一个基于 OWASP / CAPSEC 通用弱点枚举数据库的命令行 CWE 发现工具。
官方 OWASP CWE Toolkit 页面
如果您有 Node.js 环境,可以使用 npx 工具调用 cwe-tool,如下所示:
npx cwe-tool [...命令行选项...]
docker pull lirantal/cwe-tool
docker run --rm lirantal/cwe-tool --search test
git clone https://github.com/OWASP/cwe-tool
docker build -t docker.pkg.github.com/owasp/cwe-tool/cwe-tool .
上述 -t 参数后的 image name 可以替换为您选择的镜像名称!
使用 Docker 运行示例
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --id 22
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --search test
从 GitHub 包注册表拉取镜像并执行搜索
docker pull docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest --search test
CWE 工具输出为 JSON 格式,以便后续处理数据或进行深入分析。
命令行选项说明:
| 命令行参数 | 描述 | 实现状态 |
|---|---|---|
--id | 通过 ID 获取 CWE 数据。 | ✅ |
--parent-id | 当同时提供 --id 和 --parent-id 时,仅返回满足父 ID 条件的 CWE ID。 | ✅ 欢迎 PR |
--indirect | 与 --parent-id 一起指定时,检索至根节点的所有间接父级。 | ✅ |
--search | 字符串搜索,返回所有匹配的 CWE 标题。 | ✅ |
--show-membership | 返回所有 CWE ID 及其对应的 CWE 类别成员关系。 | ❌ 欢迎 PR |
npx cwe-tool --id 22
以下命令基于 CWE ID 是否在树中满足与给定父 ID 的任何直接或间接关系进行过滤。
npx cwe-tool --id 22 --parent-id 167 --indirect
输出为以下 JSON: