github / github/codeql

[JS] CWE-326 ECB

未關閉
#12,600 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

Hello, I am a college student currently working on a senior project.

Looking through your javascript security queries, I noticed that CWE-326 only had one query and was not as fleshed out as the description on MITRE.

One particular thing that was the insecurity of ECB mode as referenced in MITRE's link ([CVE-2002-1697](https://www.cve.org/CVERecord?id=CVE-2002-1697))

I am aware that ECB mode is restricted by other queries; however, it did not seem to be referenced in your CWE-326. Is this something that is being worked on or something I could add?

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。