CVE MAPPING

Methodology

How CVE Mapping reproduces vulnerabilities, records evidence, and validates detections.

  1. Start the disposable vulnerable or patched version in isolation.
  2. Record the exact version and create only synthetic lab objects.
  3. Capture nginx and Rails JSON telemetry before and during the benign test.
  4. Verify the application state change independently where the supplied lab procedure calls for it.
  5. Repeat against the patched version with a unique proof title.
  6. Correlate request method, path, authentication context, GraphQL metadata, database-write counters, rate-limiting gates, and resulting state.

The conclusions in this repository are limited to the supplied artifacts. In particular, a successful HTTP status is not sufficient evidence of a write. The observations here rely on the recorded db_write_count, application state, and preserved timestamps. Product-specific telemetry field names in detection rules are marked experimental where appropriate.