一个基于 OWASP / CAPSEC 通用弱点枚举数据库的命令行 CWE 发现工具。
官方 OWASP CWE Toolkit 页面
如果您有 Node.js 环境,可以使用 npx 工具调用 cwe-tool,如下所示:
npx cwe-tool [...命令行选项...]
docker pull lirantal/cwe-tool
docker run --rm lirantal/cwe-tool --search test
git clone https://github.com/OWASP/cwe-tool
docker build -t docker.pkg.github.com/owasp/cwe-tool/cwe-tool .
上述 -t 参数后的 image name 可以替换为您选择的镜像名称!
使用 Docker 运行示例
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --id 22
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --search test
从 GitHub 包注册表拉取镜像并执行搜索
docker pull docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest --search test
CWE 工具输出为 JSON 格式,以便后续处理数据或进行深入分析。
命令行选项说明:
npx cwe-tool --id 22
以下命令基于 CWE ID 是否在树中满足与给定父 ID 的任何直接或间接关系进行过滤。
npx cwe-tool --id 22 --parent-id 167 --indirect
输出为以下 JSON:
{
"attr": {
"@_ID": "242",
"@_Name": "Use of Inherently Dangerous Function",
"@_Abstraction": "Base",
"@_Structure": "Simple",
"@_Status": "Draft"
},
"Description": "The program calls a function that can never be guaranteed to work safely.",
"Extended_Description": "Certain functions behave in dangerous ways regardless of how they are used. Functions in this category were often implemented without taking security concerns into account. The gets() function is unsafe because it does not perform bounds checking on the size of its input. An attacker can easily send arbitrarily-sized input to gets() and overflow the destination buffer. Similarly, the >> operator is unsafe to use when reading into a statically-allocated character array because it does not perform bounds checking on the size of its input. An attacker can easily send arbitrarily-sized input to the >> operator and overflow the destination buffer.",
"Related_Weaknesses": {
"Related_Weakness": {
"attr": {
"@_Nature": "ChildOf",
"@_CWE_ID": "1177",
"@_View_ID": "1000",
"@_Ordinal": "Primary"
}
}
},
"Weakness_Ordinalities": { "Weakness_Ordinality": { "Ordinality": "Primary" } },
"Applicable_Platforms": {
"Language": [
{ "attr": { "@_Name": "C", "@_Prevalence": "Undetermined" } },
{ "attr": { "@_Name": "C++", "@_Prevalence": "Undetermined" } }
]
},
"Modes_Of_Introduction": { "Introduction": { "Phase": "Implementation" } },
"Likelihood_Of_Exploit": "High",
"Common_Consequences": { "Consequence": { "Scope": "Other", "Impact": "Varies by Context" } },
"Potential_Mitigations": {
"Mitigation": [
{
"Phase": ["Implementation", "Requirements"],
"Description": "Ban the use of dangerous functions. Use their safe equivalent."
},
{
"Phase": "Testing",
"Description": "Use grep or static analysis tools to spot usage of dangerous functions."
}
]
},
"Demonstrative_Examples": {
"Demonstrative_Example": [
{
"Intro_Text": "The code below calls gets() to read information into a buffer.",
"Example_Code": {
"attr": { "@_Nature": "bad", "@_Language": "C" },
"xhtml:div": { "#text": "char buf[BUFSIZE];gets(buf);", "xhtml:br": "" }
},
"Body_Text": "The gets() function in C is inherently unsafe."
},
{
"attr": { "@_Demonstrative_Example_ID": "DX-5" },
"Intro_Text": "The code below calls the gets() function to read in data from the command line.",
"Example_Code": {
"attr": { "@_Nature": "bad", "@_Language": "C" },
"xhtml:div": {
"#text": "}",
"xhtml:div": {
"#text": "char buf[24];printf(\"Please enter your name and press <Enter>\\n\");gets(buf);...",
"attr": { "@_style": "margin-left:10px;" },
"xhtml:br": ["", "", ""]
}
}
},
"Body_Text": "However, the programmer uses the function gets() which is inherently unsafe because it blindly copies all input from STDIN to the buffer without checking size. This allows the user to provide a string that is larger than the buffer size, resulting in an overflow condition."
