From 55402e944a1daf4e81b4caadb891b1952fa27e74 Mon Sep 17 00:00:00 2001 From: Artur Ribeiro Date: Fri, 28 Jun 2024 15:07:46 +0100 Subject: [PATCH] add cwe infos to CICD queries --- assets/queries/cicd/github/run_block_injection/metadata.json | 2 +- .../queries/cicd/github/script_block_injection/metadata.json | 2 +- .../unpinned_actions_full_length_commit_sha/metadata.json | 2 +- assets/queries/cicd/github/unsecured_commands/metadata.json | 3 ++- 4 files changed, 5 insertions(+), 4 deletions(-) diff --git a/assets/queries/cicd/github/run_block_injection/metadata.json b/assets/queries/cicd/github/run_block_injection/metadata.json index bead191bc90..9a7be67f369 100644 --- a/assets/queries/cicd/github/run_block_injection/metadata.json +++ b/assets/queries/cicd/github/run_block_injection/metadata.json @@ -8,6 +8,6 @@ "platform": "CICD", "descriptionID": "02044a75", "cloudProvider": "common", - "cwe": "", + "cwe": "94", "oldSeverity": "HIGH" } \ No newline at end of file diff --git a/assets/queries/cicd/github/script_block_injection/metadata.json b/assets/queries/cicd/github/script_block_injection/metadata.json index 9d3804b732c..491980d2603 100644 --- a/assets/queries/cicd/github/script_block_injection/metadata.json +++ b/assets/queries/cicd/github/script_block_injection/metadata.json @@ -8,5 +8,5 @@ "platform": "CICD", "descriptionID": "63e215f4", "cloudProvider": "common", - "cwe": "" + "cwe": "94" } \ No newline at end of file diff --git a/assets/queries/cicd/github/unpinned_actions_full_length_commit_sha/metadata.json b/assets/queries/cicd/github/unpinned_actions_full_length_commit_sha/metadata.json index ccd1c0c0314..9ecf6f06dd7 100644 --- a/assets/queries/cicd/github/unpinned_actions_full_length_commit_sha/metadata.json +++ b/assets/queries/cicd/github/unpinned_actions_full_length_commit_sha/metadata.json @@ -8,6 +8,6 @@ "platform": "CICD", "descriptionID": "9cb8402d", "cloudProvider": "common", - "cwe": "", + "cwe": "829", "oldSeverity": "MEDIUM" } \ No newline at end of file diff --git a/assets/queries/cicd/github/unsecured_commands/metadata.json b/assets/queries/cicd/github/unsecured_commands/metadata.json index 35e8abba232..8151792913a 100644 --- a/assets/queries/cicd/github/unsecured_commands/metadata.json +++ b/assets/queries/cicd/github/unsecured_commands/metadata.json @@ -8,5 +8,6 @@ "platform": "CICD", "descriptionID": "44751f79", "cloudProvider": "common", - "cwe": "" + "oldSeverity": "MEDIUM", + "cwe": "78" } \ No newline at end of file