Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update(query): add CWE infos to openAPI queries #7181

Merged
merged 11 commits into from
Sep 18, 2024
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#schema",
"platform": "OpenAPI",
"descriptionID": "c97fafa0",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#parameterObject",
"platform": "OpenAPI",
"descriptionID": "93b15115",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#parameterObject",
"platform": "OpenAPI",
"descriptionID": "3074f818",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#schemaObject",
"platform": "OpenAPI",
"descriptionID": "63cd2785",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#operation-object",
"platform": "OpenAPI",
"descriptionID": "f6b7b31a",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#swaggerObject",
"platform": "OpenAPI",
"descriptionID": "11bb39ad",
"cwe": ""
"cloudProvider": "common",
"cwe": "319"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#securityRequirementObject",
"platform": "OpenAPI",
"descriptionID": "14a00e4a",
"cwe": ""
"cloudProvider": "common",
"cwe": "285"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#swagger-object",
"platform": "OpenAPI",
"descriptionID": "d11c994c",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#securitySchemeObject",
"platform": "OpenAPI",
"descriptionID": "a879610a",
"cwe": ""
"cloudProvider": "common",
"cwe": "285"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/#media-type-object",
"platform": "OpenAPI",
"descriptionID": "bde04b9d",
"cwe": ""
"cloudProvider": "common",
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#security-scheme-object",
"platform": "OpenAPI",
"descriptionID": "d6163b1e",
"cwe": ""
"cloudProvider": "common",
"cwe": "284"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#securitySchemeObject",
"platform": "OpenAPI",
"descriptionID": "720629e5",
"cwe": ""
"cloudProvider": "common",
"cwe": "285"
}
Original file line number Diff line number Diff line change
@@ -1,11 +1,12 @@
{
"id": "fb889ae9-2d16-40b5-b41f-9da716c5abc1",
"queryName": "Parameter JSON Reference Does Not Exists (v2)",
"queryName": "Parameter JSON Reference Does Not Exist (v2)",
"severity": "INFO",
"category": "Structure and Semantics",
"descriptionText": "Parameter reference should exist on parameters definition field",
"descriptionUrl": "https://swagger.io/specification/v2/#parameterObject",
"platform": "OpenAPI",
"descriptionID": "7260680f",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
[
{
"queryName": "Parameter JSON Reference Does Not Exists (v2)",
"queryName": "Parameter JSON Reference Does Not Exist (v2)",
"severity": "INFO",
"line": 19,
"filename": "positive1.json"
},
{
"queryName": "Parameter JSON Reference Does Not Exists (v2)",
"queryName": "Parameter JSON Reference Does Not Exist (v2)",
"severity": "INFO",
"line": 14,
"filename": "positive2.yaml"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#responsesDefinitionsObject",
"platform": "OpenAPI",
"descriptionID": "213a6df0",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
@@ -1,11 +1,12 @@
{
"id": "98295b32-ec09-4b5b-89a9-39853197f914",
"queryName": "Schema JSON Reference Does Not Exists (v2)",
"queryName": "Schema JSON Reference Does Not Exist (v2)",
"severity": "INFO",
"category": "Structure and Semantics",
"descriptionText": "Schema reference should exists on definitions field",
"descriptionText": "Schema reference should exist on definitions field",
"descriptionUrl": "https://swagger.io/specification/v2/#definitionsObject",
"platform": "OpenAPI",
"descriptionID": "6da8f0da",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
[
{
"queryName": "Schema JSON Reference Does Not Exists (v2)",
"queryName": "Schema JSON Reference Does Not Exist (v2)",
"severity": "INFO",
"line": 15,
"filename": "positive1.json"
},
{
"queryName": "Schema JSON Reference Does Not Exists (v2)",
"queryName": "Schema JSON Reference Does Not Exist (v2)",
"severity": "INFO",
"line": 14,
"filename": "positive2.yaml"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#parameterObject",
"platform": "OpenAPI",
"descriptionID": "817fa38a",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#parameterObject",
"platform": "OpenAPI",
"descriptionID": "e0b264a9",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#parameterObject",
"platform": "OpenAPI",
"descriptionID": "e135be5b",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
"descriptionUrl": "https://swagger.io/specification/v2/#securityRequirementObject",
"platform": "OpenAPI",
"descriptionID": "33e1e674",
"cwe": "",
"cloudProvider": "common",
"cwe": "20",
"oldSeverity": "HIGH"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/",
"platform": "OpenAPI",
"descriptionID": "0bc1b81e",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#exampleObject",
"platform": "OpenAPI",
"descriptionID": "77f2d405",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#parameterObject",
"platform": "OpenAPI",
"descriptionID": "007c8e83",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,10 @@
"queryName": "Operation Object Without 'consumes'",
"severity": "MEDIUM",
"category": "Insecure Configurations",
"descriptionText": "Operation Object should have 'consumes' feild defined for 'POST', 'PUT' and 'PATCH' operations",
"descriptionText": "Operation Object should have 'consumes' field defined for 'POST', 'PUT' and 'PATCH' operations",
"descriptionUrl": "https://swagger.io/specification/v2/#operation-object",
"platform": "OpenAPI",
"descriptionID": "de859594",
"cwe": ""
"cloudProvider": "common",
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,10 @@
"queryName": "Operation Object Without 'produces'",
"severity": "MEDIUM",
"category": "Insecure Configurations",
"descriptionText": "Operation Object should have 'produces' feild defined for 'GET'operation",
"descriptionText": "Operation Object should have 'produces' field defined for 'GET'operation",
"descriptionUrl": "https://swagger.io/specification/v2/#operation-object",
"platform": "OpenAPI",
"descriptionID": "1736226c",
"cwe": ""
"cloudProvider": "common",
"cwe": "665"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
"descriptionUrl": "https://swagger.io/specification/v2/#operation-object",
"platform": "OpenAPI",
"descriptionID": "60a0b99e",
"cwe": "",
"cloudProvider": "common",
"cwe": "710",
"oldSeverity": "LOW"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
"descriptionUrl": "https://swagger.io/specification/v2/#operation-object",
"platform": "OpenAPI",
"descriptionID": "bb3bb0b3",
"cwe": "",
"cloudProvider": "common",
"cwe": "284",
"oldSeverity": "LOW"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
"descriptionUrl": "https://swagger.io/specification/v2/#operation-object",
"platform": "OpenAPI",
"descriptionID": "5f7dafc1",
"cwe": "",
"cloudProvider": "common",
"cwe": "284",
"oldSeverity": "LOW"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#operation-object",
"platform": "OpenAPI",
"descriptionID": "e0279bb3",
"cloudProvider": "common",
"cwe": ""
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#parameterObject",
"platform": "OpenAPI",
"descriptionID": "e8a62738",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#parameter-object",
"platform": "OpenAPI",
"descriptionID": "9b33f092",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#operationObject",
"platform": "OpenAPI",
"descriptionID": "4ac6f671",
"cwe": ""
"cloudProvider": "common",
"cwe": "319"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#schemaObject",
"platform": "OpenAPI",
"descriptionID": "eb2e14e6",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#responses-object",
"platform": "OpenAPI",
"descriptionID": "7a486064",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#schema-object",
"platform": "OpenAPI",
"descriptionID": "8389f514",
"cwe": ""
"cloudProvider": "common",
"cwe": "20"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#schema-object",
"platform": "OpenAPI",
"descriptionID": "2509db0d",
"cwe": ""
"cloudProvider": "common",
"cwe": "710"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#swaggerObject",
"platform": "OpenAPI",
"descriptionID": "34948b49",
"cwe": ""
"cloudProvider": "common",
"cwe": "319"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#securitySchemeObject",
"platform": "OpenAPI",
"descriptionID": "7b681b12",
"cwe": ""
"cloudProvider": "common",
"cwe": "285"
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@
"descriptionUrl": "https://swagger.io/specification/v2/#securityDefinitionsObject",
"platform": "OpenAPI",
"descriptionID": "170dbeca",
"cwe": ""
"cloudProvider": "common",
"cwe": "284"
}
Loading
Loading