A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
...
"weaknesses": [
{
"cwe_id": 352,
"name": "Cross-Site Request Forgery (CSRF)",
"description": "The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request."
},
{
"cwe_id": 1035,
"name": "OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities",
"description": "Weaknesses in this category are related to the A9 category in the OWASP Top Ten 2017."
},
{
"cwe_id": 937,
"name": "OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities",
"description": "Weaknesses in this category are related to the A9 category in the OWASP Top Ten 2013."
}
],
...
https://public.vulnerablecode.io/api/vulnerabilities/7567
This is essential data to collect but it is missing from the
affected_by_vulnerabilities
data structure. For example https://public.vulnerablecode.io/api/packages/156170Make sure to add the proper QuerySet optimization (prefetch_related).