Commit 9eaa78d
data/reports: set better CWE for GO-2025-3420
This report was assigned CWE-116 ("Improper Encoding or Escaping of Output"),
but CWE-201 ("Insertion of Sensitive Information Into Sent Data") better
describes the incorrect behavior of sending a cookie or Authorization header
when the header should have been stripped.
Change-Id: I8d3266c7348d3ed9d60d903b7a7afb39bdee212b
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/704036
Auto-Submit: Damien Neil <dneil@google.com>
Reviewed-by: Neal Patel <nealpatel@google.com>
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>1 parent 5032ebc commit 9eaa78d
2 files changed
+2
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
88 | 88 | | |
89 | 89 | | |
90 | 90 | | |
91 | | - | |
| 91 | + | |
92 | 92 | | |
93 | 93 | | |
94 | 94 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
46 | | - | |
| 46 | + | |
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
| |||
0 commit comments