Skip to content

Commit 27af8db

Browse files
authored
Merge pull request #1981 from OWASP/capec-asvs5-2
Adding mapping between capec and asvs5 for the Crypography suite
2 parents fd196dc + 479566a commit 27af8db

File tree

4 files changed

+245
-107
lines changed

4 files changed

+245
-107
lines changed

source/webapp-cards-2.2-en.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -328,7 +328,7 @@ suits:
328328
id: "CR9"
329329
value: "9"
330330
url: "https://cornucopia.owasp.org/cards/CR9"
331-
desc: "Andy can bypass random number generation, random GUID generation, hashing and encryption functions because they have been self-built and/or are weak"
331+
desc: "Andy can bypass cryptographic controls because random-number, GUID, or hashing functions are self-built, risky or weak"
332332
-
333333
id: "CRX"
334334
value: "10"

source/webapp-cards-3.0-en.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -328,7 +328,7 @@ suits:
328328
id: "CR9"
329329
value: "9"
330330
url: "https://cornucopia.owasp.org/cards/CR9"
331-
desc: "Andy can bypass random number generation, random GUID generation, hashing and encryption functions because they have been self-built and/or are weak"
331+
desc: "Andy can bypass cryptographic controls because random-number, GUID, or hashing functions are self-built, risky or weak"
332332
-
333333
id: "CRX"
334334
value: "10"

source/webapp-mappings-2.2.yaml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -885,7 +885,7 @@ suits:
885885
owasp_asvs: [ 6.2.2 ]
886886
owasp_asvs_print: [ 6.2.2 ]
887887
owasp_appsensor: [ "-" ]
888-
capec: [ 39, 162 ]
888+
capec: [ 39, 97, 162, 204 ]
889889
safecode: [ 21, 29 ]
890890
owasp_cre:
891891
owasp_asvs: [ 742-431 ]
@@ -901,7 +901,7 @@ suits:
901901
owasp_asvs: [ 10.2.3, 10.2.4, 10.2.5, 10.2.6, 10.3.1, 10.3.2, 14.1.1, 14.1.4, 14.1.5 ]
902902
owasp_asvs_print: [ 10.2.3-6, 10.3.1, 10.3.2, 14.1.1, 14.1.4, 14.1.5 ]
903903
owasp_appsensor: [ SE1, IE4 ]
904-
capec: [ 31, 39, 68, 75, 94, 133, 145, 162, 184, 203, 233, 438, 439, 442, 444, 447, 594, 690 ]
904+
capec: [ 39, 68, 75, 94, 145, 184, 438, 442, 475, 523, 594, 690 ]
905905
safecode: [ 12, 14 ]
906906
owasp_cre:
907907
owasp_asvs: [ 838-636, 838-636, 418-525, 265-800, 154-031, '028-254', 307-507, 253-452, 208-355, 347-352 ]
@@ -917,7 +917,7 @@ suits:
917917
owasp_asvs: [ 8.3.4, 9.1.1 ]
918918
owasp_asvs_print: [ 8.3.4, 9.1.1 ]
919919
owasp_appsensor: [ "-" ]
920-
capec: [ 117, 153, 185, 186, 187 ]
920+
capec: [ 94, 117 ]
921921
safecode: [ 14, 29, 30 ]
922922
owasp_cre:
923923
owasp_asvs: [ 227-045, 745-045 ]
@@ -933,7 +933,7 @@ suits:
933933
owasp_asvs: [ 1.9.1, 6.2.1, 9.1.3, 9.2.2 ]
934934
owasp_asvs_print: [ 1.9.1, 6.2.1, 9.1.3, 9.2.2 ]
935935
owasp_appsensor: [ "-" ]
936-
capec: [ 212, 620 ]
936+
capec: [ 24, 620 ]
937937
safecode: [ 21, 29 ]
938938
owasp_cre:
939939
owasp_asvs: [ 527-034, '036-810', 248-646, 636-854 ]
@@ -949,7 +949,7 @@ suits:
949949
owasp_asvs: [ 1.9.1, 2.2.5, 2.5.1, 8.3.4, 8.3.6, 9.1.3, 9.2.2 ]
950950
owasp_asvs_print: [ 1.9.1, 2.2.5, 2.5.1, 8.3.4, 8.3.6, 9.1.3, 9.2.2 ]
951951
owasp_appsensor: [ "-" ]
952-
capec: [ 31, 57, 94, 102, 157, 158, 384, 466, 546 ]
952+
capec: [ 94, 102, 116, 117, 204 ]
953953
safecode: [ 29 ]
954954
owasp_cre:
955955
owasp_asvs: [ 527-034, 558-807, 270-634, 227-045, 715-304 , 248-646, 636-854 ]
@@ -997,7 +997,7 @@ suits:
997997
owasp_asvs: [ 6.2.2, 6.2.3, 6.3.1, 6.3.3 ]
998998
owasp_asvs_print: [ 6.2.2-3, 6.3.1, 6.3.3 ]
999999
owasp_appsensor: [ "-" ]
1000-
capec: [ 97 ]
1000+
capec: [ 97, 112, 461, 473 ]
10011001
safecode: [ 14, 21, 29, 32, 33 ]
10021002
owasp_cre:
10031003
owasp_asvs: [ 742-431, 674-425, 542-488, 664-571 ]
@@ -1013,7 +1013,7 @@ suits:
10131013
owasp_asvs: [ 6.3.3 ]
10141014
owasp_asvs_print: [ 6.3.3 ]
10151015
owasp_appsensor: [ "-" ]
1016-
capec: [ 97, 463 ]
1016+
capec: [ 97, 112, 463 ]
10171017
safecode: [ 14, 21, 29, 31, 32, 33 ]
10181018
owasp_cre:
10191019
owasp_asvs: [ 664-571 ]
@@ -1029,7 +1029,7 @@ suits:
10291029
owasp_asvs: [ 1.6.1, 1.6.2, 1.6.4, 2.10.4, 6.4.1, 6.4.2 ]
10301030
owasp_asvs_print: [ 1.6.1-2, 1.6.4, 2.10.4, 6.4.1-2 ]
10311031
owasp_appsensor: [ "-" ]
1032-
capec: [ 116 ]
1032+
capec: [ 37, 57, 155, 204, 474, 639 ]
10331033
safecode: [ 21, 29 ]
10341034
owasp_cre:
10351035
owasp_asvs: [ 287-305, 508-702, 232-325, 774-888, 340-375, '032-213' ]
@@ -1045,7 +1045,7 @@ suits:
10451045
owasp_asvs: [ 1.6.1, 1.6.2, 1.6.3, 6.2.3, 8.3.6 ]
10461046
owasp_asvs_print: [ 1.6.1-3, 6.2.3, 8.3.6 ]
10471047
owasp_appsensor: [ "-" ]
1048-
capec: [ 116, 117 ]
1048+
capec: [ 20, 37, 57, 97, 155, 204, 474, 639 ]
10491049
safecode: [ 21, 29 ]
10501050
owasp_cre:
10511051
owasp_asvs: [ 287-305, 508-702, 821-832, 674-425, 715-304 ]
@@ -1061,7 +1061,7 @@ suits:
10611061
owasp_asvs: [ 1.6.2, 6.2.5, 6.2.6, 6.2.7, 6.2.8 ]
10621062
owasp_asvs_print: [ 1.6.2, 6.2.5-8 ]
10631063
owasp_appsensor: [ "-" ]
1064-
capec: [ 94, 184, 207, 554 ]
1064+
capec: [ 184, 207, 444, 523 ]
10651065
safecode: [ 14, 21, 29 ]
10661066
owasp_cre:
10671067
owasp_asvs: [ 508-702, 441-132, 433-122, 786-224, 878-880 ]

0 commit comments

Comments
 (0)