Python

Pages69

Binding to all network interfaces

Check that binding to every interface matches the service’s intended access scope.

Use of weak cryptography

Review weak cryptography and use encryption with key management and integrity verification.

Broken user authentication

Protect accounts through password verification, login-attempt limits, and session management.

Clear-text logging of sensitive data

Remove or redact sensitive values such as passwords and tokens from logs.

Clear-text storage of sensitive data

Clear-text storage of sensitive data

Python code injection

Python code injection through eval and exec

Command injection

Command injection

Cross-site request forgery

Cross-site request forgery (CSRF)

Debug and testing modes enabled

Debug or testing mode enabled in a production Python web application

Missing limits on Django login attempts

Missing limits on Django login attempts

Security decisions based on DNS lookup results

Security decisions based on DNS lookup results

Empty exception handler

Empty exception handler

Exception message exposure

Exception message exposure

Overly permissive FastAPI CORS settings

Overly permissive FastAPI CORS settings

Format string injection

External input used as a format string

Overly broad exception handling

Overly broad exception handling

Deserialization of untrusted data

Deserialization of untrusted data

Hardcoded credentials

Credentials embedded in source code

Hardcoded encryption IV

Hardcoded initialization vector in encryption

Hardcoded cryptographic keys

Cryptographic keys embedded in source code

Hardcoded secrets

Secrets embedded in application code

HTTP response splitting

HTTP response splitting

Sensitive cookies without HttpOnly

Sensitive cookies without the HttpOnly flag

Sensitive cookies without Secure

Sensitive cookies without the Secure attribute

Improper certificate validation

Improper certificate validation

Improper handling of permissions

Improper handling of insufficient permissions or privileges

Incomplete URL validation

Incomplete URL validation

Excessive file permissions

Insecure file permissions

Insecure temporary file creation

Insecure temporary file creation

Insufficient cryptographic key size

Insufficient cryptographic key size

Jinja autoescaping is disabled

Jinja autoescaping is disabled

Jinja server-side template injection (SSTI)

Jinja server-side template injection

JWT signature verification is disabled

JWT signature verification is disabled

LDAP injection

LDAP injection

Unsafe lxml XMLParser options

Disable external entities and unnecessary parser features when handling untrusted XML.

Dereferencing a value before checking for None

Dereferencing a value before checking for None

NoSQL injection

Prevent user input from changing the structure or operators of a NoSQL query.

NumPy fixed-width integer overflow

NumPy fixed-width integer overflow

Open redirect

Validate redirect hosts and schemes to prevent unintended redirects to external sites.

Origin validation errors

Apply appropriate origin validation and CSRF protection to requests whose credentials are sent automatically by the browser.

PAM authorization bypass

Check account status and access policies after successful PAM authentication.

Path traversal

Prevent user-controlled paths from reaching files outside the intended base directory.

Assigning an external array reference directly to a private field

Assigning an external array reference directly to a private field

Returning a private array directly

Returning a private array directly

Regular expression denial of service

Regular expression denial of service (ReDoS)

Secure encryption modes and padding

Use encryption modes and padding appropriate to each algorithm.

Sensitive information in comments

Sensitive information is included in comments.

Server information exposure

Unnecessary internal server information is exposed to clients.

Request data stored in class variables

User-specific request data is stored in class variables.

SQL injection

SQL injection