Referenzkatalog fuer haeufige Security-Findings. Wird vom Security-Audit-Skill gelesen und im PDF-Report als Quellen-Sektion eingebaut.
- OWASP: Nicht direkt gelistet (Infrastruktur)
- CWE: CWE-250 – Execution with Unnecessary Privileges
- Referenzen:
- OWASP: Nicht direkt gelistet (Infrastruktur)
- CWE: CWE-269 – Improper Privilege Management
- Referenzen:
- OWASP: A06:2021 – Vulnerable and Outdated Components
- CWE: CWE-1104 – Use of Unmaintained Third-Party Components
- Referenzen:
- OWASP: A10:2021 – Server-Side Request Forgery
- CWE: CWE-918 – Server-Side Request Forgery
- Referenzen:
- OWASP: A03:2021 – Injection
- CWE: CWE-89 – Improper Neutralization of Special Elements used in an SQL Command
- Referenzen:
- OWASP: A03:2021 – Injection
- CWE: CWE-78 – Improper Neutralization of Special Elements used in an OS Command
- Referenzen:
- OWASP: A03:2021 – Injection
- CWE: CWE-79 – Improper Neutralization of Input During Web Page Generation
- Referenzen:
- OWASP: A03:2021 – Injection
- CWE: CWE-20 – Improper Input Validation
- Referenzen:
- OWASP: A08:2021 – Software and Data Integrity Failures
- CWE: CWE-502 – Deserialization of Untrusted Data
- Referenzen:
- OWASP: A01:2021 – Broken Access Control
- CWE: CWE-22 – Improper Limitation of a Pathname to a Restricted Directory
- Referenzen:
- OWASP: A07:2021 – Identification and Authentication Failures
- CWE: CWE-798 – Use of Hard-coded Credentials
- Referenzen:
- OWASP: A07:2021 – Identification and Authentication Failures
- CWE: CWE-306 – Missing Authentication for Critical Function
- Referenzen:
- OWASP: A09:2021 – Security Logging and Monitoring Failures
- CWE: CWE-532 – Insertion of Sensitive Information into Log File
- Referenzen:
- OWASP: A02:2021 – Cryptographic Failures
- CWE: CWE-319 – Cleartext Transmission of Sensitive Information
- Referenzen:
- OWASP: A07:2021 – Identification and Authentication Failures
- CWE: CWE-287 – Improper Authentication
- Referenzen:
- OWASP: A02:2021 – Cryptographic Failures
- CWE: CWE-522 – Insufficiently Protected Credentials
- Referenzen:
- OWASP: A02:2021 – Cryptographic Failures
- CWE: CWE-311 – Missing Encryption of Sensitive Data
- Referenzen:
- OWASP: Nicht direkt gelistet (DoS/Abuse)
- CWE: CWE-770 – Allocation of Resources Without Limits or Throttling
- Referenzen:
- OWASP: Nicht direkt gelistet (DoS)
- CWE: CWE-770 – Allocation of Resources Without Limits or Throttling
- Referenzen:
- OWASP: Nicht direkt gelistet (DoS)
- CWE: CWE-400 – Uncontrolled Resource Consumption
- Referenzen:
- OWASP: A01:2021 – Broken Access Control
- CWE: CWE-942 – Permissive Cross-domain Policy with Untrusted Domains
- Referenzen:
- OWASP: A05:2021 – Security Misconfiguration
- CWE: CWE-693 – Protection Mechanism Failure
- Referenzen:
- OWASP: A10:2021 – Server-Side Request Forgery
- CWE: CWE-350 – Reliance on Reverse DNS Resolution for a Security-Critical Action
- Referenzen:
- OWASP: A05:2021 – Security Misconfiguration
- CWE: CWE-1188 – Initialization with an Insecure Default
- Referenzen:
- OWASP: Nicht direkt gelistet (Availability)
- CWE: CWE-404 – Improper Resource Shutdown or Release
- Referenzen:
- OWASP: A09:2021 – Security Logging and Monitoring Failures
- CWE: CWE-778 – Insufficient Logging
- Referenzen:
- OWASP: A06:2021 – Vulnerable and Outdated Components
- CWE: CWE-1035 – Cross-Cutting Concerns
- Referenzen:
- OWASP: A06:2021 – Vulnerable and Outdated Components
- CWE: CWE-1104 – Use of Unmaintained Third-Party Components
- Referenzen:
- OWASP: A06:2021 – Vulnerable and Outdated Components
- CWE: CWE-1104 – Use of Unmaintained Third-Party Components
- Referenzen:
- OWASP: A02:2021 – Cryptographic Failures
- CWE: CWE-214 – Invocation of Process Using Visible Sensitive Information
- Referenzen:
- OWASP: A06:2021 – Vulnerable and Outdated Components
- CWE: CWE-1035 – Cross-Cutting Concerns
- Referenzen:
- OWASP: A06:2021 – Vulnerable and Outdated Components
- CWE: CWE-1035 – Cross-Cutting Concerns
- Referenzen:
- OWASP Top 10:2021: https://owasp.org/Top10/
- OWASP Cheat Sheet Series: https://cheatsheetseries.owasp.org/
- CWE (Common Weakness Enumeration): https://cwe.mitre.org/
- NIST NVD (National Vulnerability Database): https://nvd.nist.gov/
- Docker Security Best Practices: https://docs.docker.com/engine/security/
- Node.js Security Best Practices: https://nodejs.org/en/learn/getting-started/security-best-practices
- OWASP Docker Security Cheat Sheet: https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html
- OWASP REST Security Cheat Sheet: https://cheatsheetseries.owasp.org/cheatsheets/REST_Security_Cheat_Sheet.html