Medium

TitleLanguage
Zone signing should not use RSA SHA1terraform
When using Queue Services for a storage account, logging should be enabled.terraform
Weak Password Requirementspython
Weak Password Requirementspython
Weak Authenticationhcl
Users should not be granted service account access at the project levelterraform
Users should not be granted service account access at the organization levelterraform
Users should not be granted service account access at the folder levelterraform
User with admin accessterraform
User Pods should not be placed in kube-system namespaceterraform
User Interface (UI) Misrepresentation of Critical Informationjavascript
Use of Web Link to Untrusted Target with window.opener Accessgeneric
Use of Weak Hash (4.12)ocaml
Use of Weak Hashrust
Use of Weak Hashruby
Use of Weak Hashruby
Use of Weak Hashkotlin
Use of Weak Hashgo
Use of Weak Hashgo
Use of Unmaintained Third Party Componentsjavascript
Use of Potentially Dangerous Functionc
Use of Potentially Dangerous Functionc
Use of Potentially Dangerous Functionc
Use of Potentially Dangerous Functionc
Use of Potentially Dangerous Functionc
Use of Password Hash With Insufficient Computational Effortjavascript
Use of Insufficiently Random Valuespython
Use of Inherently Dangerous Function (4.12)ocaml
Use of Inherently Dangerous Functionrust
Use of Incorrectly-Resolved Name or Referencejavascript
Use of Incorrectly-Resolved Name or Referencejavascript
Use of Hard-coded Cryptographic Keyapex
Use of Hard-coded Credentialsjava
Use of Hard-coded Credentialskotlin
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsgeneric
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsgeneric
Use of Hard-coded Credentialsgeneric
Use of Hard-coded Credentialshcl
Use of Hard-coded Credentialsyaml
Use of GET Request Method With Sensitive Query Stringsyaml
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')php
Use of Externally-Controlled Format Stringc
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)go
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmjavascript
Use of a Broken or Risky Cryptographic Algorithmkotlin
Use of a Broken or Risky Cryptographic Algorithmkotlin
Use of a Broken or Risky Cryptographic Algorithmkotlin
Use of a Broken or Risky Cryptographic Algorithmgo
Use of a Broken or Risky Cryptographic Algorithmgo
Use of a Broken or Risky Cryptographic Algorithmgo
Use of a Broken or Risky Cryptographic Algorithmgo
Use of a Broken or Risky Cryptographic Algorithmgo
Use of a Broken or Risky Cryptographic Algorithmgo
Use of a Broken or Risky Cryptographic Algorithmgo
Use After Freec
Use After Freec
URL Redirection to Untrusted Site ('Open Redirect')ruby
URL Redirection to Untrusted Site ('Open Redirect')ruby
URL Redirection to Untrusted Site ('Open Redirect')python
URL Redirection to Untrusted Site ('Open Redirect')php
URL Redirection to Untrusted Site ('Open Redirect')java
URL Redirection to Untrusted Site ('Open Redirect')java
URL Redirection to Untrusted Site ('Open Redirect')csharp
Unsafe sysctl options setterraform
Unintended Proxy or Intermediary ('Confused Deputy')generic
Uncontrolled Resource Consumptionpython
Trust Boundary Violationjava
Time-of-check Time-of-use (TOCTOU) Race Conditionocaml
The Kubernetes cluster does not enable surge upgradesterraform
Temporary file logging should be enabled for all temporary files.terraform
Synapse Workspace should have managed virtual network enabled, the default is disabled.terraform
SSL should be enforced on database connections where applicableterraform
Specific capabilities addedterraform
Spaces buckets should have versioning enabledterraform
Server-Side Request Forgery (SSRF)ruby
Server-Side Request Forgery (SSRF)python
Server-Side Request Forgery (SSRF)php
Server-Side Request Forgery (SSRF)php
Server-Side Request Forgery (SSRF)php
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)java
Server-Side Request Forgery (SSRF)scala
Server-Side Request Forgery (SSRF)scala
Server-Side Request Forgery (SSRF)scala
Server-Side Request Forgery (SSRF)scala
Server-Side Request Forgery (SSRF)hcl
Send notification emails for high severity alertsterraform
SELinux custom options setterraform
Selector usage in network policiesterraform
Seccomp policies disabledterraform
SAM HTTP API stages for V1 and V2 should have access logging enabledterraform
SAM API stages for V1 and V2 should have access logging enabledterraform
SAM API must have data cache enabledterraform
S3 DNS Compliant Bucket Namesterraform
S3 Data should be versionedterraform
Runs as root userterraform
RUN cd ...' to change directoryterraform
Roles should not be assigned to default service accountsterraform
Roles should not be assigned to default service accountsterraform
Roles should not be assigned to default service accountsterraform
Roles limited to the required actionsterraform
Reusing a Nonce, Key Pair in Encryptionjava
Require Vpc Flow Logs For All Vpcsterraform
Reliance on Untrusted Inputs in a Security Decisionrust
Reliance on Untrusted Inputs in a Security Decisionrust
Reliance on Untrusted Inputs in a Security Decisionrust
Reliance on Untrusted Inputs in a Security Decisionrust
Reliance on Insufficiently Trustworthy Componentyaml
Redis cluster should have backup retention turned onterraform
RDS IAM Database Authentication Disabledterraform
RDS Deletion Protection Disabledterraform
RDS Cluster Deletion Protection Disabledterraform
RDS Cluster and RDS instance should have backup retention longer than default 1 dayterraform
RDB instance should have backup retention longer than 1 dayterraform
Protection Mechanism Failurehcl
Protecting Pod service account tokensterraform
Predictable from Observable Statesolidity
Port 22 exposedterraform
Point in time recovery should be enabled to protect DynamoDB tableterraform
Permissive Cross-domain Policy with Untrusted Domainspython
Permissive Cross-domain Policy with Untrusted Domainspython
Permissions, Privileges, and Access Controlsjson
Permissions, Privileges, and Access Controlsjson
Path Traversalocaml
OS Login should be enabled at project levelterraform
OS Command Injectionocaml
Origin Validation Errorjavascript
Origin Validation Errorgeneric
Omission of Security-relevant Informationhcl
Not Using Password Aginghcl
Not Using Password Aginghcl
Non-default /proc masks setterraform
No threat detections are setterraform
No plaintext password for compute instanceterraform
Network Policy should be enabled on GKE clustersterraform
Neptune logs export should be enabledterraform
Multiple HEALTHCHECK definedterraform
MQ Broker should have audit logging enabledterraform
Missing Encryption of Sensitive Dataswift
Missing Encryption of Sensitive Dataruby
Missing Encryption of Sensitive Datatypescript
Missing Encryption of Sensitive Datatypescript
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing description for security group.terraform
Missing Authorizationcsharp
Missing Authentication for Critical Functiontypescript
Manage namespace secretsterraform
Manage Kubernetes workloads and podsterraform
Manage configmapsterraform
Least Privilege Violationswift
Key vault should have purge protection enabledterraform
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Integer Underflow (Wrap or Wraparound)solidity
Integer Overflow or Wraparoundphp
Insufficiently Protected Credentialsjavascript
Insufficiently Protected Credentialsjavascript
Insufficiently Protected Credentialsjavascript
Insufficiently Protected Credentialsjavascript
Insufficiently Protected Credentialsjavascript
Insufficiently Protected Credentialsjavascript
Insufficiently Protected Credentialsjavascript
Insufficiently Protected Credentialsjavascript
Insufficiently Protected Credentialshcl
Insufficient Verification of Data Authenticityjava
Insufficient Verification of Data Authenticityhcl
Insufficient Logginghcl
Instances should not override the project setting for OS Loginterraform
Instances should have Shielded VM VTPM enabledterraform
Instances should have Shielded VM secure boot enabledterraform
Instances should have Shielded VM integrity monitoring enabledterraform
Insertion of Sensitive Information into Log Filepython
Insertion of Sensitive Information into Externally-Accessible File or Directorydockerfile
Inefficient Regular Expression Complexityjavascript
Inefficient Regular Expression Complexityjavascript
Inefficient Regular Expression Complexitycsharp
Inefficient Regular Expression Complexitycsharp
Incorrect Type Conversion or Castpython
Incorrect Type Conversion or Castpython
Incorrect Type Conversion or Castpython
Incorrect Regular Expressionruby
Incorrect Permission Assignment for Critical Resourcehcl
Incorrect Permission Assignment for Critical Resourcehcl
Incorrect Permission Assignment for Critical Resourcehcl
Incorrect Permission Assignment for Critical Resourcehcl
Incorrect Permission Assignment for Critical Resourcehcl
Incorrect Permission Assignment for Critical Resourcehcl
Incorrect Permission Assignment for Critical Resourceyaml
Incorrect Permission Assignment for Critical Resourceyaml
Incorrect Permission Assignment for Critical Resourceyaml
Incorrect Permission Assignment for Critical Resourceyaml
Incorrect Permission Assignment for Critical Resourceyaml
Incorrect Default Permissionsruby
Incorrect Default Permissionspython
Incorrect Calculationsolidity
Incorrect Authorizationapex
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')hcl
Inclusion of Sensitive Information in Source Coderuby
Inadequate Encryption Strengthpython
Inadequate Encryption Strengthpython
Inadequate Encryption Strengthpython
Inadequate Encryption Strengthpython
Inadequate Encryption Strengthpython
Inadequate Encryption Strengthpython
Inadequate Encryption Strengthpython
Inadequate Encryption Strengthjava
Inadequate Encryption Strengthgeneric
Inadequate Encryption Strengthterraform
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Improperly Controlled Modification of Dynamically-Determined Object Attributesruby
Improperly Controlled Modification of Dynamically-Determined Object Attributesjavascript
Improperly Controlled Modification of Dynamically-Determined Object Attributescsharp
Improper Verification of Cryptographic Signaturesolidity
Improper Verification of Cryptographic Signaturecsharp
