Skip to content
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
Use CWE in findings list report instead of problem type mapping
  • Loading branch information
jankuehl committed Dec 3, 2019
commit d2a3ae18dbf8217bd1bcecc8d1454b86c71213be
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,7 @@ public TestResults parse(final File f) throws Exception {
private final StringBuilder m_CollectedCharacters = new StringBuilder();

private String m_ProblemTypeId;
private int m_CWE = -1;
private String m_Class;
private String m_Classification;

Expand All @@ -59,8 +60,7 @@ public void startElement(final String uri, final String localName, final String
switch (qName) {
case "XanitizerFindingsList":

String version = attributes.getValue("xanitizerVersion");
version = version.replace('/', '-');
String version = attributes.getValue("xanitizerVersionShort");
tr.setToolVersion(version);

break;
Expand All @@ -85,11 +85,20 @@ public void endElement(final String uri, final String localName, final String qN
m_Classification = m_CollectedCharacters.toString();
break;

case "cweNumber":
// remove leading "CWE-" and thousands delimiter
try {
m_CWE = Integer.parseInt(m_CollectedCharacters.toString().substring(4).replace(".", "").replace(",", ""));
} catch (NumberFormatException e) {
m_CWE = -1;
}
break;

case "finding":
// Finishing a finding.

// Defensiveness: This condition should always be true.
if (m_ProblemTypeId != null && m_Class != null && m_Classification != null) {
if (m_ProblemTypeId != null && m_Class != null && m_Classification != null && m_CWE > -1) {

// Skip informational findings.
if (!m_Classification.equals("Information")) {
Expand All @@ -113,7 +122,7 @@ public void endElement(final String uri, final String localName, final String qN

tcr.setNumber(testCaseNumber);
tcr.setCategory(m_ProblemTypeId);
tcr.setCWE(figureCWE(m_ProblemTypeId));
tcr.setCWE(m_CWE);

tr.put(tcr);
}
Expand All @@ -122,6 +131,7 @@ public void endElement(final String uri, final String localName, final String qN
}

m_ProblemTypeId = null;
m_CWE = -1;
m_Class = null;
m_Classification = null;
break;
Expand All @@ -146,47 +156,5 @@ public void characters(final char ch[], final int start, final int length)
return tr;
}

private static int figureCWE(final String problemTypeId) {
switch (problemTypeId) {
case "ci:CommandInjection":
return 78;

case "SpecialMethodCall:WeakEncryption":
return 327;

case "SpecialMethodCall:WeakHash":
return 328;

case "ci:LDAPInjection":
return 90;

case "pt:PathTraversal":
return 22;

case "cook:UnsecuredCookie":
return 614;

case "ci:SQLInjection":
return 89;

case "tbv:TrustBoundaryViolationSession":
return 501;

case "SpecialMethodCall:java.util.Random":
return 330;

case "ci:XPathInjection":
return 643;

case "xss:XSSFromRequest":
case "xss:XSSFromDb":
return 79;

default:
// Dummy.
return 0;
}
}

}