Skip to content

Commit e7829b1

Browse files
authored
Merge pull request #6153 from kingthorin/cwe-8714
ascanrulesBeta: Replace usage of CWE-200
2 parents 538b409 + 9c10e50 commit e7829b1

File tree

3 files changed

+4
-3
lines changed

3 files changed

+4
-3
lines changed

addOns/ascanrulesBeta/CHANGELOG.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,8 @@ All notable changes to this add-on will be documented in this file.
44
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/).
55

66
## Unreleased
7-
7+
### Changed
8+
- Replace usage of CWE-200 for the Insecure HTTP Method scan rule (Issue 8714).
89

910
## [57] - 2025-01-15
1011
### Changed

addOns/ascanrulesBeta/src/main/java/org/zaproxy/zap/extension/ascanrulesBeta/InsecureHttpMethodScanRule.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -336,7 +336,7 @@ public int getRisk() {
336336

337337
@Override
338338
public int getCweId() {
339-
return 200; // Information Exposure (primarily via TRACK / TRACE)
339+
return 749; // CWE-749: Exposed Dangerous Method or Function
340340
}
341341

342342
@Override

addOns/ascanrulesBeta/src/test/java/org/zaproxy/zap/extension/ascanrulesBeta/InsecureHttpMethodScanRuleUnitTest.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -114,7 +114,7 @@ void shouldReturnExpectedMappings() {
114114
int wasc = rule.getWascId();
115115
Map<String, String> tags = rule.getAlertTags();
116116
// Then
117-
assertThat(cwe, is(equalTo(200)));
117+
assertThat(cwe, is(equalTo(749)));
118118
assertThat(wasc, is(equalTo(45)));
119119
assertThat(tags.size(), is(equalTo(5)));
120120
assertThat(

0 commit comments

Comments
 (0)