Improper Validation of Specified Index, Position, or Offset in Inputsolidity
Improper Validation of Certificate with Host Mismatchjava
Improper Restriction of XML External Entity Referenceruby
Improper Restriction of XML External Entity Referencepython
Improper Restriction of XML External Entity Referencejavascript
Improper Restriction of XML External Entity Referencejavascript
Improper Restriction of XML External Entity Referencejavascript
Improper Restriction of XML External Entity Referencejava
Improper Restriction of XML External Entity Referencejava
Improper Restriction of XML External Entity Referencejava
Improper Restriction of XML External Entity Referencescala
Improper Restriction of XML External Entity Referencescala
Improper Restriction of XML External Entity Referencego
Improper Restriction of XML External Entity Referencecsharp
Improper Restriction of XML External Entity Referencecsharp
Improper Restriction of XML External Entity Referencecsharp
Improper Restriction of Operations within the Bounds of a Memory Bufferjavascript
Improper Restriction of Excessive Authentication Attemptscsharp
Improper Privilege Managementdockerfile
Improper Privilege Managementdockerfile
Improper Privilege Managementdockerfile
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')swift
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')ruby
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')php
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')php
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')php
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')javascript
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')javascript
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')javascript
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')scala
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')scala
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')go
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')go
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')go
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')go
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')go
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')csharp
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')php
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')php
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')javascript
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')javascript
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')javascript
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')javascript
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')java
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')java
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')java
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')java
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')kotlin
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')scala
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')scala
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')go
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')csharp
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')yaml
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')clojure
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')java
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')java
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')java
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')csharp
Improper Neutralization of Special Elements Used in a Template Enginejavascript
Improper Neutralization of Special Elements Used in a Template Enginego
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')python
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')python
Improper Neutralization of Special Elements in Data Query Logicpython
Improper Neutralization of Special Elements in Data Query Logicjava
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')php
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')php
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')typescript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')java
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Formula Elements in a CSV Filepython
Improper Neutralization of Formula Elements in a CSV Filepython
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')python
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')bash
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')php
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')javascript
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')javascript
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')javascript
Improper Neutralization of Data within XPath Expressions ('XPath Injection')csharp
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')java
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')generic
Improper Neutralization of CRLF Sequences ('CRLF Injection')python
Improper Neutralization of CRLF Sequences ('CRLF Injection')java
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')python
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')python
