From e507c9ca9f7965a9492f7d1afef4790ad82fdbf0 Mon Sep 17 00:00:00 2001 From: Riccardo Poffo Date: Tue, 4 Feb 2025 15:40:25 +0100 Subject: [PATCH] Update all CWE IDs on MASWE elements of MASVS-PLATFORM-3. --- weaknesses/MASVS-PLATFORM/MASWE-0053.md | 1 + weaknesses/MASVS-PLATFORM/MASWE-0054.md | 1 + weaknesses/MASVS-PLATFORM/MASWE-0055.md | 1 + weaknesses/MASVS-PLATFORM/MASWE-0056.md | 1 + 4 files changed, 4 insertions(+) diff --git a/weaknesses/MASVS-PLATFORM/MASWE-0053.md b/weaknesses/MASVS-PLATFORM/MASWE-0053.md index 03eda7264d..be045224ca 100644 --- a/weaknesses/MASVS-PLATFORM/MASWE-0053.md +++ b/weaknesses/MASVS-PLATFORM/MASWE-0053.md @@ -7,6 +7,7 @@ profiles: [L2] mappings: masvs-v1: [MSTG-STORAGE-7] masvs-v2: [MASVS-PLATFORM-3, MASVS-STORAGE-2] + cwe: [200, 359] draft: description: e.g. leaking passwords, PINs via the UI diff --git a/weaknesses/MASVS-PLATFORM/MASWE-0054.md b/weaknesses/MASVS-PLATFORM/MASWE-0054.md index 28619ba92f..5384a3a192 100644 --- a/weaknesses/MASVS-PLATFORM/MASWE-0054.md +++ b/weaknesses/MASVS-PLATFORM/MASWE-0054.md @@ -6,6 +6,7 @@ platform: [android, ios] profiles: [L2] mappings: masvs-v2: [MASVS-PLATFORM-3, MASVS-STORAGE-2] + cwe: [200, 359] draft: description: e.g. stealing pending intents from notifications via notificationlistenerservice diff --git a/weaknesses/MASVS-PLATFORM/MASWE-0055.md b/weaknesses/MASVS-PLATFORM/MASWE-0055.md index 6180ac853f..3f43c5e09f 100644 --- a/weaknesses/MASVS-PLATFORM/MASWE-0055.md +++ b/weaknesses/MASVS-PLATFORM/MASWE-0055.md @@ -7,6 +7,7 @@ profiles: [L2] mappings: masvs-v1: [MSTG-STORAGE-9] masvs-v2: [MASVS-PLATFORM-3, MASVS-STORAGE-2] + cwe: [200, 359] refs: - https://developer.android.com/about/versions/14/features/screenshot-detection diff --git a/weaknesses/MASVS-PLATFORM/MASWE-0056.md b/weaknesses/MASVS-PLATFORM/MASWE-0056.md index 05f9a3ad74..85f4c733c0 100644 --- a/weaknesses/MASVS-PLATFORM/MASWE-0056.md +++ b/weaknesses/MASVS-PLATFORM/MASWE-0056.md @@ -7,6 +7,7 @@ profiles: [L2] mappings: masvs-v1: [MSTG-PLATFORM-9] masvs-v2: [MASVS-PLATFORM-3, MASVS-CODE-1] + cwe: [1021] refs: - https://developer.android.com/topic/security/risks/tapjacking