}
]
},
"Taxonomy_Mappings": {
"Taxonomy_Mapping": [
{
"attr": { "@_Taxonomy_Name": "7 Pernicious Kingdoms" },
"Entry_Name": "Dangerous Functions"
},
{
"attr": { "@_Taxonomy_Name": "CERT C Secure Coding" },
"Entry_ID": "POS33-C",
"Entry_Name": "Do not use vfork()",
"Mapping_Fit": "CWE More Abstract"
},
{
"attr": { "@_Taxonomy_Name": "Software Fault Patterns" },
"Entry_ID": "SFP3",
"Entry_Name": "Use of an improper API"
}
]
},
"References": {
"Reference": [
{ "attr": { "@_External_Reference_ID": "REF-6" } },
{
"attr": { "@_External_Reference_ID": "REF-194", "@_Section": "Chapter 5. Working with I/O" }
},
{
"attr": {
"@_External_Reference_ID": "REF-7",
"@_Section": "Chapter 5, "gets and fgets" Page 163"
}
}
]
},
"Content_History": {
"Submission": { "Submission_Name": "7 Pernicious Kingdoms", "Submission_Date": "2006-07-19" },
"Modification": [
{
"Modification_Name": "Sean Eidemiller",
"Modification_Organization": "Cigital",
"Modification_Date": "2008-07-01",
"Modification_Comment": "added/updated demonstrative examples"
},
{
"Modification_Name": "Eric Dalci",
"Modification_Organization": "Cigital",
"Modification_Date": "2008-07-01",
"Modification_Comment": "updated Potential_Mitigations"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2008-09-08",
"Modification_Comment": "updated Applicable_Platforms, Relationships, Other_Notes, Taxonomy_Mappings, Type, Weakness_Ordinalities"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2008-11-24",
"Modification_Comment": "updated Relationships, Taxonomy_Mappings"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2009-10-29",
"Modification_Comment": "updated Description, Other_Notes, References"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2010-02-16",
"Modification_Comment": "updated Demonstrative_Examples, References, Relationships"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2010-04-05",
"Modification_Comment": "updated Relationships"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2011-06-01",
"Modification_Comment": "updated Common_Consequences"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2011-06-27",
"Modification_Comment": "updated Common_Consequences"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2012-05-11",
"Modification_Comment": "updated Relationships"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2012-10-30",
"Modification_Comment": "updated Potential_Mitigations"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2014-07-30",
"Modification_Comment": "updated Demonstrative_Examples, Relationships, Taxonomy_Mappings"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2017-11-08",
"Modification_Comment": "updated Causal_Nature, References, Relationships, Taxonomy_Mappings"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2018-03-27",
"Modification_Comment": "updated References"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2019-01-03",
"Modification_Comment": "updated Relationships"
},
{
"Modification_Name": "CWE Content Team",
"Modification_Organization": "MITRE",
"Modification_Date": "2020-02-24",
"Modification_Comment": "updated References, Relationships"
}
],
"Previous_Entry_Name": [
{ "#text": "Dangerous Functions", "attr": { "@_Date": "2008-01-30" } },
{ "#text": "Use of Inherently Dangerous Functions", "attr": { "@_Date": "2008-04-11" } }
]
}
}
请参考 CONTRIBUTING 以获取关于为本项目贡献的指南。
cwe-tool © Liran Tal,以 Apache-2.0 许可证发布。
| 命令行参数 | 描述 | 实现状态 |
|---|
--id | 通过 ID 获取 CWE 数据。 | ✅ |
--parent-id | 当同时提供 --id 和 --parent-id 时,仅返回满足父 ID 条件的 CWE ID。 | ✅ 欢迎 PR |
--indirect | 与 --parent-id 一起指定时,检索至根节点的所有间接父级。 | ✅ |
--search | 字符串搜索,返回所有匹配的 CWE 标题。 | ✅ |
--show-membership | 返回所有 CWE ID 及其对应的 CWE 类别成员关系。 | ❌ 欢迎 PR |