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')php
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')php
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')javascript
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')javascript
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')go
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')generic
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')csharp
Improper Input Validationpython
Improper Export of Android Application Componentsgeneric
Improper Enforcement of a Single, Unique Actionsolidity
Improper Enforcement of a Single, Unique Actionsolidity
Improper Encoding or Escaping of Outputpython
Improper Encoding or Escaping of Outputpython
Improper Control of Generation of Code ('Code Injection')ruby
Improper Control of Generation of Code ('Code Injection')ruby
Improper Control of Generation of Code ('Code Injection')ruby
Improper Control of Generation of Code ('Code Injection')ruby
Improper Control of Generation of Code ('Code Injection')ruby
Improper Control of Generation of Code ('Code Injection')ruby
Improper Control of Generation of Code ('Code Injection')ruby
Improper Control of Generation of Code ('Code Injection')php
Improper Control of Generation of Code ('Code Injection')php
Improper Control of Generation of Code ('Code Injection')php
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')java
Improper Control of Generation of Code ('Code Injection')java
Improper Control of Generation of Code ('Code Injection')scala
Improper Control of Generation of Code ('Code Injection')go
Improper Control of Generation of Code ('Code Injection')go
Improper Control of Generation of Code ('Code Injection')go
Improper Control of Generation of Code ('Code Injection')go
Improper Control of Generation of Code ('Code Injection')bash
Improper Control of Generation of Code ('Code Injection')csharp
Improper Control of Dynamically-Managed Code Resourcesyaml
Improper Certificate Validationrust
Improper Certificate Validationrust
Improper Certificate Validationrust
Improper Certificate Validationpython
Improper Certificate Validationhcl
Improper Authorizationsolidity
Improper Authenticationpython
Improper Authenticationjava
Improper Authenticationkotlin
Improper Authenticationhcl
Improper Access Controlsolidity
Improper Access Controlsolidity
Improper Access Controlruby
Improper Access Controlphp
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlyaml
Improper Access Controlyaml
Improper Access Controlyaml
Image tag \":latest\" usedterraform
IAM Users should have MFA enforcement activated.terraform
IAM Password policy should prevent password reuse.terraform
IAM Password policy should have requirement for at least one uppercase character.terraform
IAM Password policy should have requirement for at least one symbol in the password.terraform
IAM Password policy should have requirement for at least one number in the password.terraform
IAM Password policy should have requirement for at least one lowercase character.terraform
IAM Password policy should have minimum password length of 14 or more characters.terraform
IAM Password policy should have expiry less than or equal to 90 days.terraform
IAM Pass Role Filteringterraform
IAM groups should have MFA enforcement activated.terraform
IAM granted directly to user.terraform
hostPath volumes mountedterraform
Generation of Error Message Containing Sensitive Informationcsharp
Force destroy is enabled on Spaces bucket which is dangerousterraform
External Initialization of Trusted Variables or Data Storesjava
External Control of File Name or Pathruby
Exposure of Sensitive Information to an Unauthorized Actorruby
Exposure of Sensitive Information to an Unauthorized Actorphp
Exposure of Sensitive Information to an Unauthorized Actorgo
Exposure of Sensitive Information to an Unauthorized Actorhcl
Exposure of Resource to Wrong Spherepython
Exposure of Information Through Directory Listinggo
Exposure of Information Through Directory Listingcsharp
Exposed Dangerous Method or Functionyaml
Execution with Unnecessary Privilegespython
Execution with Unnecessary Privilegesdockerfile
Execution with Unnecessary Privilegeshcl
Execution with Unnecessary Privilegesyaml
Execution with Unnecessary Privilegesyaml
Execution with Unnecessary Privilegesyaml
Ensure the activity retention log is set to at least a yearterraform
Ensure that the expiration date is set on all keysterraform
Ensure that the --anonymous-auth argument is set to falseterraform
Ensure that no sensitive credentials are exposed in VM custom_dataterraform
Ensure that logging of lock waits is enabled.terraform
Ensure that logging of disconnections is enabled.terraform
Ensure that logging of connections is enabled.terraform
Ensure that logging of checkpoints is enabled.terraform
Ensure that Cloud Storage buckets have uniform bucket-level access enabledterraform
Ensure server parameter 'log_connections' is set to 'ON' for PostgreSQL Database Serverterraform
Ensure server parameter 'log_checkpoints' is set to 'ON' for PostgreSQL Database Serverterraform
Ensure server parameter 'connection_throttling' is set to 'ON' for PostgreSQL Database Serverterraform
Ensure MSK Cluster logging is enabledterraform
Ensure log profile captures all activitiesterraform
Ensure databases are not publicly accessibleterraform
Ensure AKS logging to Azure Monitoring is Configuredterraform
Ensure activitys are captured for all locationsterraform
Enforce Root Hardware Mfaterraform
Enable automated backups to recover from data-lossterraform
Enable All Regionsterraform
EKS Clusters should have cluster control plane logging turned onterraform
Double Freec
Domain logging should be enabled for Elastic Search domainsterraform
DocumentDB logs export should be enabledterraform
Divide By Zeroruby
Disable serial port connectivity for all instancesterraform
Disable project-wide SSH keys for all instancesterraform
Deserialization of Untrusted Dataruby
Deserialization of Untrusted Dataruby
Deserialization of Untrusted Datapython
Deserialization of Untrusted Datapython
Deserialization of Untrusted Datapython
Deserialization of Untrusted Datapython
Deserialization of Untrusted Datapython
Deserialization of Untrusted Dataphp
Deserialization of Untrusted Dataphp
Deserialization of Untrusted Dataocaml
Deserialization of Untrusted Datajava
Deserialization of Untrusted Datajava
Deserialization of Untrusted Datajava
Deserialization of Untrusted Datajava
Deserialization of Untrusted Datajava
Deserialization of Untrusted Datajava
Deserialization of Untrusted Datacsharp
Deserialization of Untrusted Datacsharp
Deserialization of Untrusted Datacsharp
Deserialization of Untrusted Datacsharp
Deserialization of Untrusted Datacsharp
Deserialization of Untrusted Datacsharp
Deserialization of Untrusted Datacsharp
Deserialization of Untrusted Datacsharp
Deserialization of Untrusted Dataclojure
Delete pod logsterraform
Databases should have the minimum TLS set for connectionsterraform
Database auditing rentention period should be longer than 90 daysterraform
Cryptographic Issuesjavascript
Cross-Site Request Forgery (CSRF)javascript
Cross-Site Request Forgery (CSRF)generic
Cross-database ownership chaining should be disabledterraform
Credentials which are no longer used should be disabled.terraform
Container images from public registries usedterraform
Contained database authentication should be disabledterraform
ConfigMap with sensitive contentterraform
Clusters should be set to privateterraform
Cloudfront distribution should have Access Logging configuredterraform
Cloud DNS should use DNSSECterraform
Cleartext Transmission of Sensitive Informationruby
Cleartext Transmission of Sensitive Informationruby
Cleartext Transmission of Sensitive Informationruby
Cleartext Transmission of Sensitive Informationruby
Cleartext Transmission of Sensitive Informationruby
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationjavascript
Cleartext Transmission of Sensitive Informationjavascript
Cleartext Transmission of Sensitive Informationjavascript
Cleartext Transmission of Sensitive Informationjavascript
Cleartext Transmission of Sensitive Informationjavascript
Cleartext Transmission of Sensitive Informationjavascript
Cleartext Transmission of Sensitive Informationjavascript
Cleartext Transmission of Sensitive Informationjavascript
Cleartext Transmission of Sensitive Informationtypescript
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationhtml
Cleartext Transmission of Sensitive Informationgo
Cleartext Transmission of Sensitive Informationgo
Cleartext Transmission of Sensitive Informationgo
Cleartext Transmission of Sensitive Informationgo
Cleartext Transmission of Sensitive Informationgo
Cleartext Transmission of Sensitive Informationgo
Cleartext Transmission of Sensitive Informationgo
Cleartext Transmission of Sensitive Informationhcl
Cleartext Transmission of Sensitive Informationhcl
Cleartext Transmission of Sensitive Informationhcl
Cleartext Transmission of Sensitive Informationyaml
Cleartext Transmission of Sensitive Informationyaml
Cleartext Transmission of Sensitive Informationapex
Checks for service account defined for GKE nodesterraform
Channel Accessible by Non-Endpointgo
Channel Accessible by Non-Endpointgo
Can elevate its own privilegesterraform
Authentication Bypass by Alternate Namego
Auditing should be enabled on Azure SQL Databasesterraform
At least one email address is set for threat alertsterraform
App Service authentication is activatedterraform
API Gateway stages for V1 and V2 should have access logging enabledterraform
API Gateway must have cache enabledterraform
Allocation of File Descriptors or Handles Without Limits or Throttlingc
All container images must start with the *.azurecr.io domainterraform
All container images must start with an ECR domainterraform
All container images must start with a GCR domainterraform
Active Debug Codeapex
Access to host processterraform
A security group rule allows ingress traffic from multiple public addressesterraform
A security group rule allows egress traffic to multiple public addressesterraform
A KMS key is not configured to auto-rotate.terraform
A firewall rule allows traffic from/to the public internetterraform
:latest' tag usedterraform