP) to mitigate clickjacking and other injection attacks. +6. Use secure cookies and implement anti-CSRF tokens to protect against session hijacking and CSRF attacks. +7. Implement session management best practices, including secure session identifiers and proper session expiration. +8. Enforce digital signatures and integrity checks for tokens and limit the scope and audience of their use. +9. Harden token exchange flows, limit the lifetime of tokens and enforce cryptographic proof of possession. +10. Regularly audit and update SSL/TLS configurations to prevent downgrade attacks. +11. Employ multi-factor authentication (MFA) to enhance user account security. For detailed advice on how to mitigate threats related to the card, see the [ASVS and OWASP Developer Guide requirements ](#mapping 'ASVS and OWASP Developer Guide requirements [internal]') in the table below. diff --git a/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C6/explanation.md b/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C6/explanation.md index 104060759..1a18f6632 100644 --- a/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C6/explanation.md +++ b/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C6/explanation.md @@ -8,9 +8,13 @@ Imagine a situation where Aaron exploits weaknesses in an application’s error 3. **Dependence on External Error Handling:** The application relies on other services or systems for its error management, creating gaps in control. +4. **Information Leakage through Errors:** Error messages reveal sensitive information that can be exploited. + +5. **Fallback to Insecure States:** In the event of an error, the application reverts to a less secure state, like unencrypted communication or default credentials, allowing Aaron to bypass normal controls. + ### Example -Aaron targets a web application that has incomplete error handling routines. He induces errors in the application which, due to inadequate or inconsistent handling, expose sensitive information or system functionalities. Additionally, since errors do not default to denying access or terminating execution, Aaron uses these error states to bypass normal application controls. In some cases, the application relies on external systems to handle errors, and Aaron exploits the delay or miscommunication between these systems to gain unauthorized access. +Aaron targets a web application that has incomplete error handling routines. He induces errors in the application which, due to inadequate or inconsistent handling, expose sensitive information or system functionalities. Additionally, since errors do not default to denying access or terminating execution, Aaron uses these error states to bypass normal application controls. In some cases, the application relies on external systems to handle errors, and Aaron exploits the delay or miscommunication between these systems to gain unauthorized access or to revert the application to a less secure state. ## Threat Modeling @@ -38,5 +42,6 @@ Ensure all forms of error are handled robustly and consistently (e.g. web server 4. Avoid relying solely on external systems for error handling; ensure that the application has robust internal mechanisms to deal with errors securely. The application should handle application errors and not rely on the server configuration. 5. Regularly review and test error handling routines to identify and address any weaknesses or inconsistencies. 6. Properly free allocated memory when error conditions occur. +7. Avoid fallback to insecure states in the event of an error, such as unencrypted communication or default credentials. For detailed advice on how to mitigate threats related to the card, see the [ASVS and OWASP Developer Guide requirements ](#mapping 'ASVS and OWASP Developer Guide requirements [internal]') in the table below. diff --git a/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C9/explanation.md b/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C9/explanation.md index 6c080fbd5..6ec05a8c3 100644 --- a/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C9/explanation.md +++ b/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/C9/explanation.md @@ -6,6 +6,8 @@ Consider a situation where Michael bypasses standard application protocols to ga 2. **Inadequate Access Controls for Administrative Interfaces:** The interfaces used for administrative purposes are easily accessible and lack stringent access restrictions. +3. **Weak Authentication Mechanisms:** The authentication processes for accessing administrative tools are missing or not strong enough, allowing unauthorized users to gain entry. + ### Example Michael discovers that a web application’s administrative interface is accessible through a common URL and is only protected by a weak password. Leveraging this, he gains access to the administrative panel where he can view, modify, and delete sensitive data. This unauthorized access is facilitated by the lack of multi-factor authentication, inadequate password policies, and the absence of monitoring mechanisms on the administrative interface. @@ -32,5 +34,6 @@ For more things that can go wrong, see the [Common Attack Patterns related to th 2. Enforce robust password policies and regular credential updates for system administrators. 3. Restrict access to administrative interfaces to a limited set of authorized IP addresses or networks. 4. Regularly audit and monitor activities performed through administrative tools to detect and respond to unauthorized access. +5. Ensure that administrative tools are not exposed to the public internet unless absolutely necessary, and if they are, implement additional security layers such as VPNs or bastion hosts. For detailed advice on how to mitigate threats related to the card, see the [ASVS and OWASP Developer Guide requirements ](#mapping 'ASVS and OWASP Developer Guide requirements [internal]') in the table below. diff --git a/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/CJ/explanation.md b/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/CJ/explanation.md index 798e5bf18..a940afcf6 100644 --- a/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/CJ/explanation.md +++ b/cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cornucopia/CJ/explanation.md @@ -1,3 +1,5 @@ +Roman can exploit the application because dangourous or risky compononents haven't been securely compiled or deployed, or its configuration is not secure by default, or security information was not documented, or passed on to operational teams, or the user is not warned or access blocked when the expected security features are not supported or enabled + ## Scenario: Roman’s Exploitation of Outdated Compilation and Configuration Lapses Envision a scenario where Roman takes advantage of vulnerabilities in an application caused by using outdated compilation tools, insecure default configurations, or a lack of documented security information for operational teams. These issues arise from: @@ -6,6 +8,8 @@ Envision a scenario where Roman takes advantage of vulnerabilities in an applica 2. **Insecure Default Configuration:** The application’s default configuration settings are not aligned with best security practices. +3. **Use of Dangerous or Risky Components:** The application includes components that are considered dangerous or risky, which have not been securely deployed and configured. + 3. **Lack of Security Documentation:** Essential security information and configurations are not properly documented or communicated to the operational teams responsible for maintaining the application. ### Example @@ -34,5 +38,6 @@ For more things that can go wrong, see the [Common Attack Patterns related to th 2. Configure the application with secure settings by default and regularly review these settings to align with evolving security standards. 3. Create comprehensive security documentation and ensure it is effectively communicated and accessible to all operational teams. 4. Conduct regular security audits and provide ongoing training to operational teams to keep them informed about security best practices and application-specific requirements. +5. Avoid using dangerous or risky components, and if their use is necessary, ensure they are securely deployed and configured. For detailed advice on how to mitigate threats related to the card, see the [ASVS and OWASP Developer Guide requirements ](#mapping 'ASVS and OWASP Developer Guide requirements [internal]') in the table below. diff --git a/source/webapp-cards-3.0-en.yaml b/source/webapp-cards-3.0-en.yaml index bac7666f4..1c41e1cfa 100644 --- a/source/webapp-cards-3.0-en.yaml +++ b/source/webapp-cards-3.0-en.yaml @@ -408,7 +408,7 @@ suits: id: "CJ" value: "J" url: "https://cornucopia.owasp.org/cards/CJ" - desc: "Roman can exploit the application because it was compiled using out-of-date tools, or its configuration is not secure by default, or security information was not documented, or passed on to operational teams, or the user is not warned or access blocked when the expected security features are not supported or enabled" + desc: "Roman can exploit the application because it was insecurely compiled or deployed, or its configuration is not secure by default, or because security information was not documented, or passed on to operational teams, or the user is not warned and access blocked when the expected security features are unsupported or disabled" - id: "CQ" value: "Q" diff --git a/source/webapp-mappings-2.2.yaml b/source/webapp-mappings-2.2.yaml index dbab5bc15..6dc55c669 100644 --- a/source/webapp-mappings-2.2.yaml +++ b/source/webapp-mappings-2.2.yaml @@ -1137,15 +1137,15 @@ suits: id: "C5" value: "5" url: "https://cornucopia.owasp.org/cards/C5" - stride: [ R ] + stride: [ S ] owasp_scp: [ "-" ] - stride_print: [ Repudiation ] + stride_print: [ Spoofing ] owasp_dev_guide: [ ] owasp_dev_guide_print: [ "-" ] owasp_asvs: [ 1.9.2, 5.1.5, 9.1.1, 9.2.1, 9.2.4 ] owasp_asvs_print: [ 1.9.2, 5.1.5, 9.1.1, 9.2.1, 9.2.4 ] owasp_appsensor: [ "-" ] - capec: [ 21, 22, 57, 89, 103, 181, 459 ] + capec: [ 21, 22, 57, 89, 103, 181, 473 ] safecode: [ "-" ] owasp_cre: owasp_asvs: [ 530-671, 232-217, 745-045, 430-636, 537-367 ] @@ -1162,7 +1162,7 @@ suits: owasp_asvs: [ 4.1.5, 7.1.4 ] owasp_asvs_print: [ 4.1.5, 7.1.4 ] owasp_appsensor: [ "-" ] - capec: [ 54, 98, 164, 172, 554 ] + capec: [ 54, 114, 217 ] safecode: [ 4, 11, 23 ] owasp_cre: owasp_asvs: [ 166-15, 555-048 ] @@ -1196,7 +1196,7 @@ suits: owasp_asvs: [ 1.4.5, 10.3.1, 10.3.2, 14.1.4, 14.1.5, 14.2.1, 14.2.2 ] owasp_asvs_print: [ 1.4.5, 10.3.1-2, 14.1.4-5, 14.2.1-2 ] owasp_appsensor: [ RE1, RE2 ] - capec: [ 37, 161, 169, 176, 220, 310, 536 ] + capec: [ 37, 121, 159, 169, 217, 220, 310, 446 ] safecode: [ "-" ] owasp_cre: owasp_asvs: [ 801-310, 154-031, 418-525, 208-355, 347-352, 715-334, 462-245 ] @@ -1213,7 +1213,7 @@ suits: owasp_asvs: [ 1.4.5, 4.3.1 ] owasp_asvs_print: [ 1.4.5, 4.3.1 ] owasp_appsensor: [ "-" ] - capec: [ 122, 169, 233 ] + capec: [ 1, 36, 49, 87, 121, 127, 169 ] safecode: [ "-" ] owasp_cre: owasp_asvs: [ 801-310, 201-246 ] @@ -1229,7 +1229,7 @@ suits: owasp_asvs: [ 1.14.3, 10.1.1, 10.2.3, 10.2.4, 10.2.5, 10.2.6, 14.2.1 ] owasp_asvs_print: [ 1.14.3, 10.1.1, 10.2.3-6, 14.2.1 ] owasp_appsensor: [ "-" ] - capec: [ 68, 310, 438, 439, 442, 443, 523, 524, 446, 538 ] + capec: [ 68, 159, 206, 442, 446, 523, 538, 673, 691 ] safecode: [ 15 ] owasp_cre: owasp_asvs: [ 053-751, 611-158, 838-636, 838-636, 418-525, 265-800, 715-334 ] @@ -1246,7 +1246,7 @@ suits: owasp_asvs: [ 1.14.3, 14.1.1, 14.1.2, 14.1.3, 14.1.4, 14.1.5, 14.2.1 ] owasp_asvs_print: [ 1.14.3, 14.1.1-5, 14.2.1 ] owasp_appsensor: [ "-" ] - capec: [ 445, 447 ] + capec: [ 70, 121, 127, 133, 176, 180, 191, 207 ] safecode: [ 4 ] owasp_cre: owasp_asvs: [ 053-751, 253-452, 314-131, 180-488, 208-355, 347-352, 715-334 ] @@ -1262,7 +1262,7 @@ suits: owasp_asvs: [ 8.1.4, 11.1.1-4 ] owasp_asvs_print: [ 8.1.4, 11.1.1-4 ] owasp_appsensor: [ (All) ] - capec: [ 212 ] + capec: [ 156, 268 ] safecode: [ 1, 27 ] owasp_cre: owasp_asvs: [ 176-154, 534-605, 456-535, 746-705, 630-573 ] @@ -1279,7 +1279,7 @@ suits: owasp_asvs_print: [ 2.2.1, 11.1.3-4 ] owasp_appsensor: [ UT1, UT2, UT3, UT4, STE3 ] owasp_appsensor_print: [ UT1-4, STE3 ] - capec: [ 2, 25, 125, 130, 212, 227, 469, 607 ] + capec: [ 2, 25, 100, 125, 130, 227, 469, 572, 607 ] safecode: [ 1 ] owasp_cre: owasp_asvs: [ 802-056, 746-705, 630-573 ] diff --git a/source/webapp-mappings-3.0.yaml b/source/webapp-mappings-3.0.yaml index ae942d292..1609d858f 100644 --- a/source/webapp-mappings-3.0.yaml +++ b/source/webapp-mappings-3.0.yaml @@ -20,8 +20,8 @@ suits: stride_print: [ 'Information Disclosure' ] owasp_dev_guide: [ SC1, SC2, SC3, SC4, SC8, SC9, SC10, SC11, SC12, SC13, FM1, FM2, FM5, EE6, EE7, EE8 ] owasp_dev_guide_print: [ SC1-4, SC8-13, FM1-2, FM5, EE6-8 ] - owasp_asvs: [ 2.4.1, 4.3.2, 13.2.2, 13.4.1, 13.4.2, 13.4.3, 13.4.4, 13.4.5, 13.4.6, 13.4.7, 15.2.3, 16.2.5, 16.4.2, 16.5.1, 17.1.1 ] - owasp_asvs_print: [ 2.4.1, 4.3.2, 13.2.2, 13.4.1-7, 15.2.3, 16.2.5, 16.4.2, 16.5.1, 17.1.1 ] + owasp_asvs: [ 2.4.1, 4.3.2, 13.2.2, 13.4.1, 13.4.2, 13.4.3, 13.4.4, 13.4.5, 13.4.6, 13.4.7, 15.2.3, 16.2.5, 16.3.4, 16.4.2, 16.5.1, 17.1.1 ] + owasp_asvs_print: [ 2.4.1, 4.3.2, 13.2.2, 13.4.1-7, 15.2.3, 16.2.5, 16.3.4, 16.4.2, 16.5.1, 17.1.1 ] capec: [ 54, 113, 116, 143, 144, 149, 150, 155, 169, 215, 224, 497, 541, 546 ] capec_map: 54: @@ -39,7 +39,7 @@ suits: 155: owasp_asvs: [ 13.2.2, 13.4.1, 13.4.3, 13.4.7, 15.2.3 ] 169: - owasp_asvs: [ 4.3.2, 13.2.2, 13.4.1, 13.4.2, 13.4.3, 13.4.4, 13.4.5, 13.4.6, 13.4.7, 15.2.3, 16.2.5, 16.4.2, 16.5.1, 17.1.1 ] + owasp_asvs: [ 4.3.2, 13.2.2, 13.4.1, 13.4.2, 13.4.3, 13.4.4, 13.4.5, 13.4.6, 13.4.7, 15.2.3, 16.2.5, 16.3.4, 16.4.2, 16.5.1, 17.1.1 ] 215: owasp_asvs: [ 2.4.1, 13.2.2, 13.4.2, 13.4.6, 16.2.5, 16.4.2, 16.5.1 ] 224: @@ -61,42 +61,42 @@ suits: stride_print: [ Tampering ] owasp_dev_guide: [ CEC5, CEC8, SSV2, SSV6, SSV7, SSV8, SSV9, SSV10, LF3, LF4, LF5, FV7, FV8 ] owasp_dev_guide_print: [ CEC5, CEC8, SSV2, SSV6-10, LF3-5, FV7-8 ] - owasp_asvs: [ 1.1.1, 1.2.2, 1.2.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, '1.3.10', 1.3.11, 1.3.12, 1.4.2, 1.5.3, 2.1.1, 2.2.1, 2.2.2, 3.2.3, 4.1.1, 4.1.4, 4.2.1, 4.2.2, 4.2.3, 4.2.4, 4.2.5, 5.2.1, 5.2.2, 5.2.3, 5.2.4, 5.2.5, 5.2.6, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 15.3.3, 15.3.4, 15.3.5, 15.3.6, 15.3.7, 16.5.1 ] - owasp_asvs_print: [ 1.1.1, 1.2.1-3, 1.3.1-12, 1.4.2, 1.5.3, 2.1.1, 2.2.1-2, 3.2.3, 3.5.3, 3.5.5, 4.1.1, 4.1.4, 4.2.1-5, 5.1.1, 5.2.1-6, 5.3.1-3, 5.4.1-2, 15.3.3, 15.3.5-7, 16.5.1 ] + owasp_asvs: [ 1.1.1, 1.2.2, 1.2.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, '1.3.10', 1.3.11, 1.3.12, 1.4.2, 1.5.3, 2.1.1, 2.2.1, 2.2.2, 3.2.3, 4.1.1, 4.1.4, 4.2.1, 4.2.2, 4.2.3, 4.2.4, 4.2.5, 5.2.1, 5.2.2, 5.2.3, 5.2.4, 5.2.5, 5.2.6, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 15.3.3, 15.3.4, 15.3.5, 15.3.6, 15.3.7, 16.3.3, 16.3.4, 16.5.1 ] + owasp_asvs_print: [ 1.1.1, 1.2.1-3, 1.3.1-12, 1.4.2, 1.5.3, 2.1.1, 2.2.1-2, 3.2.3, 3.5.3, 3.5.5, 4.1.1, 4.1.4, 4.2.1-5, 5.1.1, 5.2.1-6, 5.3.1-3, 5.4.1-2, 15.3.3, 15.3.5-7, 16.3.3-4, 16.5.1 ] capec: [ 28, 33, 39, 48, 64, 105, 126, 152, 153, 165, 175, 220, 231, 261, 272, 586 ] capec_map: 28: - owasp_asvs: [ 1.2.2, 1.3.1, 1.3.3, 1.3.7, '1.3.10', 1.3.12, 1.4.2, 2.1.1, 2.2.1, 2.2.2, 4.1.4, 4.2.4, 4.2.5, 15.3.3, 15.3.4, 15.3.5, 15.3.6, 15.3.7, 16.5.1 ] + owasp_asvs: [ 1.2.2, 1.3.1, 1.3.3, 1.3.7, '1.3.10', 1.3.12, 1.4.2, 2.1.1, 2.2.1, 2.2.2, 4.1.4, 4.2.4, 4.2.5, 15.3.3, 15.3.4, 15.3.5, 15.3.6, 15.3.7, 16.3.3, 16.5.1 ] 33: - owasp_asvs: [ 4.2.1, 4.2.2, 4.2.3, 4.2.4 ] + owasp_asvs: [ 4.2.1, 4.2.2, 4.2.3, 4.2.4, 16.3.3, 16.3.4 ] 39: - owasp_asvs: [ 15.3.7 ] + owasp_asvs: [ 15.3.7, 16.3.3, 16.3.4 ] 48: - owasp_asvs: [ 1.5.3, 2.1.1, 2.2.1, 2.2.2, 5.3.2, 5.3.3, 5.4.1, 5.4.2 ] + owasp_asvs: [ 1.5.3, 2.1.1, 2.2.1, 2.2.2, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 16.3.3 ] 64: - owasp_asvs: [ 1.2.2, 1.5.3, 5.4.1, 5.4.2 ] + owasp_asvs: [ 1.2.2, 1.5.3, 5.4.1, 5.4.2, 16.3.3 ] 105: - owasp_asvs: [ 4.2.1, 4.2.2, 4.2.3, 4.2.4 ] + owasp_asvs: [ 4.2.1, 4.2.2, 4.2.3, 4.2.4, 16.3.3, 16.3.4 ] 126: - owasp_asvs: [ 1.1.1, 1.5.3, 2.1.1, 2.2.1, 2.2.2, 5.3.2, 5.3.3, 5.4.1, 5.4.2 ] + owasp_asvs: [ 1.1.1, 1.5.3, 2.1.1, 2.2.1, 2.2.2, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 16.3.3 ] 152: - owasp_asvs: [ 1.2.1, 1.2.2, 1.2.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, '1.3.10', 1.3.11, 1.5.3, 2.1.1, 2.2.1, 2.2.2, 3.2.3, 5.4.1, 5.4.2, 15.3.5, 15.3.6, 16.5.1 ] + owasp_asvs: [ 1.2.1, 1.2.2, 1.2.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, '1.3.10', 1.3.11, 1.5.3, 2.1.1, 2.2.1, 2.2.2, 3.2.3, 5.4.1, 5.4.2, 15.3.5, 15.3.6, 16.3.3, 16.5.1 ] 153: - owasp_asvs: [ 1.1.1, 1.2.1, 1.2.2, 1.4.2, 1.5.3, 2.1.1, 2.2.1, 2.2.2, 4.1.1, 5.2.5, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 15.3.5, 15.3.6, 16.5.1 ] + owasp_asvs: [ 1.1.1, 1.2.1, 1.2.2, 1.4.2, 1.5.3, 2.1.1, 2.2.1, 2.2.2, 4.1.1, 5.2.5, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 15.3.5, 15.3.6, 16.3.3, 16.5.1 ] 165: - owasp_asvs: [ 1.5.3, 2.1.1, 2.2.1, 2.2.2, 3.2.1, 5.2.1, 5.2.2, 5.2.3, 5.2.4, 5.2.5, 5.2.6, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2 ] + owasp_asvs: [ 1.5.3, 2.1.1, 2.2.1, 2.2.2, 3.2.1, 5.2.1, 5.2.2, 5.2.3, 5.2.4, 5.2.5, 5.2.6, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 16.3.3 ] 175: - owasp_asvs: [ 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, '1.3.10', 1.3.11, 1.5.3, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 16.5.1 ] + owasp_asvs: [ 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, '1.3.10', 1.3.11, 1.5.3, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 16.3.3, 16.5.1 ] 220: - owasp_asvs: [ 4.2.1, 4.2.2, 4.2.3, 4.2.4 ] + owasp_asvs: [ 4.2.1, 4.2.2, 4.2.3, 4.2.4, 16.3.3, 16.3.4 ] 231: - owasp_asvs: [ 1.3.1, 1.3.3, 1.3.4, 1.3.5, 1.3.12, 1.5.2 ] + owasp_asvs: [ 1.3.1, 1.3.3, 1.3.4, 1.3.5, 1.3.12, 1.5.2, 16.3.3 ] 261: - owasp_asvs: [ 15.3.3, 15.3.7, 16.5.1 ] + owasp_asvs: [ 15.3.3, 15.3.7, 16.3.3, 16.5.1 ] 272: - owasp_asvs: [ 1.2.2, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, '1.3.10', 1.3.11, 1.3.12, 1.4.2, 1.5.3, 2.1.1, 2.2.1, 2.2.2, 4.1.1, 4.1.4, 4.2.1, 4.2.2, 4.2.3, 4.2.4, 5.4.1 ] + owasp_asvs: [ 1.2.2, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, '1.3.10', 1.3.11, 1.3.12, 1.4.2, 1.5.3, 2.1.1, 2.2.1, 2.2.2, 4.1.1, 4.1.4, 4.2.1, 4.2.2, 4.2.3, 4.2.4, 5.4.1, 16.3.3 ] 586: - owasp_asvs: [ 1.2.2, 1.3.2, 1.3.8, 2.1.1, 2.2.1, 2.2.2, 5.4.1, 5.4.2 ] + owasp_asvs: [ 1.2.2, 1.3.2, 1.3.8, 2.1.1, 2.2.1, 2.2.2, 5.4.1, 5.4.2, 16.3.3 ] safecode: [ 3, 16, 24, 35 ] owasp_cre: owasp_asvs: [ 848-711, 743-237, '042-550', '031-447', 532-878, 314-131, '036-725' ] @@ -108,26 +108,26 @@ suits: stride_print: [ Tampering] owasp_dev_guide: [ SSV2, SSV7, FV2, AC14, AC15 ] owasp_dev_guide_print: [ SSV2, SSV7, FV2, AC14-15 ] - owasp_asvs: [ 2.1.1, 2.1.2, 2.1.3, 2.2.1, 2.2.2, 2.2.3, 2.3.1, 2.3.2, 2.3.3, 15.3.3, 15.3.4, 15.3.5, 15.3.6, 15.3.7, 16.5.1 ] - owasp_asvs_print: [ 2.1.1-3, 2.2.1-3, 2.3.1-3, 15.3.3-7 ] + owasp_asvs: [ 2.1.1, 2.1.2, 2.1.3, 2.2.1, 2.2.2, 2.2.3, 2.3.1, 2.3.2, 2.3.3, 15.3.3, 15.3.4, 15.3.5, 15.3.6, 15.3.7, 16.3.3, 16.5.1 ] + owasp_asvs_print: [ 2.1.1-3, 2.2.1-3, 2.3.1-3, 15.3.3-7, 16.3.3, 16.5.1 ] capec: [ 28, 39, 113, 137, 140, 162 ] capec_map: 28: - owasp_asvs: [ 2.1.1, 2.1.2, 2.1.3, 2.2.1, 2.2.2, 2.2.3, 2.3.1, 2.3.2, 15.3.3, 15.3.4, 15.3.5, 15.3.6, 15.3.7, 16.5.1 ] + owasp_asvs: [ 2.1.1, 2.1.2, 2.1.3, 2.2.1, 2.2.2, 2.2.3, 2.3.1, 2.3.2, 15.3.3, 15.3.4, 15.3.5, 15.3.6, 15.3.7, 16.3.3, 16.5.1 ] 39: - owasp_asvs: [ 15.3.7 ] + owasp_asvs: [ 15.3.7, 16.3.3 ] 43: - owasp_asvs: [ 2.1.1, 2.1.3, 2.1.1, 2.2.1, 2.2.2, 2.3.2, 2.3.3, 16.5.1 ] + owasp_asvs: [ 2.1.1, 2.1.3, 2.1.1, 2.2.1, 2.2.2, 2.3.2, 2.3.3, 16.3.3, 16.5.1 ] 77: - owasp_asvs: [ 2.1.1, 2.1.3, 2.2.1, 2.2.2, 2.3.2, 2.3.3 ] + owasp_asvs: [ 2.1.1, 2.1.3, 2.2.1, 2.2.2, 2.3.2, 2.3.3, 16.3.3 ] 113: - owasp_asvs: [ 2.1.1, 2.2.1, 2.2.2, 2.2.3, 2.3.1, 2.3.2, 2.3.3, 15.3.3, 15.3.4, 15.3.5 15.3.6, 15.3.7 ] + owasp_asvs: [ 2.1.1, 2.2.1, 2.2.2, 2.2.3, 2.3.1, 2.3.2, 2.3.3, 15.3.3, 15.3.4, 15.3.5 15.3.6, 16.3.3, 15.3.7 ] 137: - owasp_asvs: [ 15.3.3, 15.3.4, 15.3.5, 15.3.6, 15.3.7 ] + owasp_asvs: [ 15.3.3, 15.3.4, 15.3.5, 15.3.6, 15.3.7, 16.3.3 ] 140: - owasp_asvs: [ 2.1.1, 2.2.1, 2.2.2, 2.2.3, 2.3.1, 2.3.2, 2.3.3 ] + owasp_asvs: [ 2.1.1, 2.2.1, 2.2.2, 2.2.3, 2.3.1, 2.3.2, 2.3.3, 16.3.3 ] 162: - owasp_asvs: [ 2.2.2, 15.3.3, 15.3.7 ] + owasp_asvs: [ 2.2.2, 15.3.3, 15.3.7, 16.3.3 ] safecode: [ 24, 35 ] owasp_cre: owasp_asvs: [ 304-667, 743-237, '042-550', 534-605, 456-535 ] @@ -285,20 +285,20 @@ suits: stride_print: [ Tampering ] owasp_dev_guide: [ SQ3, SQ4, CEC7, CEC8, COE2, SSV9 ] owasp_dev_guide_print: [ SQ3, SQ4, CEC7-8, COE2, SSV9 ] - owasp_asvs: [ 16.5.1, 16.5.2, 16.5.3, 16.5.4 ] - owasp_asvs_print: [ 16.5.1-4 ] + owasp_asvs: [ 16.3.3, 16.5.1, 16.5.2, 16.5.3, 16.5.4 ] + owasp_asvs_print: [ 16.3.3, 16.5.1-4 ] capec: [ 24, 28, 152, 153, 198 ] capec_map: 24: - owasp_asvs: [16.5.1, 16.5.2, 16.5.3, 16.5.4 ] + owasp_asvs: [ 16.3.3, 16.5.1, 16.5.2, 16.5.3, 16.5.4 ] 28: - owasp_asvs: [ 16.5.1 ] + owasp_asvs: [ 16.3.3, 16.5.1 ] 152: - owasp_asvs: [ 16.5.1, 16.5.3 ] + owasp_asvs: [ 16.3.3, 16.5.1, 16.5.3 ] 153: - owasp_asvs: [ 16.5.1, 16.5.3 ] + owasp_asvs: [ 16.3.3, 16.5.1, 16.5.3 ] 198: - owasp_asvs: [ 16.5.1 ] + owasp_asvs: [ 16.3.3, 16.5.1 ] safecode: [ 3, 16, 24 ] owasp_cre: owasp_asvs: [ 184-284 ] @@ -382,8 +382,8 @@ suits: stride_print: [ Tampering ] owasp_dev_guide: [ CEC5, CEC6, COE1, SSV7, LF3, LF4 ] owasp_dev_guide_print: [ CEC5-6, COE1, SSV7, LF3-4 ] - owasp_asvs: [ 1.1.1, 1.2.1, 1.2.2, 1.2.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 2.1.1, 3.1.1, 3.2.1, 3.2.2, 3.2.3, 3.4.3, 3.4.4, 3.4.6, 3.4.7, 3.4.8, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.6.1, 3.7.1, 3.7.5, 4.1.1, 15.3.5, 15.3.6 ] - owasp_asvs_print: [ 1.2.1-3, 1.3.1-7, 3.1.1, 3.2.1-3, 3.4.3, 3.4.6-8, 3.5.4-8, 3.6.1, 3.7.1, 3.7.5, 4.1.1, 15.3.5-6 ] + owasp_asvs: [ 1.1.1, 1.2.1, 1.2.2, 1.2.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 2.1.1, 3.1.1, 3.2.1, 3.2.2, 3.2.3, 3.4.3, 3.4.4, 3.4.6, 3.4.7, 3.4.8, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.6.1, 3.7.1, 3.7.5, 4.1.1, 15.3.5, 15.3.6, 16.3.3 ] + owasp_asvs_print: [ 1.2.1-3, 1.3.1-7, 3.1.1, 3.2.1-3, 3.4.3, 3.4.6-8, 3.5.4-8, 3.6.1, 3.7.1, 3.7.5, 4.1.1, 15.3.5-6, 16.3.3 ] capec: [ 19, 63, 104, 152, 160, 182, 267 ] capec_map: 19: @@ -393,13 +393,13 @@ suits: 104: owasp_asvs: [ 3.1.1, 3.4.3, 3.4.6, 3.4.7, 3.4.8, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.6.1 ] 152: - owasp_asvs: [ 1.2.1, 1.2.2, 1.2.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 3.1.1, 3.2.1, 3.2.2, 3.2.3, 3.4.3, 3.4.4, 3.4.6, 3.4.7, 3.4.8, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.6.1, 3.7.5, 4.1.1 ] + owasp_asvs: [ 1.2.1, 1.2.2, 1.2.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 3.1.1, 3.2.1, 3.2.2, 3.2.3, 3.4.3, 3.4.4, 3.4.6, 3.4.7, 3.4.8, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.6.1, 3.7.5, 4.1.1, 16.3.3 ] 160: owasp_asvs: [ 1.1.1, 1.2.1, 1.2.2, 1.2.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 2.1.1, 2.2.1, 3.2.1, 3.2.2, 3.2.3, 3.4.3, 3.4.6, 3.4.7, 3.4.8, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.6.1, 3.7.5, 4.1.1, 15.3.5, 15.3.6 ] 182: owasp_asvs: [ 1.7.1 ] 267: - owasp_asvs: [ 1.1.1, 1.2.1, 1.2.2, 1.2.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 2.1.1, 2.2.1, 3.2.3, 3.6.1, 15.3.5, 15.3.6 ] + owasp_asvs: [ 1.1.1, 1.2.1, 1.2.2, 1.2.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 2.1.1, 2.2.1, 3.2.3, 3.6.1, 15.3.5, 15.3.6, 16.3.3 ] safecode: [ 2, 17 ] owasp_cre: owasp_asvs: [ 542-445, 422-005, 366-835, 387-848 ] @@ -416,45 +416,45 @@ suits: capec: [ 19, 23, 28, 66, 83, 88, 93, 126, 136, 137, 153, 160, 175, 183, 250, 253, 261, 664, 676 ] capec_map: 19: - owasp_asvs: [ 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.11, 1.5.1, 1.5.2, 1.5.3, 2.1.1, 2.1.2, 2.1.3, 2.2.1, 2.2.2, 2.2.3, 5.3.1, 5.3.2, 5.3.3, 15.3.2, 15.3.3, 15.3.5, 15.3.6, 15.3.7, 16.5.1 ] + owasp_asvs: [ 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.11, 1.5.1, 1.5.2, 1.5.3, 2.1.1, 2.1.2, 2.1.3, 2.2.1, 2.2.2, 2.2.3, 5.3.1, 5.3.2, 5.3.3, 15.3.2, 15.3.3, 15.3.5, 15.3.6, 15.3.7, 16.3.3, 16.3.4, 16.5.1 ] 23: - owasp_asvs: [ 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.5.1, 1.5.3, 5.1.1, 5.2.2, 5.2.3, 5.2.5, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 5.4.3, 16.5.1 ] + owasp_asvs: [ 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.5.1, 1.5.3, 5.1.1, 5.2.2, 5.2.3, 5.2.5, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 5.4.3, 16.3.3, 16.3.4, 16.5.1 ] 28: - owasp_asvs: [ 15.3.1, 15.3.2, 15.3.3, 15.3.5, 15.3.6, 15.3.7, 16.5.1 ] + owasp_asvs: [ 15.3.1, 15.3.2, 15.3.3, 15.3.5, 15.3.6, 15.3.7, 16.3.3, 16.5.1 ] 66: - owasp_asvs: [ 1.2.4, 1.5.1, 1.5.3, 5.1.1, 5.2.2, 5.2.3, 5.2.5, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 5.4.3, 16.5.1 ] + owasp_asvs: [ 1.2.4, 1.5.1, 1.5.3, 5.1.1, 5.2.2, 5.2.3, 5.2.5, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 5.4.3, 16.3.3, 16.3.4, 16.5.1 ] 83: - owasp_asvs: [ 1.2.7, 16.5.1 ] + owasp_asvs: [ 1.2.7, 16.3.3, 16.3.4, 16.5.1 ] 88: - owasp_asvs: [ 1.2.5, '1.3.10', 16.5.1 ] + owasp_asvs: [ 1.2.5, '1.3.10', 16.3.3, 16.4.1, 16.5.1 ] 93: - owasp_asvs: [ 16.4.1, 16.5.1 ] + owasp_asvs: [ 16.3.3, 16.4.1, 16.5.1 ] 126: - owasp_asvs: [ 1.3.3, 1.5.3, 5.1.1, 5.2.1, 5.2.2, 5.2.3, 5.2.5, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 5.4.3, 16.5.1 ] + owasp_asvs: [ 1.3.3, 1.5.3, 5.1.1, 5.2.1, 5.2.2, 5.2.3, 5.2.5, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 5.4.3, 16.3.3, 16.5.1 ] 136: - owasp_asvs: [ 1.2.6, 16.5.1 ] + owasp_asvs: [ 1.2.6, 16.5.1, 16.3.3, 16.3.4 ] 137: - owasp_asvs: [ 1.2.2, '1.3.10', 2.1.1, 2.1.2, 2.1.3, 2.2.1, 2.2.2, 2.2.3, 5.4.1, 15.3.1, 15.3.2, 15.3.3, 15.3.5, 15.3.6, 15.3.7, 16.5.1 ] + owasp_asvs: [ 1.2.2, '1.3.10', 2.1.1, 2.1.2, 2.1.3, 2.2.1, 2.2.2, 2.2.3, 5.4.1, 15.3.1, 15.3.2, 15.3.3, 15.3.5, 15.3.6, 15.3.7, 16.3.3, 16.5.1 ] 153: - owasp_asvs: [ 1.1.1, 1.1.2, 1.2.2, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, '1.2.10', 16.4.1, 16.5.1 ] + owasp_asvs: [ 1.1.1, 1.1.2, 1.2.2, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, '1.2.10', 16.3.3, 16.4.1, 16.5.1 ] 160: - owasp_asvs: [ 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, '1.3.10', 1.3.11, 16.5.1 ] + owasp_asvs: [ 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, '1.3.10', 1.3.11, 16.3.3, 16.3.4, 16.5.1 ] 175: - owasp_asvs: [ 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, '1.3.10', 1.3.11, 1.5.3, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 5.4.3, 16.5.1 ] + owasp_asvs: [ 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, '1.3.10', 1.3.11, 1.5.3, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.3.3, 5.4.1, 5.4.2, 5.4.3, 16.3.3, 16.3.4, 16.5.1 ] 183: - owasp_asvs: [ 1.3.11, 16.5.1 ] + owasp_asvs: [ 1.3.11, 16.3.3, 16.3.4, 