Skip to content

Commit 7ee373f

Browse files
committed
Deployed 2144d00 with MkDocs version: 1.5.3
1 parent 283a00d commit 7ee373f

File tree

49 files changed

+188
-162
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

49 files changed

+188
-162
lines changed

404.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1057,7 +1057,7 @@
10571057

10581058

10591059
<span class="md-ellipsis">
1060-
CWE Abstraction
1060+
CWE Relationships
10611061
</span>
10621062

10631063

annex/Glossary/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1061,7 +1061,7 @@
10611061

10621062

10631063
<span class="md-ellipsis">
1064-
CWE Abstraction
1064+
CWE Relationships
10651065
</span>
10661066

10671067

404 KB
Loading

cisa_kev/cisa_kev/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1135,7 +1135,7 @@
11351135

11361136

11371137
<span class="md-ellipsis">
1138-
CWE Abstraction
1138+
CWE Relationships
11391139
</span>
11401140

11411141

cvss/CVSS/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1216,7 +1216,7 @@
12161216

12171217

12181218
<span class="md-ellipsis">
1219-
CWE Abstraction
1219+
CWE Relationships
12201220
</span>
12211221

12221222

cwe/cwe/index.html

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1153,7 +1153,7 @@
11531153

11541154

11551155
<span class="md-ellipsis">
1156-
CWE Abstraction
1156+
CWE Relationships
11571157
</span>
11581158

11591159

@@ -1798,7 +1798,7 @@
17981798
<h1 id="common-weakness-enumeration-cwe">Common Weakness Enumeration (<abbr title="CWE Common Weakness Enumeration">CWE</abbr>)<a class="headerlink" href="#common-weakness-enumeration-cwe" title="Permanent link">&para;</a></h1>
17991799
<div class="admonition abstract">
18001800
<p class="admonition-title">Overview</p>
1801-
<p>The Common Weakness Enumeration (<abbr title="CWE Common Weakness Enumeration">CWE</abbr>) is a community-driven catalog of software and hardware weaknesses, maintained by MITRE. It serves as a standardized language and baseline for identifying, describing, and understanding common security flaws in software and hardware architecture, design, code, and implementation. </p>
1801+
<p>The <a href="https://cwe.mitre.org">Common Weakness Enumeration (<abbr title="CWE Common Weakness Enumeration">CWE</abbr>)</a> is a community-driven catalog of software and hardware weaknesses, maintained by MITRE. It serves as a standardized language and baseline for identifying, describing, and understanding common security flaws in software and hardware architecture, design, code, and implementation. </p>
18021802
<p>By providing a common taxonomy, <abbr title="CWE Common Weakness Enumeration">CWE</abbr> facilitates consistent security vulnerability reporting, enables better tool integration, and supports data-driven analysis of security trends. </p>
18031803
<p>Leveraging <abbr title="CWE Common Weakness Enumeration">CWE</abbr> is fundamental to shifting security left, allowing organizations to proactively address the root causes of vulnerabilities and build more secure systems.</p>
18041804
</div>
@@ -1913,13 +1913,13 @@ <h2 id="challenges-in-using-cwe">Challenges in Using <abbr title="CWE Common Wea
19131913

19141914

19151915

1916-
<a href="../cwe_abstraction/" class="md-footer__link md-footer__link--next" aria-label="Next: CWE Abstraction">
1916+
<a href="../cwe_abstraction/" class="md-footer__link md-footer__link--next" aria-label="Next: CWE Relationships">
19171917
<div class="md-footer__title">
19181918
<span class="md-footer__direction">
19191919
Next
19201920
</span>
19211921
<div class="md-ellipsis">
1922-
CWE Abstraction
1922+
CWE Relationships
19231923
</div>
19241924
</div>
19251925
<div class="md-footer__button md-icon">

cwe/cwe_1000/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1068,7 +1068,7 @@
10681068

10691069

10701070
<span class="md-ellipsis">
1071-
CWE Abstraction
1071+
CWE Relationships
10721072
</span>
10731073

10741074

cwe/cwe_abstraction/index.html

Lines changed: 58 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@
2222

2323

2424

25-
<title>CWE Abstraction - Risk Based Prioritization</title>
25+
<title>CWE Relationships - Risk Based Prioritization</title>
2626

2727

2828

@@ -104,7 +104,7 @@
104104
<div data-md-component="skip">
105105

106106

107-
<a href="#cwe-abstraction" class="md-skip">
107+
<a href="#cwe-relationships" class="md-skip">
108108
Skip to content
109109
</a>
110110

@@ -140,7 +140,7 @@
140140
<div class="md-header__topic" data-md-component="header-topic">
141141
<span class="md-ellipsis">
142142

143-
CWE Abstraction
143+
CWE Relationships
144144

145145
</span>
146146
</div>
@@ -1077,7 +1077,7 @@
10771077

10781078

10791079
<span class="md-ellipsis">
1080-
CWE Abstraction
1080+
CWE Relationships
10811081
</span>
10821082

10831083

@@ -1088,7 +1088,7 @@
10881088

10891089

10901090
<span class="md-ellipsis">
1091-
CWE Abstraction
1091+
CWE Relationships
10921092
</span>
10931093

10941094

@@ -1161,6 +1161,15 @@
11611161
</span>
11621162
</a>
11631163

1164+
</li>
1165+
1166+
<li class="md-nav__item">
1167+
<a href="#vulnerability-mapping-label-and-notes" class="md-nav__link">
1168+
<span class="md-ellipsis">
1169+
Vulnerability Mapping Label and Notes
1170+
</span>
1171+
</a>
1172+
11641173
</li>
11651174

11661175
</ul>
@@ -1796,6 +1805,15 @@
17961805
</span>
17971806
</a>
17981807

1808+
</li>
1809+
1810+
<li class="md-nav__item">
1811+
<a href="#vulnerability-mapping-label-and-notes" class="md-nav__link">
1812+
<span class="md-ellipsis">
1813+
Vulnerability Mapping Label and Notes
1814+
</span>
1815+
</a>
1816+
17991817
</li>
18001818

