github / github/codeql

[JS] CWE-326 ECB

オープン
#12,600 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
question
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

Hello, I am a college student currently working on a senior project.

Looking through your javascript security queries, I noticed that CWE-326 only had one query and was not as fleshed out as the description on MITRE.

One particular thing that was the insecurity of ECB mode as referenced in MITRE's link ([CVE-2002-1697](https://www.cve.org/CVERecord?id=CVE-2002-1697))

I am aware that ECB mode is restricted by other queries; however, it did not seem to be referenced in your CWE-326. Is this something that is being worked on or something I could add?

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。