16.5.1 ] 201: - owasp_asvs: [ 1.3.6, 1.3.8, 1.5.1, 1.5.3 ] + owasp_asvs: [ 1.3.6, 1.3.8, 1.5.1, 1.5.3, 16.3.3, 16.3.4 ] 250: - owasp_asvs: [ 1.2.7, 1.3.5, 1.5.1, 1.5.2, 1.5.3, 16.5.1 ] + owasp_asvs: [ 1.2.7, 1.3.5, 1.5.1, 1.5.2, 1.5.3, 16.3.3, 16.3.4, 16.5.1 ] 253: - owasp_asvs: [ 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, '1.3.10', 1.3.11, 1.5.3, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.3.3, 5.4.3, 16.5.1 ] + owasp_asvs: [ 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, '1.3.10', 1.3.11, 1.5.3, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.3.3, 5.4.3, 16.3.3, 16.3.4, 16.5.1 ] 261: - owasp_asvs: [ 15.3.1, 15.3.2, 15.3.3, 15.3.5, 15.3.6, 15.3.7, 16.5.1 ] + owasp_asvs: [ 15.3.1, 15.3.2, 15.3.3, 15.3.5, 15.3.6, 15.3.7, 16.3.3, 16.5.1 ] 664: - owasp_asvs: [ 1.3.6, 1.5.3, 5.3.2, 16.5.1 ] + owasp_asvs: [ 1.3.6, 1.5.3, 5.3.2, 16.3.3, 16.3.4, 16.5.1 ] 676: - owasp_asvs: [ 1.2.4, 16.5.1 ] + owasp_asvs: [ 1.2.4, 16.3.3, 16.5.1 ] safecode: [ 2, 19, 20 ] owasp_cre: owasp_asvs: [ 542-445, 538-446, 732-873, 531-558, 857-718, 547-283, 134-207 ] @@ -614,14 +614,14 @@ suits: stride_print: [ Spoofing ] owasp_dev_guide: [ A4, A12, A18, A19, A20, A21, P4, ACM1 ] owasp_dev_guide_print: [ A4, A12, A18-21, P4, ACM1 ] - owasp_asvs: [ 6.1.1, 6.1.2, 6.2.1, 6.2.2, 6.2.4, 6.2.5, 6.2.8, 6.2.9, '6.2.10', 6.2.11, 6.2.12, 6.3.1, 6.3.2, 6.3.3, 6.3.5, 6.3.8, 6.4.1, 6.4.2, 6.4.3, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.6.3, 6.6.4, 16.3.3 ] - owasp_asvs_print: [ 6.1.1, 6.2.1-2, 6.2.4-5, 6.2.8-12, 6.3.1-3, 6.3.5, 6.3.8, 6.4.1-3, 6.5.1-5, 6.6.3-4, 16.3.3 ] + owasp_asvs: [ 6.1.1, 6.1.2, 6.2.1, 6.2.2, 6.2.4, 6.2.5, 6.2.8, 6.2.9, '6.2.10', 6.2.11, 6.2.12, 6.3.1, 6.3.2, 6.3.3, 6.3.5, 6.3.8, 6.4.1, 6.4.2, 6.4.3, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.6.3, 6.6.4, 16.3.1, 16.3.3 ] + owasp_asvs_print: [ 6.1.1, 6.2.1-2, 6.2.4-5, 6.2.8-12, 6.3.1-3, 6.3.5, 6.3.8, 6.4.1-3, 6.5.1-5, 6.6.3-4, 16.3.1, 16.3.3 ] capec: [ 2, 49 ] capec_map: 2: - owasp_asvs: [ 6.1.1, 6.3.1, 6.3.8, 16.3.3 ] + owasp_asvs: [ 6.1.1, 6.3.1, 6.3.8, 16.3.1, 16.3.3 ] 49: - owasp_asvs: [ 6.1.1, 6.1.2, 6.2.1, 6.2.4, 6.2.5, 6.2.8, 6.2.9, '6.2.10', 6.2.11, 6.2.12, 6.3.1, 6.3.2, 6.3.3, 6.3.5, 6.3.8, 6.4.1, 6.4.2, 6.4.3, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.6.3, 6.6.4, 16.3.3 ] + owasp_asvs: [ 6.1.1, 6.1.2, 6.2.1, 6.2.4, 6.2.5, 6.2.8, 6.2.9, '6.2.10', 6.2.11, 6.2.12, 6.3.1, 6.3.2, 6.3.3, 6.3.5, 6.3.8, 6.4.1, 6.4.2, 6.4.3, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.6.3, 6.6.4, 16.3.1, 16.3.3 ] safecode: [ 27 ] owasp_cre: owasp_asvs: [ 158-874, 576-651, 338-370, 802-056 ] @@ -737,26 +737,26 @@ suits: stride_print: [ Tampering ] owasp_dev_guide: [ A3 ] owasp_dev_guide_print: [ A3 ] - owasp_asvs: [ 5.4.3, 7.2.1, 10.1.1, 10.1.2, 10.2.1, 13.2.1, 13.2.3, 13.3.1, 13.3.2, 13.3.3, 13.3.4, 15.1.1, 15.1.2, 15.2.4, 15.2.5, 16.3.3, 16.5.3 ] - owasp_asvs_print: [ 5.4.3, 7.2.1, 10.1.1-2, 10.2.1, 13.2.1, 13.2.3, 13.3.1, 13.3.1-4, 15.1.1-2, 15.2.4-5, 16.3.3, 16.5.3 ] + owasp_asvs: [ 5.4.3, 7.2.1, 10.1.1, 10.1.2, 10.2.1, 13.2.1, 13.2.3, 13.3.1, 13.3.2, 13.3.3, 13.3.4, 15.1.1, 15.1.2, 15.2.4, 15.2.5, 16.3.3, 16.3.4, 16.5.3 ] + owasp_asvs_print: [ 5.4.3, 7.2.1, 10.1.1-2, 10.2.1, 13.2.1, 13.2.3, 13.3.1, 13.3.1-4, 15.1.1-2, 15.2.4-5, 16.3.3-4, 16.5.3 ] capec: [ 115, 207, 443, 445, 446, 461, 511, 523, 554 ] capec_map: 115: - owasp_asvs: [ 7.2.1, 10.1.1, 10.1.2, 10.2.1, 13.2.1, 13.2.3, 15.2.4, 16.3.3, 16.5.3 ] + owasp_asvs: [ 7.2.1, 10.1.1, 10.1.2, 10.2.1, 13.2.1, 13.2.3, 15.2.4, 16.3.3, 16.5.3 ] 207: owasp_asvs: [ 7.2.1, 10.1.1 ] 443: owasp_asvs: [ 15.2.4, 15.2.5 ] 445: - owasp_asvs: [ 15.1.1, 15.1.2, 13.2.3, 13.3.1, 13.3.2, 13.3.3, 13.3.4, 15.2.4, 15.2.5 ] + owasp_asvs: [ 15.1.1, 15.1.2, 13.2.3, 13.3.1, 13.3.2, 13.3.3, 13.3.4, 15.2.4, 15.2.5, 16.3.4 ] 446: - owasp_asvs: [ 15.1.1, 15.1.2, 15.2.4, 15.2.5 ] + owasp_asvs: [ 15.1.1, 15.1.2, 15.2.4, 15.2.5, 16.3.4 ] 461: - owasp_asvs: [ 16.3.3, 16.5.3 ] + owasp_asvs: [ 16.3.3, 16.3.4, 16.5.3 ] 511: - owasp_asvs: [ 13.3.1, 13.3.2, 13.3.3, 13.3.4, 15.1.1, 15.1.2, 15.2.4, 15.2.5 ] + owasp_asvs: [ 13.3.1, 13.3.2, 13.3.3, 13.3.4, 15.1.1, 15.1.2, 15.2.4, 15.2.5, 16.3.4 ] 523: - owasp_asvs: [ 5.4.3, 15.1.1, 15.1.2, 15.2.4, 15.2.5 ] + owasp_asvs: [ 5.4.3, 15.1.1, 15.1.2, 15.2.4, 15.2.5, 16.3.4 ] 554: owasp_asvs: [ 7.2.1, 10.1.1, 10.1.2, 10.2.1, 13.2.1, 13.2.3, 13.3.1, 13.3.2, 13.3.3, 13.3.4, 15.1.1, 15.1.2, 15.2.4, 15.2.5, 16.3.3, 16.5.3 ] safecode: [ 14, 28 ] @@ -1028,14 +1028,14 @@ suits: stride_print: [ Spoofing ] owasp_dev_guide: [ SM1, SM2, SM3 ] owasp_dev_guide_print: [ SM1-3 ] - owasp_asvs: [ 4.4.3, 7.2.1, 7.2.2, 10.1.1, 10.1.2, 10.2.1, 10.2.2, 10.2.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.4.6, 10.4.7, 10.4.8, 10.4.9, 10.4.10, 10.4.11, 10.4.12, 10.4.13, 10.4.14, 10.4.15, 10.4.16, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, 10.6.1, 10.6.2, 10.7.1, 10.7.2, 10.7.3, 13.2.1 ] - owasp_asvs_print: [ 4.4.3, 7.2.1-2, 10.1.1-2, 10.2.1-3, 10.3.1-5, 10.4.1-16, 10.5.1-5, 10.6.1-2, 10.7.1-3, 13.2.1 ] + owasp_asvs: [ 4.4.3, 7.2.1, 7.2.2, 10.1.1, 10.1.2, 10.2.1, 10.2.2, 10.2.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.4.6, 10.4.7, 10.4.8, 10.4.9, 10.4.10, 10.4.11, 10.4.12, 10.4.13, 10.4.14, 10.4.15, 10.4.16, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, 10.6.1, 10.6.2, 10.7.1, 10.7.2, 10.7.3, 13.2.1, 16.3.3, 16.3.4 ] + owasp_asvs_print: [ 4.4.3, 7.2.1-2, 10.1.1-2, 10.2.1-3, 10.3.1-5, 10.4.1-16, 10.5.1-5, 10.6.1-2, 10.7.1-3, 13.2.1, 16.3.3-4 ] capec: [ 21, 633 ] capec_map: 21: - owasp_asvs: [ 4.4.3, 7.2.1, 7.2.2, 13.2.1 ] + owasp_asvs: [ 4.4.3, 7.2.1, 7.2.2, 13.2.1, 16.3.3, 16.3.4 ] 633: - owasp_asvs: [ 4.4.3, 10.1.1, 10.1.2, 10.2.1, 10.2.2, 10.2.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.4.6, 10.4.7, 10.4.8, 10.4.9, 10.4.10, 10.4.11, 10.4.12, 10.4.13, 10.4.14, 10.4.15, 10.4.16, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, 10.6.1, 10.6.2, 10.7.1, 10.7.2, 10.7.3, 13.2.1 ] + owasp_asvs: [ 4.4.3, 10.1.1, 10.1.2, 10.2.1, 10.2.2, 10.2.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.4.6, 10.4.7, 10.4.8, 10.4.9, 10.4.10, 10.4.11, 10.4.12, 10.4.13, 10.4.14, 10.4.15, 10.4.16, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, 10.6.1, 10.6.2, 10.7.1, 10.7.2, 10.7.3, 13.2.1, 16.3.3, 16.3.4 ] safecode: [ 14, 28 ] owasp_cre: owasp_asvs: [ 344-611 ] @@ -1124,12 +1124,12 @@ suits: stride_print: [ 'Elevation of Privilege' ] owasp_dev_guide: [ AC3, AC10, AC11 ] owasp_dev_guide_print: [ AC3, AC10-11 ] - owasp_asvs: [ 16.3.3, 16.5.3 ] - owasp_asvs_print: [ 16.3.3, 16.5.3 ] + owasp_asvs: [ 16.3.2, 16.5.3 ] + owasp_asvs_print: [ 16.3.2, 16.5.3 ] capec: [ 180 ] capec_map: 180: - owasp_asvs: [ 16.3.3, 16.5.3 ] + owasp_asvs: [ 16.3.2, 16.5.3 ] safecode: [ 8, 10, 11 ] owasp_cre: owasp_asvs: [ 166-151 ] @@ -1142,35 +1142,35 @@ suits: owasp_dev_guide: [ SC1, SC2, SDC1, SDA2, SM2, SM12, AC2, AC3, AC4, ACM4, ACM5, ACM6, ACM7, ACM8, ACM9, SCM2, SCM4, PDR3, PDR4, SLD3 ] owasp_dev_guide_print: [ SC1-2, SDC1, SDA2, SDA2, SM2, SM12, AC2-4, ACM4-9, SCM2, SCM4, PDR3-4, SLD3 ] owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 13.3.2, 16.4.2 ] - owasp_asvs_print: [ 8.1.1, 10.2.3, 13.2.2, 13.3.2, 16.4.2 ] + owasp_asvs_print: [ 8.1.1, 10.2.3, 13.2.2, 13.3.2, 16.3.3, 16.4.2 ] capec: [ 54, 58, 75, 77, 87, 122, 126, 143, 144, 149, 155, 203, 240, 268 ] capec_map: 54: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 16.3.2 ] 58: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 13.3.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 13.3.2, 16.3.2 ] 75: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 16.3.2 ] 87: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 16.3.2 ] 122: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 13.3.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 13.3.2, 16.3.2 ] 126: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 16.3.2 ] 143: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 16.3.2 ] 144: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 16.3.2 ] 149: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 16.3.2 ] 155: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 13.3.