18011819
</ul>
@@ -1813,15 +1831,15 @@
18131831

18141832

18151833

1816-
<h1 id="cwe-abstraction"><abbr title="CWE Common Weakness Enumeration">CWE</abbr> Abstraction<a class="headerlink" href="#cwe-abstraction" title="Permanent link">&para;</a></h1>
1834+
<h1 id="cwe-relationships"><abbr title="CWE Common Weakness Enumeration">CWE</abbr> Relationships<a class="headerlink" href="#cwe-relationships" title="Permanent link">&para;</a></h1>
18171835
<div class="admonition abstract">
18181836
<p class="admonition-title">Overview</p>
1819-
<p>MITRE's <abbr title="CWE Common Weakness Enumeration">CWE</abbr> framework categorizes weaknesses into four abstraction levels: <a href="https://cwe.mitre.org/documents/glossary/index.html#Pillar%20Weakness">Pillar</a>, <a href="https://cwe.mitre.org/documents/glossary/index.html#Class%20Weakness">Class</a>, <a href="https://cwe.mitre.org/documents/glossary/index.html#Base%20Weakness">Base</a>, and <a href="https://cwe.mitre.org/documents/glossary/index.html#Variant%20Weakness">Variant</a>:</p>
1837+
<p>MITRE's <abbr title="CWE Common Weakness Enumeration">CWE</abbr> framework categorizes weaknesses into four abstraction levels: </p>
18201838
<ul>
1821-
<li>Pillar: Highest abstraction (broad vulnerability concepts).</li>
1822-
<li>Class: Group related vulnerabilities around common behaviors.</li>
1823-
<li>Base: Specific weaknesses directly used in practical mappings.</li>
1824-
<li>Variant: More specific instances of Base weaknesses (context-specific or subtle distinctions).</li>
1839+
<li><a href="https://cwe.mitre.org/documents/glossary/index.html#Pillar%20Weakness">Pillar</a>: Highest abstraction (broad vulnerability concepts).</li>
1840+
<li><a href="https://cwe.mitre.org/documents/glossary/index.html#Class%20Weakness">Class</a>: Group related vulnerabilities around common behaviors.</li>
1841+
<li><a href="https://cwe.mitre.org/documents/glossary/index.html#Base%20Weakness">Base</a>: Specific weaknesses directly used in practical mappings.</li>
1842+
<li><a href="https://cwe.mitre.org/documents/glossary/index.html#Variant%20Weakness">Variant</a>: More specific instances of Base weaknesses (context-specific or subtle distinctions).</li>
18251843
</ul>
18261844
<p>Each level provides a different degree of specificity, aiding different practical purposes from research to vulnerability remediation.</p>
18271845
<p>Refer to the official schema: <a href="https://cwe.mitre.org/documents/schema/#AbstractionEnumeration">AbstractionEnumeration</a>.</p>
@@ -1839,8 +1857,8 @@ <h2 id="pillar">Pillar ⚠️<a class="headerlink" href="#pillar" title="Permane
18391857
<li>
18401858
<p>Examples:</p>
18411859
<ul>
1842-
<li><strong><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-284:</strong> Improper Access Control</li>
1843-
<li><strong><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-682:</strong> Incorrect Calculation</li>
1860+
<li><strong><a href="https://cwe.mitre.org/data/definitions/284.html"><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-284</a>:</strong> Improper Access Control</li>
1861+
<li><strong><a href="https://cwe.mitre.org/data/definitions/682.html"><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-682</a>:</strong> Incorrect Calculation</li>
18441862
</ul>
18451863
</li>
18461864
</ul>
@@ -1854,8 +1872,8 @@ <h2 id="class">Class 🗂️<a class="headerlink" href="#class" title="Permanent
18541872
<li>
18551873
<p>Examples:</p>
18561874
<ul>
1857-
<li><strong><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-20:</strong> Improper Input Validation</li>
1858-
<li><strong><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-200:</strong> Exposure of Sensitive Information</li>
1875+
<li><strong><a href="https://cwe.mitre.org/data/definitions/20.html"><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-20</a>:</strong> Improper Input Validation</li>
1876+
<li><strong><a href="https://cwe.mitre.org/data/definitions/200.html"><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-200</a>:</strong> Exposure of Sensitive Information</li>
18591877
</ul>
18601878
</li>
18611879
</ul>
@@ -1870,9 +1888,9 @@ <h2 id="base">Base 🎯<a class="headerlink" href="#base" title="Permanent link"
18701888
<li>
18711889
<p>Examples:</p>
18721890
<ul>
1873-
<li><strong><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-79:</strong> Cross-Site Scripting (XSS)</li>
1874-
<li><strong><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-89:</strong> SQL Injection</li>
1875-
<li><strong><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-787:</strong> Out-of-Bounds Write</li>
1891+
<li><strong><a href="https://cwe.mitre.org/data/definitions/79.html"><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-79</a>:</strong> Cross-Site Scripting (XSS)</li>
1892+
<li><strong><a href="https://cwe.mitre.org/data/definitions/89.html"><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-89</a>:</strong> SQL Injection</li>
1893+
<li><strong><a href="https://cwe.mitre.org/data/definitions/787.html"><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-787</a>:</strong> Out-of-Bounds Write</li>
18761894
</ul>
18771895
</li>
18781896
</ul>
@@ -1886,8 +1904,8 @@ <h2 id="variant">Variant 🔬<a class="headerlink" href="#variant" title="Perman
18861904
<li>
18871905
<p>Examples:</p>
18881906
<ul>
1889-
<li><strong><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-599:</strong> Missing Validation of OpenSSL Certificate</li>
1890-
<li><strong><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-467:</strong> Use of <code>sizeof()</code> on a Pointer Type (C/C++)</li>
1907+
<li><strong><a href="https://cwe.mitre.org/data/definitions/599.html"><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-599</a>:</strong> Missing Validation of OpenSSL Certificate</li>
1908+
<li><strong><a href="https://cwe.mitre.org/data/definitions/467.html"><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-467</a>:</strong> Use of <code>sizeof()</code> on a Pointer Type (C/C++)</li>
18911909
</ul>
18921910
</li>
18931911
</ul>
@@ -1905,6 +1923,26 @@ <h2 id="compound">Compound 🔗<a class="headerlink" href="#compound" title="Per
19051923
<p><strong>Compound CWEs</strong> help analyze complex vulnerability scenarios, providing insights into how weaknesses interrelate.</p>
19061924
</div>
19071925
<hr />
1926+
<h2 id="vulnerability-mapping-label-and-notes"><a href="https://cwe.mitre.org/documents/schema/#MappingNotesType">Vulnerability Mapping Label and Notes</a><a class="headerlink" href="#vulnerability-mapping-label-and-notes" title="Permanent link">&para;</a></h2>
1927+
<p>Vulnerability Mapping Label:</p>
1928+
<ul>
1929+
<li>ALLOWED (this <abbr title="CWE Common Weakness Enumeration">CWE</abbr> ID could be used to map to real-world vulnerabilities)</li>
1930+
<li>ALLOWED (with careful review of mapping notes)</li>
1931+
<li>DISCOURAGED (this <abbr title="CWE Common Weakness Enumeration">CWE</abbr> ID should not be used to map to real-world vulnerabilities)</li>
1932+
<li>PROHIBITED (this <abbr title="CWE Common Weakness Enumeration">CWE</abbr> ID must not be used to map to real-world vulnerabilities)</li>
1933+
</ul>
1934+
<p>See <a href="https://cwe.mitre.org/documents/cwe_usage/guidance.html#relationships">https://cwe.mitre.org/documents/cwe_usage/guidance.html#relationships</a>.</p>
1935+
<figure>
1936+
<p><img alt="" src="../../assets/images/vulnerability_mapping_notes.png" width="600" />
1937+
</p>
1938+
<figcaption> <figcaption>
1939+
</figcaption>
1940+
</figure>
1941+
<div class="admonition info">
1942+
<p class="admonition-title">Info</p>
1943+
<p>CWEs assigned to CVEs may change their Mapping Label over time. </p>
1944+
<p>Alternative CWEs may be suggested for the <abbr title="CWE Common Weakness Enumeration">CWE</abbr> per example above.</p>
1945+
</div>
19081946
<div class="admonition success">
19091947
<p class="admonition-title">Takeaways</p>
19101948
<ul>

cwe/cwe_views/index.html

Lines changed: 3 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -1068,7 +1068,7 @@
10681068

