Bugcrowd Vulnerability Rating Taxonomy 1.0
Bugcrowd Vulnerability Rating Taxonomy 1.0
Server-Side Injection
Using Default Credentials
File Inclusion
Production Server
Local
Authentication Bypass
Subdomain Takeover
Horizontal
Missing Function Level Access Control Server-Side Request Forgery (SSRF) Internal
Broken Authentication and Session Management Weak Login Function Over HTTP
v1.0.0 - February 24, 2017 Broken Authentication and Session Management Session Fixation ©Bugcrowd 2017
Priority OWASP Top Ten + Bugcrowd Extras Specific Vulnerability Name Variant or Affected Function
P3
Sensitive Data Exposure EXIF Geolocation Data Not Stripped From Uploaded Images Automatic User Enumeration
Insufficient Security Configurability Weak Password Policy Complexity, Both Length and Char Type Not Enforced
Clickjacking
Session Token
Sensitive Action
Server Security Misconfiguration Lack of Security Headers Cache-Control for a Sensitive Page
Broken Authentication and Session Management Failure to Invalidate Session On Password Reset
Broken Authentication and Session Management Failure to Invalidate Session On Password Change
Broken Authentication and Session Management Session Token in URL Over HTTP
Broken Authentication and Session Management Weak Registration Implementation Over HTTP
Sensitive Data Exposure EXIF Geolocation Data Not Stripped From Uploaded Images Manual User Enumeration
P4
CONTINUED
Cross-Site Scripting (XSS)
Cookie-Based
Admin to Anyone
Missing Function Level Access Control Server-Side Request Forgery (SSRF) External
Insufficient Security Configurability Weak Password Policy Complexity, Length Not Enforced
Insufficient Security Configurability Weak Password Policy Complexity, Char Type Not Enforced
Insufficient Security Configurability Weak Password Reset Implementation Token is Not Invalidated After Use
Insecure Data Storage Sensitive Application Data Stored Unencrypted On External Storage
Server Security Misconfiguration Mail Server Misconfiguration Missing SPF on Non-Email Domain
Server Security Misconfiguration Mail Server Misconfiguration SPF Uses a Soft Fail
Server Security Misconfiguration Unsafe File Upload File Extension Filter Bypass
Server Security Misconfiguration Missing Secure or HTTPOnly Cookie Flag Non-Session Cookie
OPTIONS
Server Security Misconfiguration Lack of Security Headers Cache-Control for a Non-Sensitive Page
Broken Authentication and Session Management Failure to Invalidate Session All Sessions
Broken Authentication and Session Management Failure to Invalidate Session On Email Change
Broken Authentication and Session Management Failure to Invalidate Session Long Timeout
Broken Authentication and Session Management Session Token in URL Over HTTPS
P5
CONTINUED
Cross-Site Scripting (XSS)
IE-Only
Self
Insufficient Security Configurability Weak Password Policy Allows Reuse of Old Passwords
Insufficient Security Configurability Weak Password Policy Allows Password to be Same as Email/Username
Insufficient Security Configurability Weak Password Reset Implementation Token is Not Invalidated After Email Change
Insufficient Security Configurability Weak Password Reset Implementation Token is Not Invalidated After Password Change
Insufficient Security Configurability Weak Password Reset Implementation Token Has Long Timed Expiry
Insufficient Security Configurability Weak Password Reset Implementation Token is Not Invalidated After New Token is Requested
Insufficient Security Configurability Weak Registration Implementation Allows Disposable Email Addresses
v1.0.0 - February 24, 2017 ©Bugcrowd 2017
Insufficient Security Configurability Weak 2FA Implementation Missing Failsafe
Priority OWASP Top Ten + Bugcrowd Extras Specific Vulnerability Name Variant or Affected Function
Using Components with Known Vulnerabilities Outdated Software Version
P5
CONTINUED
Using Components with Known Vulnerabilities
On Internal Storage
Insecure Data Storage Sensitive Application Data Stored Unencrypted On Internal Storage
Follow us at @BugcrowdOps and continue the discussion on our forum. 1.0.0 - February 24, 2017 (Current Version)
Major changes to taxonomy structure with the addition of top-level categorizations
to provide flexibility for context-dependent severity ratings. With this update we also
launched our web-based taxonomy at bugcrowd.com/vrt. See full documentation of
changes here.