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 13.3.2, 16.3.2 ] 203: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 16.3.2 ] 240: - owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2 ] + owasp_asvs: [ 8.1.1, 10.2.3, 13.2.2, 16.3.2 ] 268: - owasp_ascs: [ 16.4.2 ] + owasp_ascs: [ 16.3.3, 16.4.2, 16.3.3 ] safecode: [ 8, 10, 11, 13 ] owasp_cre: owasp_asvs: [ 278-413, 650-560, 368-633, 304-667 ] @@ -1182,14 +1182,14 @@ suits: stride_print: [ 'Elevation of Privilege' ] owasp_dev_guide: [ AC2, AC4, ACM6, ACM7, ACM8, DP4 ] owasp_dev_guide_print: [ AC2, AC4, ACM6-8, DP4 ] - owasp_asvs: [ 8.1.1, 8.1.2, 8.2.2, 8.2.3, 15.3.1 ] - owasp_asvs_print: [ 8.1.1-2, 8.2.2-3 ] + owasp_asvs: [ 8.1.1, 8.1.2, 8.2.2, 8.2.3, 15.3.1, 16.3.2 ] + owasp_asvs_print: [ 8.1.1-2, 8.2.2-3, 16.3.2 ] capec: [ 58, 122 ] capec_map: 58: - owasp_asvs: [ 8.1.1, 8.1.2, 8.2.2, 8.2.3, 15.3.1 ] + owasp_asvs: [ 8.1.1, 8.1.2, 8.2.2, 8.2.3, 15.3.1, 16.3.2 ] 122: - owasp_asvs: [ 8.1.1, 8.1.2, 8.2.2, 8.2.3, 15.3.1 ] + owasp_asvs: [ 8.1.1, 8.1.2, 8.2.2, 8.2.3, 15.3.1, 16.3.2 ] safecode: [ 8, 10, 11 ] owasp_cre: owasp_asvs: [ 368-633, 304-667 ] @@ -1201,16 +1201,16 @@ suits: stride_print: [ 'Elevation of Privilege' ] owasp_dev_guide: [ AC2, AC4, ACM5, ACM6, ACM7, ACM8, DP4 ] owasp_dev_guide_print: [ AC2, AC4, ACM5-8, DP4 ] - owasp_asvs: [ 8.1.1, 8.1.2, 8.2.1, 8.2.2, 8.2.3, 15.3.1 ] - owasp_asvs_print: [ 8.1.1-2, 8.2.1-3, 15.3.1 ] + owasp_asvs: [ 8.1.1, 8.1.2, 8.2.1, 8.2.2, 8.2.3, 15.3.1, 16.3.2 ] + owasp_asvs_print: [ 8.1.1-2, 8.2.1-3, 15.3.1, 16.3.2 ] capec: [ 58, 122, 212 ] capec_map: 58: - owasp_asvs: [ 8.1.1, 8.1.2, 8.2.1, 8.2.2, 8.2.3, 15.3.1 ] + owasp_asvs: [ 8.1.1, 8.1.2, 8.2.1, 8.2.2, 8.2.3, 15.3.1, 16.3.2 ] 122: - owasp_asvs: [ 8.1.1, 8.1.2, 8.2.1, 8.2.2, 8.2.3, 15.3.1 ] + owasp_asvs: [ 8.1.1, 8.1.2, 8.2.1, 8.2.2, 8.2.3, 15.3.1, 16.3.2 ] 212: - owasp_asvs: [ 8.1.1, 8.1.2, 8.2.1, 8.2.2, 8.2.3, 15.3.1 ] + owasp_asvs: [ 8.1.1, 8.1.2, 8.2.1, 8.2.2, 8.2.3, 15.3.1, 16.3.2 ] safecode: [ 8, 10, 11 ] owasp_cre: owasp_asvs: [ 368-633, 304-667 ] @@ -1222,24 +1222,24 @@ suits: stride_print: [ Tampering, 'Elevation of Privilege' ] owasp_dev_guide: [ SSV7, FV6, A18, AC14, AC15, ACM1 ] owasp_dev_guide_print: [ SSV7, FV6, A18, AC14-15, ACM1 ] - owasp_asvs: [ 2.1.3, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 3.5.7, 8.3.1, 16.3.3 ] - owasp_asvs_print: [ 2.1.3, 2.3.1-5, 3.5.7, 8.3.1, 16.3.3 ] + owasp_asvs: [ 2.1.3, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 3.5.7, 8.3.1, 16.3.2, 16.3.3 ] + owasp_asvs_print: [ 2.1.3, 2.3.1-5, 3.5.7, 8.3.1, 16.3.2-3 ] capec: [ 39, 74, 162, 166, 172, 207, 212 ] capec_map: 39: - owasp_asvs: [ 2.3.1, 2.3.4, 2.3.5, 8.3.1, 16.3.3 ] + owasp_asvs: [ 2.3.1, 2.3.4, 2.3.5, 8.3.1, 16.3.2, 16.3.3 ] 74: - owasp_asvs: [ 2.3.1, 2.3.4, 2.3.5, 3.5.7, 8.3.1, 16.3.3 ] + owasp_asvs: [ 2.3.1, 2.3.4, 2.3.5, 3.5.7, 8.3.1, 16.3.2, 16.3.3 ] 162: - owasp_asvs: [ 2.3.1, 2.3.4, 2.3.5, 8.3.1, 16.3.3 ] + owasp_asvs: [ 2.3.1, 2.3.4, 2.3.5, 8.3.1, 16.3.2, 16.3.3 ] 166: - owasp_asvs: [ 2.3.1, 2.3.4, 2.3.5, 8.3.1, 16.3.3 ] + owasp_asvs: [ 2.3.1, 2.3.4, 2.3.5, 8.3.1, 16.3.2, 16.3.3 ] 172: - owasp_asvs: [ 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 8.3.1, 16.3.3 ] + owasp_asvs: [ 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 8.3.1, 16.3.2, 16.3.3 ] 207: - owasp_asvs: [ 8.3.1, 16.3.3 ] + owasp_asvs: [ 8.3.1, 16.3.2, 16.3.3 ] 212: - owasp_asvs: [ 2.1.3, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 3.5.7, 8.3.1, 16.3.3 ] + owasp_asvs: [ 2.1.3, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 3.5.7, 8.3.1, 16.3.2, 16.3.3 ] safecode: [ 8, 10, 11, 12 ] owasp_cre: owasp_asvs: [ 368-633, 304-667, 284-521, 770-361, 534-605, 456-535 ] @@ -1278,24 +1278,24 @@ suits: stride_print: [ 'Elevation of Privilege' ] owasp_dev_guide: [ AC9, AC15 ] owasp_dev_guide_print: [ AC9, AC15 ] - owasp_asvs: [ 8.3.1, 8.3.2, 8.4.1, 10.4.11, 16.3.3 ] - owasp_asvs_print: [ 8.3.1-2, 8.4.1, 10.4.11, 16.3.3 ] + owasp_asvs: [ 8.3.1, 8.4.1, 10.4.11, 13.2.2, 16.3.2, 16.3.3 ] + owasp_asvs_print: [ 8.3.1-2, 8.4.1, 10.4.11, 13.2.2, 13.3.2, 16.3.2-3 ] capec: [ 1, 22, 36, 95, 121, 179, 180 ] capec_map: 1: - owasp_asvs: [ 8.3.1, 8.4.1, 16.3.3 ] + owasp_asvs: [ 8.3.1, 8.4.1, 13.2.2, 13.3.2, 16.3.2, 16.3.3 ] 22: - owasp_asvs: [ 8.3.1, 8.3.2, 10.4.11, 16.3.3 ] + owasp_asvs: [ 8.3.1, 16.3.2, 16.3.3 ] 36: - owasp_asvs: [ 8.3.1, 16.3.3 ] + owasp_asvs: [ 8.3.1, 16.3.2, 16.3.3 ] 95: - owasp_asvs: [ 8.3.1, 16.3.3 ] + owasp_asvs: [ 8.3.1, 16.3.2, 16.3.2, 16.3.3 ] 121: - owasp_asvs: [ 8.3.1, 16.3.3 ] + owasp_asvs: [ 8.3.1, 16.3.2, 16.3.3 ] 179: - owasp_asvs: [ 8.3.1, 10.4.11, 16.3.3 ] + owasp_asvs: [ 8.3.1, 13.2.2, 10.4.11, 16.3.2, 16.3.3 ] 180: - owasp_asvs: [ 8.3.1, 8.4.1, 10.4.11, 16.3.3 ] + owasp_asvs: [ 8.3.1, 8.4.1, 10.4.11, 13.2.2, 13.3.2, 16.3.2, 16.3.3 ] safecode: [ 8, 10, 11 ] owasp_cre: owasp_asvs: [ 344-611, 650-560 ] @@ -1307,28 +1307,28 @@ suits: stride_print: [ 'Information Disclosure', 'Elevation of Privilege' ] owasp_dev_guide: [ ACM8 ] owasp_dev_guide_print: [ ACM8 ] - owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.3.1, 8.4.2, 13.4.1, 13.4.7, 14.2.4, 16.3.3 ] - owasp_asvs_print: [ 8.1.1, 8.1.4, 8.2.1, 8.3.1, 8.4.2, 13.4.1, 13.4.7, 14.2.4, 16.3.3 ] + owasp_asvs: [ 3.1.1, 3.7.5, 8.1.1, 8.1.4, 8.2.1, 8.3.1, 8.4.2, 13.2.2, 13.3.2, 13.4.1, 13.4.7, 14.2.4, 16.3.2, 16.3.3 ] + owasp_asvs_print: [ 3.1.1, 3.7.5, 8.1.1, 8.1.4, 8.2.1, 8.3.1, 8.4.2, 13.2.2, 13.3.2, 13.4.1, 13.4.7, 14.2.4, 16.3.2-3 ] capec: [ 1, 11, 75, 116, 133, 176, 179, 180, 207 ] capec_map: 1: - owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 14.2.4, 16.3.3 ] + owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 13.2.2, 13.3.2, 14.2.4, 16.3.2, 16.3.3 ] 11: - owasp_asvs: [ 13.4.1, 13.4.7, 16.3.3 ] + owasp_asvs: [ 13.4.1, 13.4.7, 16.3.2, 16.3.3 ] 75: - owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 14.2.4, 16.3.3 ] + owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 14.2.4, 16.3.2, 16.3.3 ] 116: - owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 13.4.1, 13.4.7, 14.2.4, 16.3.3 ] + owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 13.4.1, 13.4.7, 14.2.4, 16.3.2, 16.3.3 ] 133: - owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 13.4.1, 13.4.7, 14.2.4, 16.3.3 ] + owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 13.4.1, 13.4.7, 14.2.4, 16.3.2, 16.3.3 ] 176: - owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.3.1, 13.4.1, 13.4.7, 14.2.4, 16.3.3 ] + owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.3.1, 13.2.2, 13.3.2, 13.4.1, 13.4.7, 14.2.4, 16.3.2, 16.3.3 ] 179: - owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 14.2.4 ] + owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 13.2.2, 14.2.4 ] 180: - owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 14.2.4 ] + owasp_asvs: [ 8.1.1, 8.1.4, 8.2.1, 8.4.2, 13.2.2, 13.3.2, 14.2.4, 16.3.2, 16.3.3 ] 207: - owasp_asvs: [ 8.1.1, 8.1.4, 8.3.1, 14.2.4 ] + owasp_asvs: [ 3.1.1, 3.7.5, 8.1.1, 8.1.4, 8.3.1, 14.2.4 ] safecode: [ 8, 10, 11 ] owasp_cre: owasp_asvs: [ 368-633, 838-636, 418-525, 265-800, 154-031 ] @@ -1340,22 +1340,22 @@ suits: stride_print: [ 'Elevation of Privilege' ] owasp_dev_guide: [ SFL9, CEC7, LF6 ] owasp_dev_guide_print: [ SFL9, CEC7, LF6 ] - owasp_asvs: [ 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, '1.2.10', 5.4.2, 5.4.3, 16.3.3, 16.4.1 ] - owasp_asvs_print: [ '1.2.3-10', 5.4.2-3, 16.3.3, 16.4.1 ] - capec: [ 35, 93, 122, 233, 242, 248 ] + owasp_asvs: [ 1.1.1, 1.1.2, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, '1.2.10', 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 1.3.10, 3.1.1, 3.4.2, 3.4.3, 3.4.6, 3.4.7, 3.4.8, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.6.1, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 6.7.1, 8.3.3, 8.4.2, 11.6.1, 11.6.2, 13.3.1, 13.3.2, 13.3.3, 13.4.5, 15.2.5, 16.3.3, 16.4.1 ] + owasp_asvs_print: [ 1.1.1-2, '1.2.1-10', 1.3.1-10, 3.1.1, 3.4.2-3, 3.4.6-8, 3.5.2-8, 3.6.1, 5.1.1, 5.2.2, 5.3.1-2, 5.4.1-3, 6.7.1, 8.3.3, 8.4.2, 11.6.1-2, 13.3.1-3, 13.4.5, 15.2.5, 16.3.3, 16.4.1 ] + capec: [ 93, 122, 233, 242, 248, 636 ] capec_map: - 35: - owasp_asvs: [ 1.2.3, 5.4.3, 16.3.3 ] 93: - owasp_asvs: [ 1.2.3, 1.2.4, 16.3.3, 16.4.1 ] + owasp_asvs: [ 1.2.3, 1.2.4, 16.3.3, 16.4.1 ] 122: - owasp_asvs: [ 1.2.3, 5.4.3, 16.3.3 ] + owasp_asvs: [ 1.2.3, 5.4.3, 16.3.3 ] 233: - owasp_asvs: [ 1.2.3, 5.4.3, 16.3.3 ] + owasp_asvs: [ 1.2.3, 3.1.1, 3.4.2, 3.4.3, 3.4.6, 3.4.7, 3.4.8, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.6.1, 5.4.3, 6.7.1, 8.3.3, 8.4.2, 11.6.1, 11.6.2, 13.3.1, 13.3.2, 13.3.3, 13.4.5, 15.2.5, 16.3.3 ] 242: - owasp_asvs: [ 1.2.3, 5.4.2, 5.4.3, 16.3.3 ] + owasp_asvs: [ 1.1.1, 1.1.2, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 1.3.10, 1.3.11, 1.3.12, 1.4.1, 1.4.2, 1.4.3, 1.5.1, 1.5.2, 1.5.3, 3.1.1, 3.2.1, 3.2.2, 3.2.3, 3.4.3, 3.4.6, 3.4.7, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.6.1, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.7.5, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 10.4.7, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3, 16.4.1 ] 248: - owasp_asvs: [ 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, '1.2.10', 5.4.2, 5.4.3, 16.3.3, 16.4.1 ] + owasp_asvs: [ 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, '1.2.10', 1.3.2, 1.3.3, 1.3.6, 1.3.8, 1.3.10, 1.3.11, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 16.3.3, 16.4.1 ] + 636: + owasp_asvs: [ 1.2.3, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 16.3.3 ] safecode: [ 8, 10, 11 ] owasp_cre: owasp_asvs: [ 857-718 ] @@ -1428,34 +1428,34 @@ suits: stride_print: [ Tampering ] owasp_dev_guide: [ SFL3, SFL4, VSD1 ] owasp_dev_guide_print: [ SFL3-4, VSD1 ] - owasp_asvs: [ 4.1.5, 6.7.1, 9.1.1, 9.1.2, 9.1.3, 11.3.3, 11.4.3, 14.2.4 ] - owasp_asvs_print: [ 4.1.5, 6.7.1, 9.1.1-3, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 