10691069

10701070
<span class="md-ellipsis">
1071-
CWE Abstraction
1071+
CWE Relationships
10721072
</span>
10731073

10741074

@@ -1230,15 +1230,6 @@
12301230
</ul>
12311231
</nav>
12321232

1233-
</li>
1234-
1235-
<li class="md-nav__item">
1236-
<a href="#example-using-cwe-798-use-of-hard-coded-credential" class="md-nav__link">
1237-
<span class="md-ellipsis">
1238-
Example using CWE-798 Use of Hard-coded Credential
1239-
</span>
1240-
</a>
1241-
12421233
</li>
12431234

12441235
</ul>
@@ -1901,15 +1892,6 @@
19011892
</ul>
19021893
</nav>
19031894

1904-
</li>
1905-
1906-
<li class="md-nav__item">
1907-
<a href="#example-using-cwe-798-use-of-hard-coded-credential" class="md-nav__link">
1908-
<span class="md-ellipsis">
1909-
Example using CWE-798 Use of Hard-coded Credential
1910-
</span>
1911-
</a>
1912-
19131895
</li>
19141896

19151897
</ul>
@@ -1975,13 +1957,6 @@ <h3 id="research-view-view-1000_1">Research View (<a href="https://cwe.mitre.org
19751957
</div>
19761958
<h3 id="nvd-view-view-1003_1"><abbr title="National Vulnerability Database">NVD</abbr> View (<a href="https://cwe.mitre.org/data/definitions/1003.html">View-1003</a>)<a class="headerlink" href="#nvd-view-view-1003_1" title="Permanent link">&para;</a></h3>
19771959
<p><a href="https://cwe.mitre.org/data/definitions/121.html"><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-121 Stack-based Buffer Overflow </a> is not part of <abbr title="National Vulnerability Database">NVD</abbr> View (<a href="https://cwe.mitre.org/data/definitions/1003.html">View-1003</a>).</p>
1978-
<h2 id="example-using-cwe-798-use-of-hard-coded-credential">Example using <a href="https://cwe.mitre.org/data/definitions/798.html"><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-798 Use of Hard-coded Credential </a><a class="headerlink" href="#example-using-cwe-798-use-of-hard-coded-credential" title="Permanent link">&para;</a></h2>
1979-
<p><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-798 is a child of three different nodes:</p>
1980-
<ol>
1981-
<li><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-1391 (Use of Weak Credentials) under Pillar <abbr title="CWE Common Weakness Enumeration">CWE</abbr>-284: Improper Access Control</li>
1982-
<li><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-671 (Lack of Administrator Control over Security) under Pillar <abbr title="CWE Common Weakness Enumeration">CWE</abbr>-710: Improper Adherence to Coding Standards</li>
1983-
<li><abbr title="CWE Common Weakness Enumeration">CWE</abbr>-344 (Use of Invariant Value in Changing Context) under Pillar <abbr title="CWE Common Weakness Enumeration">CWE</abbr>-693: Protection Mechanism Failure</li>
1984-
</ol>
19851960

19861961

19871962

@@ -2013,7 +1988,7 @@ <h2 id="example-using-cwe-798-use-of-hard-coded-credential">Example using <a hre
20131988
<nav class="md-footer__inner md-grid" aria-label="Footer" >
20141989

20151990

2016-
<a href="../cwe_abstraction/" class="md-footer__link md-footer__link--prev" aria-label="Previous: CWE Abstraction">
1991+
<a href="../cwe_abstraction/" class="md-footer__link md-footer__link--prev" aria-label="Previous: CWE Relationships">
20171992
<div class="md-footer__button md-icon">
20181993

20191994
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11h12Z"/></svg>
@@ -2023,7 +1998,7 @@ <h2 id="example-using-cwe-798-use-of-hard-coded-credential">Example using <a hre
20231998
Previous
20241999
</span>
20252000
<div class="md-ellipsis">
2026-
CWE Abstraction
2001+
CWE Relationships
20272002
</div>
20282003
</div>
20292004
</a>

cwe/sunburst/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1068,7 +1068,7 @@
10681068

10691069

10701070
<span class="md-ellipsis">
1071-
CWE Abstraction
1071+
CWE Relationships
10721072
</span>
10731073

10741074

0 commit comments

Comments
 (0)