github / github/codeql

[JS] CWE-326 ECB

Abierto
#12,600 2 comentarios 0 reacciones 0 asignados Ver en GitHub
question
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

Hello, I am a college student currently working on a senior project.

Looking through your javascript security queries, I noticed that CWE-326 only had one query and was not as fleshed out as the description on MITRE.

One particular thing that was the insecurity of ECB mode as referenced in MITRE's link ([CVE-2002-1697](https://www.cve.org/CVERecord?id=CVE-2002-1697))

I am aware that ECB mode is restricted by other queries; however, it did not seem to be referenced in your CWE-326. Is this something that is being worked on or something I could add?

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.