Skip to content

Commit 1b0aa8f

Browse files
Updating IDOR's (#435)
* Updating IDOR's From: P1 – Broken Access Control (BAC) > Insecure Direct Object References (IDOR) > Read/Edit/Delete Sensitive Information/Iterable Object Identifiers P2 – Broken Access Control (BAC) > Insecure Direct Object References (IDOR) > Edit/Delete Sensitive Information/Iterable Object Identifiers P3 – Broken Access Control (BAC) > Insecure Direct Object References (IDOR) > Read Sensitive Information/Iterable Object Identifiers P4 – Broken Access Control (BAC) > Insecure Direct Object References (IDOR) > Read/Edit/Delete Sensitive Information/Complex Object Identifiers(GUID) P5 – Broken Access Control (BAC) > Insecure Direct Object References (IDOR) > Read/Edit/Delete Non-Sensitive Information To: P1 - Broken Access Control (BAC) > Insecure Direct Object References (IDOR) > Modify/View Sensitive Information(Iterable Object Identifiers) P2 - Broken Access Control (BAC) > Insecure Direct Object References (IDOR) > Modify Sensitive Information(Iterable Object Identifiers) P3 - Broken Access Control (BAC) > Insecure Direct Object References (IDOR) > View Sensitive Information(Iterable Object Identifiers) P4 - Broken Access Control (BAC) > Insecure Direct Object References (IDOR) > Modify/View Sensitive Information(Complex Object Identifiers GUID/UUID) P5 - Broken Access Control (BAC) > Insecure Direct Object References (IDOR) > View Non-Sensitive Information * Additional Files * Rebase changes --------- Co-authored-by: Abhinav Nain <[email protected]>
1 parent 23b179a commit 1b0aa8f

File tree

3 files changed

+33
-18
lines changed

3 files changed

+33
-18
lines changed

deprecated-node-mapping.json

+15
Original file line numberDiff line numberDiff line change
@@ -238,5 +238,20 @@
238238
},
239239
"server_security_misconfiguration.misconfigured_dns.subdomain_takeover": {
240240
"1.14.1": "server_security_misconfiguration.misconfigured_dns.basic_subdomain_takeover"
241+
},
242+
"broken_access_control.idor.view_non_sensitive_information": {
243+
"1.14.2": "broken_access_control.idor.read_edit_delete_non_sensitive_information"
244+
},
245+
"broken_access_control.idor.modify_view_sensitive_information_guid": {
246+
"1.14.2": "broken_access_control.idor.read_edit_delete_sensitive_information_guid"
247+
},
248+
"broken_access_control.idor.view_sensitive_information_iterable_object_identifiers": {
249+
"1.14.2": "broken_access_control.idor.read_sensitive_information_iterable_object_identifiers"
250+
},
251+
"broken_access_control.idor.modify_sensitive_information_iterable_object_identifiers": {
252+
"1.14.2": "broken_access_control.idor.edit_delete_sensitive_information_iterable_object_identifiers"
253+
},
254+
"broken_access_control.idor.modify_view_sensitive_information_iterable_object_identifiers": {
255+
"1.14.2": "broken_access_control.idor.read_edit_delete_sensitive_information_iterable_object_identifiers"
241256
}
242257
}

third-party-mappings/remediation_training/secure-code-warrior-links.json

+5-5
Original file line numberDiff line numberDiff line change
@@ -62,11 +62,11 @@
6262
"broken_access_control.exposed_sensitive_android_intent": "https://integration-api.securecodewarrior.com/api/v1/trial?id=bugcrowd&mappingList=vrt&mappingKey=broken_access_control:exposed_sensitive_android_intent&redirect=true",
6363
"broken_access_control.exposed_sensitive_ios_url_scheme": "https://integration-api.securecodewarrior.com/api/v1/trial?id=bugcrowd&mappingList=vrt&mappingKey=broken_access_control:exposed_sensitive_ios_url_scheme&redirect=true",
6464
"broken_access_control.idor": "https://integration-api.securecodewarrior.com/api/v1/trial?id=bugcrowd&mappingList=vrt&mappingKey=broken_access_control:idor&redirect=true",
65-
"broken_access_control.idor.edit_delete_sensitive_information_iterable_object_identifiers": null,
66-
"broken_access_control.idor.read_edit_delete_non_sensitive_information": null,
67-
"broken_access_control.idor.read_edit_delete_sensitive_information_guid": null,
68-
"broken_access_control.idor.read_edit_delete_sensitive_information_iterable_object_identifiers": null,
69-
"broken_access_control.idor.read_sensitive_information_iterable_object_identifiers": null,
65+
"broken_access_control.idor.modify_sensitive_information_iterable_object_identifiers": null,
66+
"broken_access_control.idor.modify_view_sensitive_information_guid": null,
67+
"broken_access_control.idor.modify_view_sensitive_information_iterable_object_identifiers": null,
68+
"broken_access_control.idor.view_non_sensitive_information": null,
69+
"broken_access_control.idor.view_sensitive_information_iterable_object_identifiers": null,
7070
"broken_access_control.privilege_escalation": null,
7171
"broken_access_control.username_enumeration": null,
7272
"broken_access_control.username_enumeration.non_brute_force": "https://integration-api.securecodewarrior.com/api/v1/trial?id=bugcrowd&mappingList=vrt&mappingKey=broken_access_control:username_enumeration:non_brute_force&redirect=true",

vulnerability-rating-taxonomy.json

+13-13
Original file line numberDiff line numberDiff line change
@@ -396,32 +396,32 @@
396396
"type": "subcategory",
397397
"children": [
398398
{
399-
"id": "edit_delete_sensitive_information_iterable_object_identifiers",
400-
"name": "Edit/Delete Sensitive Information/Iterable Object Identifiers",
399+
"id": "modify_sensitive_information_iterable_object_identifiers",
400+
"name": "Modify Sensitive Information(Iterable Object Identifiers)",
401401
"type": "variant",
402402
"priority": 2
403403
},
404404
{
405-
"id": "read_edit_delete_non_sensitive_information",
406-
"name": "Read/Edit/Delete Non-Sensitive Information",
405+
"id": "modify_view_sensitive_information_guid",
406+
"name": "Modify/View Sensitive Information(Complex Object Identifiers GUID/UUID)",
407407
"type": "variant",
408-
"priority": 5
408+
"priority": 4
409409
},
410410
{
411-
"id": "read_edit_delete_sensitive_information_guid",
412-
"name": "Read/Edit/Delete Sensitive Information/Complex Object Identifiers(GUID)",
411+
"id": "modify_view_sensitive_information_iterable_object_identifiers",
412+
"name": "Modify/View Sensitive Information(Iterable Object Identifiers)",
413413
"type": "variant",
414-
"priority": 4
414+
"priority": 1
415415
},
416416
{
417-
"id": "read_edit_delete_sensitive_information_iterable_object_identifiers",
418-
"name": "Read/Edit/Delete Sensitive Information/Iterable Object Identifiers",
417+
"id": "view_non_sensitive_information",
418+
"name": "View Non-Sensitive Information",
419419
"type": "variant",
420-
"priority": 1
420+
"priority": 5
421421
},
422422
{
423-
"id": "read_sensitive_information_iterable_object_identifiers",
424-
"name": "Read Sensitive Information/Iterable Object Identifiers",
423+
"id": "view_sensitive_information_iterable_object_identifiers",
424+
"name": "View Sensitive Information(Iterable Object Identifiers)",
425425
"type": "variant",
426426
"priority": 3
427427
}

0 commit comments

Comments
 (0)