9.1.1, 9.1.2, 9.1.3, 11.3.3, 11.4.3, 11.3.5, 14.2.4, 16.3.1, 16.3.2, 16.3.3, 16.3.4 ] + owasp_asvs_print: [ 4.1.5, 6.7.1, 9.1.1-3, 11.3.3, 11.4.3, 11.3.5, 14.2.4, 16.3.1, 16.3.2, 16.3.3, 16.3.4 ] capec: [ 39, 68, 75, 94, 145, 184, 438, 442, 475, 523, 594, 690 ] capec_map: 39: - owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4, 16.3.1, 16.3.3 ] 68: - owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4, 16.3.1, 16.3.2, 16.3.3, 16.3.4 ] 75: - owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4, 16.3.1 ] 94: - owasp_asvs: [ 4.1.5, 6.7.1, 9.1.1, 9.1.2, 9.1.3, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 9.1.1, 9.1.2, 9.1.3, 11.3.3, 11.4.3, 14.2.4, 16.3.4 ] 145: - owasp_asvs: [ 4.1.5, 6.7.1, 9.1.1, 9.1.2, 9.1.3, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 9.1.1, 9.1.2, 9.1.3, 11.3.3, 11.4.3, 14.2.4, 16.3.3, 16.3.4 ] 184: - owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4, 16.3.3, 16.3.4 ] 438: - owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4, 16.3.4 ] 442: - owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4, 16.3.4 ] 475: - owasp_asvs: [ ] + owasp_asvs: [ 9.1.1, 9.1.2, 9.1.3, 11.3.3, 11.4.3, 11.3.5, 14.2.4, 16.3.3, 16.3.4 ] 523: - owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4, 16.3.4 ] 594: - owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4, 16.3.4 ] 690: - owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4 ] + owasp_asvs: [ 4.1.5, 6.7.1, 11.3.3, 11.4.3, 14.2.4, 16.3.4 ] safecode: [ 12, 14 ] owasp_cre: owasp_asvs: [ 838-636, 838-636, 418-525, 265-800, 154-031, '028-254', 307-507, 253-452, 208-355, 347-352 ] @@ -1486,14 +1486,14 @@ suits: stride_print: [ Tampering, 'Information Disclosure' ] owasp_dev_guide: [ CP3, PDT4 ] owasp_dev_guide_print: [ CP3, PDT4 ] - owasp_asvs: [ 11.2.5, 12.2.1 ] - owasp_asvs_print: [ 11.2.5, 12.2.1, 16.3.3 ] + owasp_asvs: [ 11.2.5, 12.2.1, 16.3.3, 16.3.4 ] + owasp_asvs_print: [ 11.2.5, 12.2.1, 16.3.3, 16.3.4 ] capec: [ 24, 620 ] capec_map: 24: - owasp_asvs: [ 11.2.5, 16.3.3 ] + owasp_asvs: [ 11.2.5, 16.3.3, 16.3.4 ] 620: - owasp_asvs: [ 12.2.1, 16.3.3 ] + owasp_asvs: [ 12.2.1, 16.3.3, 16.3.4 ] safecode: [ 21, 29 ] owasp_cre: owasp_asvs: [ 527-034, '036-810', 248-646, 636-854 ] @@ -1530,32 +1530,32 @@ suits: stride_print: [ Tampering, 'Information Disclosure' ] owasp_dev_guide: [ SM15, PDT4, PDT5, PDT6, PDT7, PDT8 ] owasp_dev_guide_print: [ SM15, PDT4-8 ] - owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.3.1, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3 ] - owasp_asvs_print: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3-5, 11.3.1-5, 11.4.1, 11.4.3, 11.5.1-2, 11.6.1-2, 12.1.1-4, 12.2.1-2, 12.3.1-5, 16.3.3 ] + owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.3.1, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3, 16.3.4 ] + owasp_asvs_print: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3-5, 11.3.1-5, 11.4.1, 11.4.3, 11.5.1-2, 11.6.1-2, 12.1.1-4, 12.2.1-2, 12.3.1-5, 16.3.3-4 ] capec: [ 39, 94, 114, 145, 157, 216, 218, 220, 272, 594, 620 ] capec_map: 39: - owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3 ] + owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.1, 16.3.3, 16.3.4 ] 94: - owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3 ] + owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3, 16.3.4 ] 114: - owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3 ] + owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3, 16.3.4 ] 145: - owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3 ] + owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3, 16.3.4 ] 157: - owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3 ] + owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3, 16.3.4 ] 216: - owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3 ] + owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3, 16.3.4 ] 218: - owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3 ] + owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3, 16.3.4 ] 220: - owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3 ] + owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3, 16.3.4 ] 272: - owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3 ] + owasp_asvs: [ 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.3, 16.3.4 ] 594: - owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3 ] + owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3, 16.3.4 ] 620: - owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3 ] + owasp_asvs: [ 3.4.1, 3.7.4, 4.1.2, 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3, 16.3.4 ] safecode: [ 14, 29, 30 ] owasp_cre: owasp_asvs: [ 530-671, 786-224, 745-045, 430-636, 537-367, '036-147' ] @@ -1732,10 +1732,34 @@ suits: stride_print: [ Tampering ] owasp_dev_guide: [ SFL8, SFL10, ACM9, MM1, MM2, MM3, MM4, MM5, MM6, MM8, MM9 ] owasp_dev_guide_print: [ SFL8, SFL10, ACM9, MM1-6, MM8-9 ] - owasp_asvs: [ 1.4.1, 1.4.2, 1.4.3, 3.7.1, 11.2.5, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.2, 15.2.5, 15.4.1, 15.4.2, 15.4.3, 15.4.4, 16.5.2, 16.5.3 ] - owasp_asvs_print: [ 1.4.1-3, 3.7.1, 11.2.5, 15.1.1-2, 15.1.4-5, 15.2.1-2, 15.2.5, 15.4.1-4, 16.5.2-3 ] - capec: [ 25, 26, 77, 29, 96, 100, 123, 124, 125, 128, 129, 130, 131, 264, 446 ] - capec_map: {} + owasp_asvs: [ 1.4.1, 1.4.2, 1.4.3, 3.7.1, 11.2.4, 11.2.5, 11.3.1, 15.1.1, 15.1.2, 15.1.3, 15.1.4, 15.2.4, 15.1.5, 15.2.1, 15.2.2, 15.2.5, 15.4.1, 15.4.2, 15.4.3, 15.4.4, 16.5.2, 16.5.3 ] + owasp_asvs_print: [ 1.4.1-3, 3.7.1, 11.2.4, 11.2.5, 11.3.1, 15.1.1-5, 15.2.1-2, 15.2.5, 15.4.1-4, 16.5.2-3 ] + capec: [ 25, 26, 77, 100, 124, 125, 128, 129, 130, 131, 446 ] + capec_map: + 25: + owasp_asvs: [ 1.4.1, 1.4.2, 15.4.3, 15.4.4, 16.5.2, 16.5.3 ] + 26: + owasp_asvs: [ 15.4.1, 15.4.2, 16.5.3 ] + 77: + owasp_asvs: [ 16.5.3 ] + 100: + owasp_asvs: [ 16.5.2, 16.5.3 ] + 124: + owasp_asvs: [ 15.4.3, 15.4.4, 16.5.2, 16.5.3 ] + 125: + owasp_asvs: [ 15.1.3, 15.2.2, 16.5.2, 16.5.3 ] + 128: + owasp_asvs: [ 1.4.1, 1.4.2, 16.5.3 ] + 129: + owasp_asvs: [ 1.4.1, 1.4.2, 1.4.3, 16.5.2, 16.5.3 ] + 130: + owasp_asvs: [ 1.4.1, 1.4.2, 1.4.3, 15.1.3, 15.2.2, 16.5.2, 16.5.3 ] + 131: + owasp_asvs: [ 1.4.1, 1.4.2, 1.4.3, 15.4.1, 16.5.2, 16.5.3 ] + 446: + owasp_asvs: [ 3.7.1, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5 ] + 463: + owasp_asvs: [ 11.2.4, 11.2.5, 11.3.1, 16.3.3 ] safecode: [ 3, 5, 6, 7, 9, 22, 25, 26, 34 ] owasp_cre: owasp_asvs: [ 314-131 ] @@ -1747,10 +1771,20 @@ suits: stride_print: [ 'Information Disclosure' ] owasp_dev_guide: [ SC2, SC4, SC9, SC11 ] owasp_dev_guide_print: [ SC2, SC4, SC9, SC11 ] - owasp_asvs: [ 13.4.1, 13.4.2, 13.4.5, 13.4.6, 13.4.7, 15.2.3 ] - owasp_asvs_print: [ 13.4.1-2, 13.4.5-7, 15.2.3 ] - capec: [ 116, 167, 188, 189, 207 ] - capec_map: {} + owasp_asvs: [ 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.1.5, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 13.3.1, 13.4.1, 13.4.2, 13.4.5, 13.4.6, 13.4.7, 15.2.3, 16.3.3 ] + owasp_asvs_print: [ 12.1.1-5, 12.2.1-2, 12.3.1-5, 13.3.1, 13.4.1-2, 13.4.5-7, 15.2.3, 16.3.3 ] + capec: [ 11, 65, 94, 188, 207 ] + capec_map: + 11: + owasp_asvs: [ 13.4.7, 16.3.3 ] + 65: + owasp_asvs: [ 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.1.5, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5 ] + 94: + owasp_asvs: [ 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.1.5, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5 ] + 188: + owasp_asvs: [ 13.3.1, 13.4.1, 13.4.2, 13.4.5, 13.4.6, 13.4.7, 15.2.3, 16.3.3 ] + 207: + owasp_asvs: [ 13.3.1, 13.4.1, 13.4.2, 15.2.3, 16.3.3 ] safecode: [ "-" ] owasp_cre: owasp_asvs: [ 253-452 ] @@ -1762,10 +1796,12 @@ suits: stride_print: [ Repudiation ] owasp_dev_guide: [ A1, A2, A13, A18, P5 ] owasp_dev_guide_print: [ A1-2, A13, A18, P5 ] - owasp_asvs: [ 6.3.2, 6.7.1, 6.8.2, 16.3.1, 16.3.2, 16.3.3, 16.3.4 ] - owasp_asvs_print: [ 6.3.2, 6.7.1, 6.8.2, 16.3.1-4 ] + owasp_asvs: [ 6.3.2, 6.7.1, 6.8.2, 16.2.1, 16.2.2, 16.2.3, 16.2.4, 16.2.5, 16.3.1, 16.3.2, 16.3.3, 16.3.4, 16.4.1, 16.4.2, 16.4.3 ] + owasp_asvs_print: [ 6.3.2, 6.7.1, 6.8.2, 16.1.1, 16.2.1-5. 16.3.1-4, 16.4.1-3 ] capec: [ 268 ] - capec_map: {} + capec_map: + 268: + owasp_asvs: [ 6.3.2, 6.7.1, 6.8.2, 16.1.1, 16.2.1, 16.2.2, 16.2.3, 16.2.4, 16.2.5, 16.3.1, 16.3.2, 16.3.3, 16.3.4, 16.4.1, 16.4.2, 16.4.3 ] safecode: [ "-" ] owasp_cre: owasp_asvs: [ 841-710, 443-447 ] @@ -1773,14 +1809,28 @@ suits: id: "C5" value: "5" url: "https://cornucopia.owasp.org/cards/C5" - stride: [ R ] - stride_print: [ Repudiation ] + stride: [ S ] + stride_print: [ Spoofing ] owasp_dev_guide: [ ] owasp_dev_guide_print: [ "-" ] - owasp_asvs: [ 3.4.3, 3.4.6, 3.4.7, 3.4.8, 3.7.2, 3.7.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.4 ] - owasp_asvs_print: [ 3.4.3, 3.4.6-8, 3.7.2-3, 12.1.4, 12.2.1-2, 12.3.1, 12.3.4 ] - capec: [ 21, 22, 57, 89, 103, 181, 459 ] - capec_map: {} + owasp_asvs: [ 3.1.1, 3.2.1, 3.3.1, 3.3.2, 3.3.3, 3.3.4, 3.4.1, 3.4.2, 3.4.3, 3.4.4, 3.4.5, 3.4.6, 3.4.7, 3.5.1, 3.5.4, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.7.5, 9.1.1, 9.1.2, 9.1.3, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 10.1.1, 10.1.2, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.4.6, 10.4.7, 10.4.8, 10.4.9, 10.4.10, 10.4.11, 10.4.12, 10.4.13, 10.4.14, 10.4.15, 10.4.16, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 13.2.1, 13.2.2, 13.2.3, 13.2.4, 13.2.5 ] + owasp_asvs_print: [ 3.1.1, 3.2.1, 3.3.1-4, 3.4.1-7, 3.5.1, 3.5.4, 3.7.1-5, 9.1.1-3, 9.2.1-4, 10.1.1-2, 10.3.1-5, 10.4.1-16, 10.5.4, 11.1.1-2, 12.1.1-4, 12.2.1-2, 12.3.1-5, 13.2.1-5 ] + capec: [ 21, 22, 57, 89, 103, 181, 473 ] + capec_map: + 21: + owasp_asvs: [ 3.1.1, 3.3.2, 3.3.4, 3.4.1, 3.4.2, 3.4.3, 3.4.4, 3.4.6, 3.4.7, 3.5.1, 3.5.4, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.7.5, 9.1.1, 9.1.2, 9.1.3, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 10.1.1, 10.1.2, 10.2.1, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.4.6, 10.4.7, 10.4.8, 10.4.9, 10.4.10, 10.4.11, 10.4.12, 10.4.13, 10.4.14, 10.4.15, 10.4.16, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 13.2.1, 13.2.2, 13.2.3 ] + 22: + owasp_asvs: [ 3.1.1, 3.3.1, 3.3.2, 3.3.3, 3.3.4, 3.4.1, 3.4.2, 3.4.3, 3.4.4, 3.4.5, 3.4.6, 3.4.7, 3.5.1, 10.1.1, 10.1.2, 10.3.1, 10.3.5, 10.4.1, 10.4.4, 10.4.5, 10.4.6, 10.4.10, 10.4.11, 10.4.12, 10.4.13, 10.4.14, 10.4.15, 10.4.16, 10.6.1 ] + 57: + owasp_asvs: [ 9.1.1, 9.1.2, 9.1.3, 10.1.1, 10.1.2, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.4.14, 10.5.4, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 13.2.1, 13.2.2, 13.2.3, 13.2.4, 13.2.5 ] + 89: + owasp_asvs: [ 3.1.1, 3.4.1, 3.4.3, 3.4.7, 3.7.4, 3.7.5, 12.1.4, 12.1.5, 12.2.1, 12.2.2, 12.3.2 ] + 103: + owasp_asvs: [ 3.2.1, 3.3.2, 3.4.3, 3.4.6, 3.4.7, 3.7.5 ] + 181: + owasp_asvs: [ 3.7.1 ] + 473: + owasp_asvs: [ 11.1.1, 11.1.2, 11.1.3, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5 ] safecode: [ "-" ] owasp_cre: owasp_asvs: [ 530-671, 232-217, 745-045, 430-636, 537-367 ] @@ -1792,10 +1842,16 @@ suits: stride_print: [ Tampering ] owasp_dev_guide: [ A4, AC10, CP3, EE1, EE8, EE9, EE10, EE11 ] owasp_dev_guide_print: [ A4, AC10, CP3, EE1, EE8-11 ] - owasp_asvs: [ 11.2.5, 12.2.1, 12.3.1, 12.3.3, 16.5.3 ] - owasp_asvs_print: [ 11.2.5, 12.2.1, 12.3.1, 12.3.3, 16.5.3 ] - capec: [ 54, 98, 164, 172, 554 ] - capec_map: {} + owasp_asvs: [ 11.2.5, 12.2.1, 12.3.1, 12.3.3, 16.3.2, 16.3.3, 16.3.4, 16.5.3 ] + owasp_asvs_print: [ 11.2.5, 12.2.1, 12.3.1, 12.3.3, 16.3.2-4, 16.5.3 ] + capec: [ 54, 114, 217 ] + capec_map: + 54: + owasp_asvs: [ 11.2.5, 16.3.2, 16.3.3, 16.5.3 ] + 114: + owasp_asvs: [ 11.2.5, 16.3.2, 16.3.3, 16.5.3 ] + 217: + owasp_asvs: [ 12.2.1, 12.3.1, 12.3.3, 116.3.3, 16.3.4 ] safecode: [ 4, 11, 23 ] owasp_cre: owasp_asvs: [ 166-15, 555-048 ] @@ -1809,8 +1865,10 @@ suits: owasp_dev_guide_print: [ A4 SL1-3, SL6-13, SLD3-4, SLD8-10 ] owasp_asvs: [ 16.1.1, 16.2.1, 16.2.2, 16.2.3, 16.2.4, 16.3.1, 16.3.2, 16.3.3, 16.3.4, 16.4.1, 16.4.2, 16.4.3 ] owasp_asvs_print: [ 16.1.1, 16.2.1-4, 16.3.1-4, 16.4.1-3 ] - capec: [ 81, 93, 268 ] - capec_map: {} + capec: [ 268 ] + capec_map: + 268: + owasp_asvs: [ 16.1.1, 16.2.1, 16.2.2, 16.2.3, 16.2.4, 16.3.1, 16.3.2, 16.3.3, 16.3.4, 16.4.1, 16.4.2, 16.4.3 ] safecode: [ 4 ] owasp_cre: owasp_asvs: [ 240-274, 555-048, 841-710, 443-447, '048-612', 713-683, '015-063', 668-364 ] @@ -1822,10 +1880,24 @@ suits: stride_print: [ 'Information Disclosure' ] owasp_dev_guide: [ SC1, SC2, SC3, SC4, SC5, SC6, SC7, SC8, SC9, SC10, SC11, SC12, SC13, SFL1, SFL2, SFL14, SFL15, SDC2, SDC3, SDC4, SDC5, SDC6, SDA1, PDT1, PDT2, PDT3, PDT4, PDT5, PDT6, PDT7, PDT8, PDT9, PDT10, PDT11 ] owasp_dev_guide_print: [ SC1-13, SFL1-2, SFL14-15, SDC2-6, SDA1, PDT1-11 ] - owasp_asvs: [ 13.2.1, 13.2.2, 13.2.3, 15.1.1, 15.1.2, 15.2.1, 15.2.4 ] - owasp_asvs_print: [ 13.2.1-3, 15.1.1-2, 15.2.1, 15.2.4 ] - capec: [ 37, 161, 169, 176, 220, 310, 536 ] - capec_map: {} + owasp_asvs: [ 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.1.5, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 13.2.1, 13.2.2, 13.2.3, 13.3.1, 13.3.2, 13.3.3, 13.3.4, 13.3.5, 13.4.1, 13.4.2, 13.4.3, 13.4.4, 13.4.5, 13.4.6, 13.4.7, 15.1.1, 15.1.2, 15.2.1, 15.2.4, 16.3.3, 16.3.4 ] + owasp_asvs_print: [ 12.1.1-5, 12.2.1-2, 12.3.1-5, 13.2.1-3, 13.3.1-5, 13.4.1-7, 15.1.1-2, 15.2.1, 15.2.4, 16.3.3-4 ] + capec: [ 37, 121, 159, 169, 217, 220, 310, 446 ] + capec_map: + 37: + owasp_asvs: [ 13.2.1, 13.2.2, 13.2.3, 13.3.1, 13.3.2, 13.3.3, 13.3.4, 13.3.5, 13.4.1, 13.4.7 ] + 121: + owasp_asvs: [ 13.4.2 ] + 169: + owasp_asvs: [ 13.4.1, 13.4.2, 13.4.3, 13.4.4, 13.4.5, 13.4.6, 13.4.7, 15.1.1, 15.1.2, 16.3.4 ] + 217: + owasp_asvs: [ 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.1.5, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3, 16.3.4 ] + 220: + owasp_asvs: [ 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.1.5, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.4 ] + 310: + owasp_asvs: [ 13.4.1, 13.4.2, 13.4.6, 13.4.7, 16.3.4 ] + 445: + owasp_asvs: [ 15.1.1, 15.1.2, 15.2.1, 15.2.4, 16.3.4 ] safecode: [ "-" ] owasp_cre: owasp_asvs: [ 801-310, 154-031, 418-525, 208-355, 347-352, 715-334, 462-245 ] @@ -1837,10 +1909,26 @@ suits: stride_print: [ 'Elevation of Privilege' ] owasp_dev_guide: [ A1, A3, A9, A10, AC2, AC12, ACM4, ACM5, ACM6, ACM7, ACM8 ] owasp_dev_guide_print: [ A1, A3, A9-10, AC2, AC12, 7.2-8 ] - owasp_asvs: [ 7.5.3, 8.4.2, 13.2.1, 13.2.2, 13.2.3 ] - owasp_asvs_print: [ 7.5.3, 8.4.2, 13.2.1-3 ] - capec: [ 122, 169, 233 ] - capec_map: {} + owasp_asvs: [ 6.1.1, 6.2.2, 6.2.4, 6.2.11, 6.3.1, 6.3.2, 6.3.8, 6.4.2, 7.5.3, 8.4.2, 13.2.1, 13.2.2, 13.2.3, 13.3.2, 13.4.2, 13.4.3, 13.4.4, 13.4.5, 16.3.1, 16.3.2, 16.3.3, 16.3.4, 17.1.1 ] + owasp_asvs_print: [ 6.1.1, 6.2.2, 6.2.4, 6.2.11, 6.3.1-2, 6.3.8, 6.4.2, 7.5.3, 8.4.2, 13.2.1-3, 13.3.2, 13.4.2-5, 16.3.1-4, 17.1.1 ] + capec: [ 1, 36, 49, 87, 121, 127, 169 ] + capec_map: + 1: + owasp_asvs: [ 13.2.2, 13.3.2, 16.3.2 ] + 36: + owasp_asvs: [ 13.2.1, 13.4.5 ] + 49: + owasp_asvs: [ 4.4.3, 6.3.2, 7.5.3, 8.4.2, 13.2.1, 13.2.3, 16.3.1, 16.3.3 ] + 70: + owasp_asvs: [ 6.1.1, 6.2.2, 6.2.4, 6.2.11, 6.3.1, 6.3.2, 6.3.8, 6.4.2, 13.2.3, 16.3.1, 16.3.3, 16.5.1, 16.5.3 ] + 87: + owasp_asvs: [ 13.2.1, 13.4.5 ] + 121: + owasp_asvs: [ 13.4.2, 13.4.5 ] + 127: + owasp_asvs: [ 13.4.3, 16.3.3 ] + 169: + owasp_asvs: [ 13.2.1, 13.4.3, 13.4.4, 13.4.5, 16.3.4, 17.1.1 ] safecode: [ "-" ] owasp_cre: owasp_asvs: [ 801-310, 201-246 ] @@ -1852,10 +1940,28 @@ suits: stride_print: [ Tampering ] owasp_dev_guide: [ SC4, SFL1, SFL2, SFL10, SFL11, SFL12, SFL13, SFL14, SFL15 ] owasp_dev_guide_print: [ SC4, SFL1-2, SFL10-15 ] - owasp_asvs: [ 15.1.1, 15.1.2, 15.2.1, 15.2.2, 15.2.3, 15.2.4, 15.2.5 ] - owasp_asvs_print: [ 15.1.1-2, 15.2.1-5 ] - capec: [ 68, 310, 438, 439, 442, 443, 523, 524, 446, 538 ] - capec_map: {} + owasp_asvs: [ 6.7.1, 11.4.1, 11.4.3, 11.6.1, 11.6.2, 13.3.1, 13.3.2, 13.3.3, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.4 ] + owasp_asvs_print: [ 6.7.1, 11.4.1, 11.4.3, 11.6.1-2, 13.3.1-3, 15.1.1-2, 15.1.4-5, 15.2.1, 15.2.4-5, 16.3.1-4 ] + capec: [ 68, 159, 206, 442, 446, 523, 538, 673, 691 ] + capec_map: + 68: + owasp_asvs: [ 6.7.1, 11.4.1, 11.4.3, 11.6.1, 11.6.2, 13.3.1, 13.3.2, 13.3.3, 15.2.5, 16.3.1, 16.3.2, 16.3.3, 16.3.4 ] + 159: + owasp_asvs: [ 15.2.4, 16.3.4 ] + 206: + owasp_asvs: [ 13.3.1, 13.3.2, 13.3.3, 16.3.1, 16.3.2, 16.3.3, 16.3.4 ] + 442: + owasp_asvs: [ 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.4 ] + 446: + owasp_asvs: [ 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.4 ] + 523: + owasp_asvs: [ 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.4 ] + 538: + owasp_asvs: [ 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.4 ] + 673: + owasp_asvs: [ 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.4 ] + 691: + owasp_asvs: [ 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.4 ] safecode: [ 15 ] owasp_cre: owasp_asvs: [ 053-751, 611-158, 838-636, 838-636, 418-525, 265-800, 715-334 ] @@ -1867,10 +1973,26 @@ suits: stride_print: [ Tampering ] owasp_dev_guide: [ SC1, SC12, SC13, FM1, FM2, FM3, FM4, FM5, SFL1, SFL2, SFL3, SFL4, SFL5, SFL6, SDC4, SDC5, SDC6, SDA1, SDA2, AC6, AC7, ACM8, PDT2, PDT8 ] owasp_dev_guide_print: [ SC1, SC12-13, FM1-5, SFL1-6, SDC4-6, SDA1-2, AC6-7, ACM8, PDT2, PDT8 ] - owasp_asvs: [ 3.7.5, 15.1.1, 15.1.2, 15.2.1, 15.2.2, 15.2.3, 15.2.4, 15.2.5 ] - owasp_asvs_print: [ 3.7.5, 15.1.1-2, 15.2.1-5 ] - capec: [ 445, 447 ] - capec_map: {} + owasp_asvs: [ 3.1.1, 3.4.3, 3.4.7, 3.6.1, 3.7.5, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.3.1, 8.4.2, 13.1.1, 13.2.1, 13.2.2, 13.2.3, 13.3.1, 13.3.2, 13.4.1, 13.4.2, 13.4.3, 13.4.4, 13.4.5, 13.4.6, 13.4.7, 15.2.3, 15.2.5, 16.3.2, 16.3.3, 16.3.4 ] + owasp_asvs_print: [ 3.1.1, 3.4.3, 3.4.7, 3.6.1, 3.7.5, 8.2.1-4, 8.3.1, 8.4.2, 13.1.1, 13.2.1-3, 13.3.2, 13.4.1-7, 15.2.3, 15.2.5, 16.3.2-4 ] + capec: [ 70, 121, 127, 133, 176, 180, 191, 207 ] + capec_map: + 70: + owasp_asvs: [ 13.2.3 ] + 121: + owasp_asvs: [ 13.4.1, 13.4.5, 15.2.3 ] + 127: + owasp_asvs: [ 13.4.3, 