Skip to content

Conversation

@abhinav-nain
Copy link
Collaborator

@abhinav-nain abhinav-nain commented Aug 18, 2025

Q3'25 Release

Adding:

Cloud Security > Identity and Access Management (IAM) Misconfigurations > Overly Permissive IAM Roles > P2
Cloud Security > Identity and Access Management (IAM) Misconfigurations > Publicly Accessible IAM Credentials > P1
Cloud Security > Storage Misconfigurations > Publicly Accessible Cloud Storage > Varies
Cloud Security > Storage Misconfigurations > Unencrypted Sensitive Data at Rest > P2
Cloud Security > Network Configuration Issues > Open Management Ports to the Internet > P3
Cloud Security > Network Configuration Issues > Lack of Network Segmentation > P3
Cloud Security > Misconfigured Services and APIs > Exposed Debug or Admin Interfaces > Varies
Cloud Security > Misconfigured Services and APIs > Insecure API Endpoints > P4
Cloud Security > Logging and Monitoring Issues > Disabled or Insufficient Logging > P5
Server-Side Injection > Exposed Data > Non-Sensitive Data > P5
Server-Side Injection > Exposed Data > Sensitive Data > Varies
Server Security Misconfiguration > Exposed Portal > Protected > P5
Server Security Misconfiguration > Exposed Portal > Admin Portal > P1
Server Security Misconfiguration > Exposed Portal > Non-Admin Portal > P3

Remove

Server Security Misconfiguration > Exposed Admin Portal > To Internet > P3

Checklist:

  • I have added entries to CHANGELOG.md and marked it Added/Changed/Removed
  • I have made corresponding changes to the documentation (if needed)

TimmyBugcrowd and others added 4 commits August 18, 2025 09:03
* Update vulnerability-rating-taxonomy.json

* Update vulnerability-rating-taxonomy.json

Small spelling update

---------

Co-authored-by: RRudder <96507400+RRudder@users.noreply.github.com>
* Update vulnerability-rating-taxonomy.json

* Updates
* Admin Portal Expansion

Add:
Server Security Misconfiguration - Exposed Portal - Protected - P5
Server Security Misconfiguration - Exposed Portal - Admin Portal - P1
Server Security Misconfiguration - Exposed Portal - Non-Admin Portal - P3

Remove:
Server Security Misconfiguration - Exposed Admin Portal - To Internet - P3

* Indicators of Attack

Adding Indicators of Attack based on this: #466 issue.

* Revert "Indicators of Attack"

This reverts commit 3e0c017.
@abhinav-nain abhinav-nain requested a review from nnons August 18, 2025 04:44
Copy link

@nnons nnons left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@nnons nnons merged commit 159790e into master Aug 18, 2025
3 checks passed
@nnons nnons deleted the q3-25-release-1 branch August 18, 2025 13:52
@abhinav-nain abhinav-nain mentioned this pull request Aug 18, 2025
4 tasks
Copy link

@gigako1981 gigako1981 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Owner GIORGI MESKHIDZE ``

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants