Skip to content

Commit fd196dc

Browse files
authored
Merge pull request #1980 from OWASP/capec-asvs5-1
Mapping CAPEC to ASVS 5.0 for the Authorization suite
2 parents fd9280c + 14f3ab9 commit fd196dc

File tree

5 files changed

+222
-66
lines changed

5 files changed

+222
-66
lines changed

cornucopia.owasp.org/data/cards/webapp-cards-2.2-en/cryptography/CR7/explanation.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ Gunter targets an online service that uses encryption for data transmission. How
2020

2121
The primary applicable STRIDE categories for this scenario is **Information Disclosure** and **Tampering**.
2222

23-
Because Gunter can intercept and decrypt the data in transit due to weak protocol deployment, misconfigured SSL/TLS, or untrusted/invalid certificates. This is a confidentiality failure, but as he can also modify the encrypted data (MITM style, degrade the connection, or re-encrypt altered content), it also falls into **Tampering**.
23+
Because Gunter can intercept and decrypt the data in transit due to weak protocol deployment, misconfigured SSL/TLS, or untrusted/invalid certificates. This is a confidentiality failure, but as he can also modify the encrypted data (MITM style, degrade the connection, or re-encrypt altered content), it also falls into **Tampering**, finally, if cryptographic signatures is used and can be faked, the **Tampering** can also lead to **Spoofing**.
2424

2525
### What can go wrong?
2626

Binary file not shown.

source/webapp-cards-3.0-en.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -318,7 +318,7 @@ suits:
318318
id: "CR7"
319319
value: "7"
320320
url: "https://cornucopia.owasp.org/cards/CR7"
321-
desc: "Gunter can intercept or modify encrypted data in transit because the protocol is poorly deployed, or weakly configured, or certificates are invalid, or certificates are not trusted, or the connection can be degraded to a weaker or un-encrypted communication"
321+
desc: "Gunter can intercept or modify encrypted and/or hashed data in transit because the protocol is poorly deployed, or weakly configured, or certificates are invalid, or certificates are not trusted, or the connection can be degraded to a weaker or un-encrypted communication"
322322
-
323323
id: "CR8"
324324
value: "8"