16.3.3 ] + 133: + owasp_asvs: [ 13.2.1, 13.4.2, 13.4.4, 13.4.5, 13.4.6 ] + 176: + owasp_asvs: [ 1.3.8, 3.7.5, 8.3.1, 8.4.2, 13.1.1, 13.2.4, 15.2.5, 16.3.3, 16.3.4 ] + 180: + owasp_asvs: [ 8.2.1, 8.2.2, 8.2.3, 8.2.4, 13.2.2, 13.3.2, 16.3.2 ] + 191: + owasp_asvs: [ 13.3.1, 13.4.7 ] + 207: + owasp_asvs: [ 3.1.1, 3.4.3, 3.4.7, 3.6.1, 3.7.5 ] safecode: [ 4 ] owasp_cre: owasp_asvs: [ 053-751, 253-452, 314-131, 180-488, 208-355, 347-352, 715-334 ] @@ -1882,10 +2004,14 @@ suits: stride_print: [ Repudiation ] owasp_dev_guide: [ M1, M2 ] owasp_dev_guide_print: [ M1-2 ] - owasp_asvs: [ 2.3.2, 2.4.1, 2.4.2, 6.3.1, 6.3.5, 6.3.7, 7.4.5, 7.5.1, 7.5.2, 7.5.3, 8.1.3, 8.1.4, 8.3.2, 8.4.2, 16.3.1, 16.3.2, 16.3.3, 16.3.4 ] - owasp_asvs_print: [ 2.3.2, 2.4.1-2, 6.3.1, 6.3.5, 6.3.7, 7.4.5, 7.5.1-3, 8.1.3-4, 8.3.2, 8.4.2, 16.3.1-4 ] - capec: [ 212 ] - capec_map: {} + owasp_asvs: [ 6.3.5, 6.3.7, 8.1.3, 8.1.4, 8.3.1, 8.3.2, 8.3.3, 8.4.2, 16.3.1, 16.3.2, 16.3.3, 16.3.4, 16.4.1, 16.4.2, 16.4.3 ] + owasp_asvs_print: [ 6.3.5, 6.3.7, 8.1.3-4, 8.3.2, 8.4.2, 16.3.1-4 ] + capec: [ 156, 268 ] + capec_map: + 156: + owasp_asvs: [ 6.3.5, 6.3.7, 8.1.3, 8.1.4, 8.3.1, 8.3.2, 8.3.3, 8.4.2, 16.3.1, 16.3.2, 16.3.3, 16.3.4 ] + 268: + owasp_asvs: [ 16.4.1, 16.4.2, 16.4.3 ] safecode: [ 1, 27 ] owasp_cre: owasp_asvs: [ 176-154, 534-605, 456-535, 746-705, 630-573 ] @@ -1897,10 +2023,26 @@ suits: stride_print: [ 'Denial of Service' ] owasp_dev_guide: [ A12, ACM1 ] owasp_dev_guide_print: [ A12, ACM1 ] - owasp_asvs: [ 1.3.12, 2.3.2, 2.4.1, 2.4.2, 4.2.5, 4.3.1, 5.2.1, 5.2.6, 6.1.1, 6.3.1, 10.5.5, 10.6.2, 13.1.2, 13.1.3, 13.2.6, 15.1.3, 17.1.2, 17.3.1, 17.3.2 ] - owasp_asvs_print: [ 1.3.12, 2.3.2, 2.4.1-2, 4.2.5, 4.3.1, 5.2.1, 5.2.6, 6.1.1, 6.3.1, 10.5.5, 10.6.2, 13.1.2-3, 13.2.6, 15.1.3, 17.1.2, 17.3.1-2 ] - capec: [ 2, 25, 125, 130, 212, 227, 469, 607 ] - capec_map: {} + owasp_asvs: [ 1.3.12, 2.3.2, 2.4.1, 2.4.2, 4.2.5, 4.3.1, 5.2.1, 5.2.6, 6.1.1, 6.3.1, 6.4.5, 6.4.6, 10.5.5, 10.6.2, 13.1.2, 13.1.3, 13.2.6, 15.1.3, 15.3.3, 15.4.3-4, 16.3.3, 16.5.2, 17.1.2, 17.3.1, 17.3.2 ] + owasp_asvs_print: [ 1.3.12, 2.3.2, 2.4.1-2, 4.2.5, 4.3.1, 5.2.1, 5.2.6, 6.1.1, 6.3.1, 6.4.5-6, 10.5.5, 10.6.2, 13.1.2-3, 13.2.6, 15.1.3, 15.3.3, 15.4.3-4, 16.3.3, 16.5.2, 17.1.2, 17.3.1-2 ] + capec: [ 2, 25, 100, 125, 130, 227, 572, 607 ] + capec_map: + 2: + owasp_asvs: [ 2.3.2, 2.4.1, 2.4.2, 6.1.1, 6.3.1, 10.5.5, 10.6.2, 16.3.3 ] + 25: + owasp_asvs: [ 2.3.2, 4.2.5, 16.3.3 ] + 100: + owasp_asvs: [ 4.2.5, 4.3.1, 16.3.3 ] + 125: + owasp_asvs: [ 2.4.1, 13.1.2, 13.1.3, 13.2.6, 16.3.3, 16.5.2, 17.1.2, 17.3.1, 17.3.2 ] + 130: + owasp_asvs: [ 1.3.12, 2.4.1, 4.3.1, 5.2.1, 5.2.6, 15.1.3, 15.3.3, 16.3.3, 16.5.2 ] + 227: + owasp_asvs: [ 2.3.2, 4.2.5, 13.1.2, 13.1.3, 13.2.6, 16.3.3, 16.5.2 ] + 572: + owasp_asvs: [ 5.2.1, 5.2.6, 16.3.3 ] + 607: + owasp_asvs: [ 6.4.5, 6.4.6, 13.1.3, 15.4.3, 15.4.4, 17.3.2, 16.3.3, 16.5.2 ] safecode: [ 1 ] owasp_cre: owasp_asvs: [ 802-056, 746-705, 630-573 ] @@ -1929,10 +2071,32 @@ suits: stride_print: [ ] owasp_dev_guide: [ "-" ] owasp_dev_guide_print: [ "-" ] - owasp_asvs: [ 3.1.1, 5.1.1, 5.4.3, 10.4.7 ] - owasp_asvs_print: [ 3.1.1, 5.1.1, 5.4.3, 10.4.7 ] - capec: [ 23, 165, 184, 186, 242, 441, 444, 523, 533, 549, 657 ] - capec_map: {} + owasp_asvs: [ 1.1.1, 1.1.2, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 1.3.10, 1.3.11, 1.3.12, 1.4.1, 1.4.2, 1.4.3, 1.5.1, 1.5.2, 1.5.3, 3.1.1, 3.2.1, 3.2.2, 3.2.3, 3.4.3, 3.4.6, 3.4.7, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.6.1, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.7.5, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 6.7.1, 10.4.7, 11.4.1, 11.4.3, 11.6.1, 11.6.2, 13.3.1, 13.3.2, 13.3.3, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3, 16.4.1 ] + owasp_asvs_print: [ 1.1.1-2, 1.2.1-10, 1.3.1-12, 1.4.1-3, 1.5.1-3, 3.1.1, 3.2.1-3, 3.4.3, 3.4.6-7, 3.5.4-7, 3.6.1, 3.7.1-5, 5.1.1, 5.2.2, 5.3.1-2, 5.4.1-3, 6.7.1, 10.4.7, 11.4.1, 11.4.3, 11.6.1-2, 13.3.1-3, 15.1.1-2, 15.1.4-5, 15.2.1, 15.2.4-5, 16.3.1-4, 16.4.1 ] + capec: [ 184, 242, 248, 441, 444, 523, 549, 636, 691 ] + capec_map: + 68: + owasp_asvs: [ 6.3.3, 6.7.1, 11.4.1, 11.4.3, 11.6.1, 11.6.2, 13.3.1, 13.3.2, 13.3.3, 15.2.5, 16.3.1, 16.3.2, 16.3.3, 16.3.4 ] + 159: + owasp_asvs: [ 15.2.4, 16.3.4 ] + 184: + owasp_asvs: [ 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.2, 1.3.3, 1.3.6, 1.3.8, 1.3.10, 1.3.11, 3.6.1, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.4 ] + 242: + owasp_asvs: [ 1.1.1, 1.1.2, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 1.3.10, 1.3.11, 1.3.12, 1.4.1, 1.4.2, 1.4.3, 1.5.1, 1.5.2, 1.5.3, 3.1.1, 3.2.1, 3.2.2, 3.2.3, 3.4.3, 3.4.6, 3.4.7, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.6.1, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.7.5, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 10.4.7, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3, 16.4.1 ] + 248: + owasp_asvs: [ 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, '1.2.10', 1.3.2, 1.3.3, 1.3.6, 1.3.8, 1.3.10, 1.3.11, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 16.3.3, 16.4.1 ] + 441: + owasp_asvs: [ 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.2, 1.3.3, 1.3.6, 1.3.8, 1.3.10, 1.3.11, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3 ] + 444: + owasp_asvs: [ 3.6.1, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3 ] + 523: + owasp_asvs: [ 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 10.4.7, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3 ] + 549: + owasp_asvs: [ 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.2, 1.3.3, 1.3.6, 1.3.8, 1.3.10, 1.3.11, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 10.4.7, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3 ] + 636: + owasp_asvs: [ 1.2.3, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3 ] + 691: + owasp_asvs: [ 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5 ] safecode: [ "-" ] - id: "JOB" @@ -1942,8 +2106,32 @@ suits: stride_print: [ ] owasp_dev_guide: [ "-" ] owasp_dev_guide_print: [ "-" ] - owasp_asvs: [ 3.1.1, 5.1.1, 6.4.5-6, 7.6.2, 10.7.1, 10.7.2, 10.7.3, 11.1.3, 11.1.4, 13.1.4, 14.2.8 ] - owasp_asvs_print: [ 3.1.1, 5.1.1, 6.4.5-6, 7.6.2, 10.7.1-3, 11.1.1-4, 13.1.4 ] - capec: [ 9, 184, 416, 438, 439, 444, 447, 524, 548, 669, 691 ] - capec_map: {} + owasp_asvs: [ 1.1.1, 1.1.2, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 1.3.10, 1.3.11, 1.3.12, 1.4.1, 1.4.2, 1.4.3, 1.5.1, 1.5.2, 1.5.3, 3.1.1, 3.2.1, 3.2.2, 3.2.3, 3.4.3, 3.4.6, 3.4.7, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.6.1, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.7.5, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 6.3.3, 6.4.5, 6.4.6, 6.7.1, 7.6.2, 10.4.7, 10.7.1, 10.7.2, 10.7.3, 11.1.3, 11.1.4, 11.4.1, 11.4.3, 11.6.1, 11.6.2, 13.1.3, 13.1.4, 13.3.1, 13.3.2, 13.3.3, 14.2.4, 14.2.8, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 15.4.3, 15.4.4, 16.3.3, 16.4.1, 16.5.2 ] + owasp_asvs_print: [ 1.1.1-2, 1.2.1-10, 1.3.1-12, 1.4.1-3, 1.5.1-3, 3.1.1, 3.2.1-3, 3.4.3, 3.4.6-7, 3.5.4-7, 3.6.1, 3.7.1-5, 5.1.1, 5.2.2, 5.3.1-2, 5.4.1-3, 6.3.3, 6.4.5-6, 6.7.1, 7.6.2, 10.4.7, 10.7.1-3, 11.1.3-4, 11.4.1, 11.4.3, 11.6.1-2, 13.1.3-4, 13.3.1-3, 14.2.4, 14.2.8, 15.1.1-2, 15.1.4-5, 15.2.1, 15.2.4-5, 15.4.3-4, 16.3.1-4, 16.4.1, 16.5.2 ] + capec: [ 184, 242, 416, 438, 441, 444, 523, 518, 519, 548, 636, 691 ] + capec_map: + 184: + owasp_asvs: [ 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.2, 1.3.3, 1.3.6, 1.3.8, 1.3.10, 1.3.11, 3.6.1, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.4 ] + 242: + owasp_asvs: [ 1.1.1, 1.1.2, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 1.3.10, 1.3.11, 1.3.12, 1.4.1, 1.4.2, 1.4.3, 1.5.1, 1.5.2, 1.5.3, 3.1.1, 3.2.1, 3.2.2, 3.2.3, 3.4.3, 3.4.6, 3.4.7, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.6.1, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.7.5, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 10.4.7, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3, 16.4.1 ] + 416: + owasp_asvs: [ 6.4.6 ] + 441: + owasp_asvs: [ 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.2, 1.3.3, 1.3.6, 1.3.8, 1.3.10, 1.3.11, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3 ] + 444: + owasp_asvs: [ 3.6.1, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3 ] + 523: + owasp_asvs: [ 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 10.4.7, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3 ] + 518: + owasp_asvs: [ 3.1.1, 5.1.1, 6.3.3, 6.4.5, 6.4.6, 6.7.1 ] + 519: + owasp_asvs: [ 5.1.1, 6.3.3, 6.4.5, 6.4.6, 6.7.1 ] + 548: + owasp_asvs: [ 5.1.1, 6.3.3, 6.4.6, 6.7.1, 10.7.1, 10.7.2, 10.7.3, 11.1.1, 11.1.2, 11.1.3, 11.1.4, 13.1.4, 13.3.1, 13.3.2, 13.3.3, 14.2.4, 14.2.5, 14.2.6, 14.2.7, 14.2.8 ] + 603: + owasp_asvs: [ 6.4.5, 6.4.6, 13.1.3, 15.4.3, 15.4.4, 17.3.2, 16.3.3, 16.5.2 ] + 636: + owasp_asvs: [ 1.2.3, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 16.3.4 ] + 691: + owasp_asvs: [ 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.4 ] safecode: [ "-" ]