Skip to content

Conversation

TimmyBugcrowd
Copy link
Contributor

Add:
Broken Access Control (BAC) - Bypass of Password Confirmation - Change Password

Add:
Broken Access Control – Bypass of Password Confirmation – Change Password
@TimmyBugcrowd TimmyBugcrowd changed the title Q2 25 release mapping changes Broken Access Control (BAC) - Bypass of Password Confirmation - Change Password May 4, 2025
@abhinav-nain abhinav-nain changed the base branch from master to q2-25-release-mapping June 20, 2025 08:54
@abhinav-nain abhinav-nain merged commit ed709df into q2-25-release-mapping Jun 20, 2025
1 check passed
@abhinav-nain abhinav-nain deleted the q2-25-release-mapping-changes branch June 20, 2025 08:55
nnons pushed a commit that referenced this pull request Jun 20, 2025
* GraphQL Introspection Enabled - P5

#450

* Bypass of Password Confirmation on Password Change

Add:
Broken Access Control – Bypass of Password Confirmation – Change Password

* Revert "Bypass of Password Confirmation on Password Change"

This reverts commit a6e415a.

* Bypass of Password Confirmation on Password Change

Add:
Broken Access Control – Bypass of Password Confirmation – Change Password

* Revert "Bypass of Password Confirmation on Password Change"

This reverts commit 3418212.

* Broken Access Control (BAC) - Bypass of Password Confirmation - Change Password (#462)

* Revert "Bypass of Password Confirmation on Password Change"

This reverts commit 3418212.

* Bypass of Password Confirmation on Password Change

Add:
Broken Access Control – Bypass of Password Confirmation – Change Password

* AI entries revised (#464)

* AI entries revised

Adding:
P1 - AI Application Security - Training Data Poisoning - Backdoor Injection / Bias Manipulation
P1 - AI Application Security - Model Extraction - API Query-Based Model Reconstruction
P1 - AI Application Security - Sensitive Information Disclosure - Cross-Tenant PII Leakage/Exposure
P1 - AI Application Security - Remote Code Execution - Full System Compromise
P1 - AI Application Security - Sensitive Information Disclosure - Key Leak
P2 - AI Application Security - Remote Code Execution - Sandboxed Container Code Execution
P2 - AI Application Security - Prompt Injection - System Prompt Leakage
P2 - AI Application Security - Vector and Embedding Weaknesses - Embedding Exfiltration / Model Extraction
P2 - AI Application Security - Denial-of-Service (DoS) - Application-Wide
P3 - AI Application Security - Vector and Embedding Weaknesses - Semantic Indexing
P3 - AI Application Security - Improper Output Handling - Cross-Site Scripting (XSS)
P4 - AI Application Security - Improper Output Handling - Markdown/HTML Injection
P4 - AI Application Security - AI Safety - Misinformation / Wrong Factual Data
P4 - AI Application Security - Insufficient Rate Limiting - Query Flooding / API Token Abuse
P4 - AI Application Security - Denial-of-Service (DoS) - Tenant-Scoped
P4 - AI Application Security - Adversarial Example Injection - AI Misclassification Attacks
P5 - AI Application Security - Improper Input Handling - ANSI Escape Codes
P5 - AI Application Security - Improper Input Handling - Unicode Confusables
P5 - AI Application Security - Improper Input Handling - RTL Overrides

* Update vulnerability-rating-taxonomy.json

* Fixing errors

* Fixing errors2

* Update vulnerability-rating-taxonomy.json

* Update vulnerability-rating-taxonomy.json

* Update vulnerability-rating-taxonomy.json

* Update vulnerability-rating-taxonomy.json

* Update vulnerability-rating-taxonomy.json

* Update cvss_v3.json

* Fixed deprecated node mapping (#457)

* Updated varies to default and removed redundant entries (#461)

* Updated varies to default and removed redundant entries

* Reverting some changes

---------

Co-authored-by: Abhinav Nain <[email protected]>

* Final Changes - Adding Changelog + deprecated-node-mappings + ALL JSON Sorting + SCW

---------

Co-authored-by: SamAtBugcrowd <[email protected]>
Co-authored-by: Abhinav Nain <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants