Tag all security queries in supported languages' experimental directories with an experimental tag

This commit is contained in:
turbo
2022-12-14 17:15:50 +01:00
parent a92acf5218
commit 4ec401a3f6
148 changed files with 155 additions and 3 deletions

View File

@@ -9,6 +9,7 @@
* @security-severity 7.5
* @precision high
* @tags security
* experimental
* external/cwe/cwe-022
*/

View File

@@ -9,6 +9,7 @@
* @security-severity 7.5
* @precision high
* @tags security
* experimental
* external/cwe/cwe-022
*/

View File

@@ -6,6 +6,7 @@
* @precision high
* @id py/template-injection
* @tags security
* experimental
* external/cwe/cwe-074
*/

View File

@@ -8,6 +8,7 @@
* @sub-severity high
* @id py/reflective-xss-email
* @tags security
* experimental
* external/cwe/cwe-079
* external/cwe/cwe-116
*/

View File

@@ -7,6 +7,7 @@
* @precision high
* @id py/xslt-injection
* @tags security
* experimental
* external/cwe/cwe-643
*/

View File

@@ -6,6 +6,7 @@
* @problem.severity error
* @id py/header-injection
* @tags security
* experimental
* external/cwe/cwe-113
* external/cwe/cwe-079
*/

View File

@@ -6,6 +6,7 @@
* @problem.severity error
* @id py/csv-injection
* @tags security
* experimental
* external/cwe/cwe-1236
*/

View File

@@ -5,6 +5,7 @@
* @problem.severity warning
* @id py/improper-ldap-auth
* @tags security
* experimental
* external/cwe/cwe-287
*/

View File

@@ -3,6 +3,7 @@
* @description Using version v1 of Azure Storage client-side encryption is insecure, and may enable an attacker to decrypt encrypted data
* @kind problem
* @tags security
* experimental
* cryptography
* external/cwe/cwe-327
* @id py/azure-storage/unsafe-client-side-encryption-in-use

View File

@@ -9,6 +9,7 @@
* @precision high
* @id py/insecure-randomness
* @tags security
* experimental
* external/cwe/cwe-338
*/

View File

@@ -8,6 +8,7 @@
* @security-severity 5
* @id py/predictable-token
* @tags security
* experimental
* external/cwe/cwe-340
*/

View File

@@ -5,6 +5,7 @@
* @problem.severity warning
* @id py/jwt-empty-secret-or-algorithm
* @tags security
* experimental
*/
// determine precision above

View File

@@ -5,6 +5,7 @@
* @problem.severity warning
* @id py/jwt-missing-verification
* @tags security
* experimental
* external/cwe/cwe-347
*/

View File

@@ -7,6 +7,7 @@
* @precision high
* @id py/ip-address-spoofing
* @tags security
* experimental
* external/cwe/cwe-348
*/

View File

@@ -5,6 +5,7 @@
* @problem.severity error
* @id py/insecure-ldap-auth
* @tags security
* experimental
* external/cwe/cwe-522
* external/cwe/cwe-523
*/

View File

@@ -6,6 +6,7 @@
* @precision high
* @id py/simple-xml-rpc-server-dos
* @tags security
* experimental
* external/cwe/cwe-776
*/

View File

@@ -5,6 +5,7 @@
* @problem.severity error
* @id py/cookie-injection
* @tags security
* experimental
* external/cwe/cwe-614
*/

View File

@@ -8,6 +8,7 @@
* @precision ???
* @id py/insecure-cookie
* @tags security
* experimental
* external/cwe/cwe-614
*/

View File

@@ -6,6 +6,7 @@
* @problem.severity error
* @id py/nosql-injection
* @tags security
* experimental
* external/cwe/cwe-943
*/