Java
Pages85
SpEL, Janino, and Java JSR-223 code injection
Untrusted SpEL, Janino, and Java JSR-223 executable input
OS command and argument injection
External input can change the executable, command, options or arguments of a Java process.
Overly permissive CORS settings
Restrict CORS settings that allow untrusted origins to read browser responses.
Overly permissive Spring CORS settings
Overly permissive Spring CORS settings
Cross-site request forgery (CSRF)
Block unwanted requests that misuse credentials automatically sent by the browser.
Cross-site scripting (XSS)
Encode untrusted values for their output context to prevent script execution in the browser.
XSS from disabled Jakarta Faces output escaping
Jakarta Faces output escaping is disabled.
Open redirect
Unvalidated user-selected redirect URLs may enable phishing or abuse of authentication flows.
Review Java security permissions
Restrict unnecessary class-loader and reflection permissions in legacy Java security policies.
Plaintext storage in Android SharedPreferences
Sensitive data stored in plaintext in Android SharedPreferences
Android Fragment injection
Android Fragment creation based on external input
Android Intent redirection
Redirection through a user-supplied Intent
Android Intent URI permission manipulation
Returning a user-supplied Intent as a result
Android WebView ignores certificate errors
Ignoring Android WebView certificate errors
Android WebView JavaScript interface exposure
Android WebView JavaScript interface exposure
Android WebView debugging enabled
Android WebView debugging enabled
Android WebView file and content access allowed
Android WebView file or content access allowed
Android WebView JavaScript enabled
Android WebView JavaScript enabled
Permission checks based on external input
Permission checks based on external input
Deserialization of untrusted data
Deserialization of untrusted data
Expression Language (EL) injection
Expression Language (EL) injection
Sensitive information exposed to unauthorized users
Sensitive information exposed to unauthorized users
Sensitive data in cleartext logs
Sensitive data in cleartext logs
External control of database configuration
External control of database configuration
File disclosure through Spring ModelAndView
File disclosure through Spring ModelAndView
Disabled Spring Security protections
Disabled Spring Security protections
Disabled session expiration
Disabled session expiration
Detailed Spring error attributes exposed
Detailed Spring error attributes exposed
File disclosure through RequestDispatcher
File disclosure through RequestDispatcher
Overly permissive file permissions
Overly permissive file permissions
Unvalidated upload filenames
Unvalidated upload filenames
Hard-coded credentials
Use of Hard-coded Credentials
Hard-coded passwords
Use of Hard-Coded Password
HTTP Parameter Pollution (HPP) and SSRF
HTTP parameter pollution
Improper authentication
Improper Authentication
Improper privilege management
Improper Privilege Management
Incorrect authorization
Incorrect Authorization
Groovy Code Injection
Groovy code injection
Insecure LDAP Authentication (Cleartext Transmission)
LDAP simple bind over cleartext
TLS Trust Verification Disabled
TLS settings with trust verification disabled
Insecure Randomness
Insecure randomness
Insufficient cryptographic key size
Choose cryptographic key sizes that meet the required security strength
AES cipher transformation without an explicit mode and padding
Specify the mode and padding when configuring AES encryption
JEXL injection
Injection into JEXL expressions, scripts and templates
JNDI injection
Resource injection through an untrusted JNDI lookup name
Missing JWT signature verification
Require a valid JWT signature before trusting authentication claims
HTTP request or response splitting with Netty header validation disabled
Keep Netty HTTP header validation enabled to prevent CRLF injection
Log injection
Prevent untrusted text from forging log-record boundaries
Predictable seed for a secure random generator
Avoid initializing a security-sensitive random generator using predictable values alone
Denial of service from inefficient regular expressions
Reduce excessive regex backtracking and limit input length