Templates by weakness class
The catalog sorted by the class of defect a check is
looking for, taken from each template’s own @cwe header. A template may
name several, and appears under each.
Checks that name no weakness class
Section titled “Checks that name no weakness class”These declare no @cwe. The field is optional, and nothing refuses to run
a template without one, so this is a description of the corpus rather than
a list of faults.
| Check | Category |
|---|---|
etcd-auth-check |
devops |
etcd-instead-http-request |
devops |
etcd-think-path-wrong |
devops |
etcd-unauth |
devops |
etcd-unauthenticated-access |
devops |
http-header-injection |
web |
http-service-responding |
network |
password-reset-takeover |
web |
postgresql-extension-rce |
databases |
prometheus-node-exporter-exposed |
monitoring |
prototype-pollution |
web |
runner-token-detection |
devops |
saml-sso-bypass-gitlab |
devops |
server-side-js-injection |
web |
websocket-message-fuzzer |
network |