source/webapp-mappings-2.2.yaml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -207,7 +207,7 @@ suits:
207207
owasp_asvs: [ 5.2.1, 5.2.2, 5.3.4, 5.3.7, 5.3.8, 5.3.9, 5.3.10 ]
208208
owasp_asvs_print: [ 5.2.1, 5.2.2, 5.3.4, 5.3.7-10 ]
209209
owasp_appsensor: [ CIE1, CIE2 ]
210-
capec: [ 19, 23, 28, 66, 83, 88, 93, 126, 136, 137, 153, 160, 183, 250, 253, 261, 664, 676 ]
210+
capec: [ 19, 23, 28, 66, 83, 88, 93, 126, 136, 137, 153, 160, 183, 201, 250, 253, 261, 664, 676 ]
211211
safecode: [ 2, 19, 20 ]
212212
owasp_cre:
213213
owasp_asvs: [ 542-445, 538-446, 732-873, 531-558, 857-718, 547-283, 134-207 ]
@@ -668,7 +668,7 @@ suits:
668668
owasp_asvs: [ 4.1.3, 4.2.1, 5.1.5 ]
669669
owasp_asvs_print: [ 4.1.3, 4.2.1, 5.1.5 ]
670670
owasp_appsensor: [ "-" ]
671-
capec: [ 94, 154, 161, 173, 240, 569 ]
671+
capec: [ 62, 94, 154, 157, 173, 240, 481, 569 ]
672672
safecode: [ 8, 10, 11 ]
673673
owasp_cre:
674674
owasp_asvs: [ 368-633, 304-667, 232-217 ]
@@ -684,7 +684,7 @@ suits:
684684
owasp_asvs: [ 4.1.3, 4.1.5, 8.1.2, 8.2.1, 8.3.1, 8.3.4, 8.3.6, 8.3.8, 12.4.1 ]
685685
owasp_asvs_print: [ 4.1.3, 4.1.5, 8.1.2, 8.2.1, 8.3.1, 8.3.4, 8.3.6, 8.3.8, 12.4.1 ]
686686
owasp_appsensor: [ "-" ]
687-
capec: [ 33, 69, 126, 213, 233 ]
687+
capec: [ 30, 69, 126, 204, 234 ]
688688
safecode: [ 8, 10, 11 ]
689689
owasp_cre:
690690
owasp_asvs: [ 368-633, 166-151, 157-430, 473-758, 186-540, 227-045, 715-304, 268-272, 307-111 ]
@@ -700,7 +700,7 @@ suits:
700700
owasp_asvs: [ 4.1.5 ]
701701
owasp_asvs_print: [ 4.1.5 ]
702702
owasp_appsensor: [ "-" ]
703-
capec: [ 122 ]
703+
capec: [ 180 ]
704704
safecode: [ 8, 10, 11 ]
705705
owasp_cre:
706706
owasp_asvs: [ 166-151 ]
@@ -718,7 +718,7 @@ suits:
718718
owasp_asvs_print: [ 1.2.2, 4.1.1, 4.1.3, 4.2.1 ]
719719
owasp_appsensor: [ ACE1, ACE2, ACE3, ACE4, HT2 ]
720720
owasp_appsensor_print: [ ACE1-4, HT2 ]
721-
capec: [ 13, 54, 58, 75, 87, 95, 122, 126, 143, 144, 149, 155, 203, 265 ]
721+
capec: [ 54, 58, 75, 77, 87, 122, 126, 143, 144, 149, 155, 203, 268 ]
722722
safecode: [ 8, 10, 11, 13 ]
723723
owasp_cre:
724724
owasp_asvs: [ 278-413, 650-560, 368-633, 304-667 ]
@@ -752,7 +752,7 @@ suits:
752752
owasp_asvs_print: [ 4.1.3, 4.2.1 ]
753753
owasp_appsensor: [ ACE1, ACE2, ACE3, ACE4 ]
754754
owasp_appsensor_print: [ ACE1-4 ]
755-
capec: [ 122, 212 ]
755+
capec: [ 58, 122, 212 ]
756756
safecode: [ 8, 10, 11 ]
757757
owasp_cre:
758758
owasp_asvs: [ 368-633, 304-667 ]
@@ -768,7 +768,7 @@ suits:
768768
owasp_asvs: [ 4.1.2, 4.2.1, 4.3.3, 7.3.4, 11.1.1, 11.1.2 ]
769769
owasp_asvs_print: [ 4.1.2, 4.2.1, 4.3.3, 7.3.4, 11.1.1-2 ]
770770
owasp_appsensor: [ ACE3 ]
771-
capec: [ 25, 31, 39, 74, 162, 166, 172, 207, 212, 240 ]
771+
capec: [ 39, 74, 162, 166, 172, 207, 212 ]
772772
safecode: [ 8, 10, 11, 12 ]
773773
owasp_cre:
774774
owasp_asvs: [ 368-633, 304-667, 284-521, 770-361, 534-605, 456-535 ]
@@ -785,7 +785,7 @@ suits:
785785
owasp_asvs_print: [ 11.1.3-4 ]
786786
owasp_appsensor: [ AE3, FIO1, FIO2, UT2, UT3, UT4, STE1, STE2, STE3 ]
787787
owasp_appsensor_print: [ AE3, FIO1-2, UT2-4, STE1-3 ]
788-
capec: [ 26, 29, 125, 212, 261, 469, 488 ]
788+
capec: [ 26, 125, 130, 212, 227, 469 ]
789789
safecode: [ 1, 35 ]
790790
owasp_cre:
791791
owasp_asvs: [ 746-705, 630-573 ]
@@ -802,7 +802,7 @@ suits:
802802
owasp_asvs_print: [ 1.1.6, 4.1.1 ]
803803
owasp_appsensor: [ ACE1, ACE2, ACE3, ACE4 ]
804804
owasp_appsensor_print: [ ACE1-4 ]
805-
capec: [ 36, 95, 121, 179, 554 ]
805+
capec: [ 1, 22, 36, 95, 121, 179, 180 ]
806806
safecode: [ 8, 10, 11 ]
807807
owasp_cre:
808808
owasp_asvs: [ 344-611, 650-560 ]
@@ -818,7 +818,7 @@ suits:
818818
owasp_asvs: [ 4.1.2, 10.2.3, 10.2.4, 10.2.5, 10.2.6 ]
819819
owasp_asvs_print: [ 4.1.2, 10.2.3-6 ]
820820
owasp_appsensor: [ "-" ]
821-
capec: [ 75, 116, 122, 133, 176, 180, 203 ]
821+
capec: [ 1, 11, 75, 116, 133, 176, 179, 180, 207 ]
822822
safecode: [ 8, 10, 11 ]
823823
owasp_cre:
824824
owasp_asvs: [ 368-633, 838-636, 418-525, 265-800, 154-031 ]
@@ -834,7 +834,7 @@ suits:
834834
owasp_asvs: [ 5.3.8 ]
835835
owasp_asvs_print: [ 5.3.8 ]
836836
owasp_appsensor: [ "-" ]
837-
capec: [ 17, 23, 30, 35, 66, 69, 88, 122, 136, 233, 234, 242, 248, 250, 676 ]
837+
capec: [ 35, 93, 122, 233, 242, 248 ]
838838
safecode: [ 8, 10, 11 ]
839839
owasp_cre:
840840
owasp_asvs: [ 857-718 ]
@@ -965,7 +965,7 @@ suits:
965965
owasp_asvs: [ 1.9.2, 6.2.7, 9.1.1, 9.2.1, 9.2.4, 14.4.5 ]
966966
owasp_asvs_print: [ 1.9.2, 6.2.7, 9.1.1, 9.2.1, 9.2.4, 14.4.5 ]
967967
owasp_appsensor: [ IE4 ]
968-
capec: [ 31, 90, 94, 114, 117, 212, 216, 220, 272, 594, 620 ]
968+
capec: [ 39, 94, 114, 145, 157, 216, 218, 220, 272, 594, 620 ]
969969
safecode: [ 14, 29, 30 ]
970970
owasp_cre:
971971
owasp_asvs: [ 530-671, 786-224, 745-045, 430-636, 537-367, '036-147' ]

0 commit comments

Comments
 (0)