Java

Pages85

SpEL, Janino, and Java JSR-223 code injection

Untrusted SpEL, Janino, and Java JSR-223 executable input

OS command and argument injection

External input can change the executable, command, options or arguments of a Java process.

Overly permissive CORS settings

Restrict CORS settings that allow untrusted origins to read browser responses.

Overly permissive Spring CORS settings

Overly permissive Spring CORS settings

Cross-site request forgery (CSRF)

Block unwanted requests that misuse credentials automatically sent by the browser.

Cross-site scripting (XSS)

Encode untrusted values for their output context to prevent script execution in the browser.

XSS from disabled Jakarta Faces output escaping

Jakarta Faces output escaping is disabled.

Open redirect

Unvalidated user-selected redirect URLs may enable phishing or abuse of authentication flows.

Review Java security permissions

Restrict unnecessary class-loader and reflection permissions in legacy Java security policies.

Plaintext storage in Android SharedPreferences

Sensitive data stored in plaintext in Android SharedPreferences

Android Fragment injection

Android Fragment creation based on external input

Android Intent redirection

Redirection through a user-supplied Intent

Android Intent URI permission manipulation

Returning a user-supplied Intent as a result

Android WebView ignores certificate errors

Ignoring Android WebView certificate errors

Android WebView JavaScript interface exposure

Android WebView JavaScript interface exposure

Android WebView debugging enabled

Android WebView debugging enabled

Android WebView file and content access allowed

Android WebView file or content access allowed

Android WebView JavaScript enabled

Android WebView JavaScript enabled

Permission checks based on external input

Permission checks based on external input

Deserialization of untrusted data

Deserialization of untrusted data

Expression Language (EL) injection

Expression Language (EL) injection

Sensitive information exposed to unauthorized users

Sensitive information exposed to unauthorized users

Sensitive data in cleartext logs

Sensitive data in cleartext logs

External control of database configuration

External control of database configuration

File disclosure through Spring ModelAndView

File disclosure through Spring ModelAndView

Disabled Spring Security protections

Disabled Spring Security protections

Disabled session expiration

Disabled session expiration

Detailed Spring error attributes exposed

Detailed Spring error attributes exposed

File disclosure through RequestDispatcher

File disclosure through RequestDispatcher

Overly permissive file permissions

Overly permissive file permissions

Unvalidated upload filenames

Unvalidated upload filenames

Hard-coded credentials

Use of Hard-coded Credentials

Hard-coded passwords

Use of Hard-Coded Password

HTTP Parameter Pollution (HPP) and SSRF

HTTP parameter pollution

Improper authentication

Improper Authentication

Improper privilege management

Improper Privilege Management

Incorrect authorization

Incorrect Authorization

Groovy Code Injection

Groovy code injection

Insecure LDAP Authentication (Cleartext Transmission)

LDAP simple bind over cleartext

TLS Trust Verification Disabled

TLS settings with trust verification disabled

Insecure Randomness

Insecure randomness

Insufficient cryptographic key size

Choose cryptographic key sizes that meet the required security strength

AES cipher transformation without an explicit mode and padding

Specify the mode and padding when configuring AES encryption

JEXL injection

Injection into JEXL expressions, scripts and templates

JNDI injection

Resource injection through an untrusted JNDI lookup name

Missing JWT signature verification

Require a valid JWT signature before trusting authentication claims

HTTP request or response splitting with Netty header validation disabled

Keep Netty HTTP header validation enabled to prevent CRLF injection

Log injection

Prevent untrusted text from forging log-record boundaries

Predictable seed for a secure random generator

Avoid initializing a security-sensitive random generator using predictable values alone

Denial of service from inefficient regular expressions

Reduce excessive regex backtracking and limit input length