10095 lines
356 KiB
YAML
10095 lines
356 KiB
YAML
rules:
|
|
- id: generic.nginx.security.insecure-ssl-version.insecure-ssl-version
|
|
patterns:
|
|
- pattern-not: ssl_protocols TLSv1.2 TLSv1.3;
|
|
- pattern-not: ssl_protocols TLSv1.3 TLSv1.2;
|
|
- pattern-not: ssl_protocols TLSv1.2;
|
|
- pattern-not: ssl_protocols TLSv1.3;
|
|
- pattern: ssl_protocols ...;
|
|
paths:
|
|
include:
|
|
- '*.conf'
|
|
- '*.vhost'
|
|
- '**/sites-available/*'
|
|
- '**/sites-enabled/*'
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
message: Detected use of an insecure SSL version. Secure SSL versions are TLSv1.2
|
|
and TLS1.3; older versions are known to be broken and are susceptible to attacks.
|
|
Prefer use of TLSv1.2 or later.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
references:
|
|
- https://www.acunetix.com/blog/web-security-zone/hardening-nginx/
|
|
- https://www.acunetix.com/blog/articles/tls-ssl-cipher-hardening/
|
|
category: security
|
|
technology:
|
|
- nginx
|
|
confidence: HIGH
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/generic.nginx.security.insecure-ssl-version.insecure-ssl-version
|
|
shortlink: https://sg.run/gLKy
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9041
|
|
rv_id: 1262676
|
|
rule_id: WAUo9k
|
|
version_id: vdT06O4
|
|
url: https://semgrep.dev/playground/r/vdT06O4/generic.nginx.security.insecure-ssl-version.insecure-ssl-version
|
|
origin: community
|
|
- id: go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-300: Channel Accessible by Non-Endpoint'
|
|
references:
|
|
- https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption
|
|
category: security
|
|
technology:
|
|
- grpc
|
|
confidence: HIGH
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection
|
|
shortlink: https://sg.run/J9yZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9090
|
|
rv_id: 1262916
|
|
rule_id: PeUZ4X
|
|
version_id: YDTZeZB
|
|
url: https://semgrep.dev/playground/r/YDTZeZB/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection
|
|
origin: community
|
|
message: 'Found an insecure gRPC connection using ''grpc.WithInsecure()''. This
|
|
creates a connection without encryption to a gRPC server. A malicious attacker
|
|
could tamper with the gRPC message, which could compromise the machine. Instead,
|
|
establish a secure connection with an SSL certificate using the ''grpc.WithTransportCredentials()''
|
|
function. You can create a create credentials using a ''tls.Config{}'' struct
|
|
with ''credentials.NewTLS()''. The final fix looks like this: ''grpc.WithTransportCredentials(credentials.NewTLS(<config>))''.'
|
|
languages:
|
|
- go
|
|
severity: ERROR
|
|
pattern: $GRPC.Dial($ADDR, ..., $GRPC.WithInsecure(...), ...)
|
|
fix-regex:
|
|
regex: (.*)WithInsecure\(.*?\)
|
|
replacement: \1WithTransportCredentials(credentials.NewTLS(<your_tls_config_here>))
|
|
- id: go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-300: Channel Accessible by Non-Endpoint'
|
|
references:
|
|
- https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption
|
|
category: security
|
|
technology:
|
|
- grpc
|
|
confidence: HIGH
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection
|
|
shortlink: https://sg.run/5Q5l
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9091
|
|
rv_id: 1262917
|
|
rule_id: JDUy0B
|
|
version_id: 6xT2923
|
|
url: https://semgrep.dev/playground/r/6xT2923/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection
|
|
origin: community
|
|
message: Found an insecure gRPC server without 'grpc.Creds()' or options with credentials.
|
|
This allows for a connection without encryption to this server. A malicious attacker
|
|
could tamper with the gRPC message, which could compromise the machine. Include
|
|
credentials derived from an SSL certificate in order to create a secure gRPC connection.
|
|
You can create credentials using 'credentials.NewServerTLSFromFile("cert.pem",
|
|
"cert.key")'.
|
|
languages:
|
|
- go
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sinks:
|
|
- requires: OPTIONS and not CREDS
|
|
pattern: grpc.NewServer($OPT, ...)
|
|
- requires: EMPTY_CONSTRUCTOR
|
|
pattern: grpc.NewServer()
|
|
pattern-sources:
|
|
- label: OPTIONS
|
|
pattern: grpc.ServerOption{ ... }
|
|
- label: CREDS
|
|
pattern: grpc.Creds(...)
|
|
- label: EMPTY_CONSTRUCTOR
|
|
pattern: grpc.NewServer()
|
|
- id: go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm
|
|
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
|
|
assumes the integrity of the token has already been verified. This would allow
|
|
a malicious actor to forge a JWT token that will automatically be verified. Do
|
|
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm
|
|
shortlink: https://sg.run/Gej1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9092
|
|
rv_id: 1262919
|
|
rule_id: 5rUOWQ
|
|
version_id: zyTb2bz
|
|
url: https://semgrep.dev/playground/r/zyTb2bz/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import "github.com/golang-jwt/jwt"
|
|
...
|
|
- pattern-inside: |
|
|
import "github.com/dgrijalva/jwt-go"
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
jwt.SigningMethodNone
|
|
- pattern: jwt.UnsafeAllowNoneSignatureType
|
|
- id: go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion
|
|
message: '`MinVersion` is missing from this TLS configuration. By default, as of
|
|
Go 1.22, TLS 1.2 is currently used as the minimum. General purpose web applications
|
|
should default to TLS 1.3 with all other protocols disabled. Only where it is
|
|
known that a web server must support legacy clients with unsupported an insecure
|
|
browsers (such as Internet Explorer 10), it may be necessary to enable TLS 1.0
|
|
to provide support. Add `MinVersion: tls.VersionTLS13'' to the TLS configuration
|
|
to bump the minimum version to TLS 1.3.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go
|
|
references:
|
|
- https://go.dev/doc/go1.22#minor_library_changes
|
|
- https://pkg.go.dev/crypto/tls#:~:text=MinVersion
|
|
- https://www.us-cert.gov/ncas/alerts/TA14-290A
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion
|
|
shortlink: https://sg.run/oxEN
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9116
|
|
rv_id: 1262924
|
|
rule_id: NbUk4X
|
|
version_id: 1QTypyp
|
|
url: https://semgrep.dev/playground/r/1QTypyp/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern: |
|
|
tls.Config{ $...CONF }
|
|
- pattern-not: |
|
|
tls.Config{..., MinVersion: ..., ...}
|
|
fix: |
|
|
tls.Config{ $...CONF, MinVersion: tls.VersionTLS13 }
|
|
- id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure
|
|
message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14,
|
|
SSLv3 will be removed. Instead, use 'tls.VersionTLS13'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go
|
|
references:
|
|
- https://golang.org/doc/go1.14#crypto/tls
|
|
- https://www.us-cert.gov/ncas/alerts/TA14-290A
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure
|
|
shortlink: https://sg.run/zvE1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9117
|
|
rv_id: 1262926
|
|
rule_id: kxUkJ2
|
|
version_id: yeTxpxj
|
|
url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
fix-regex:
|
|
regex: VersionSSL30
|
|
replacement: VersionTLS13
|
|
pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}'
|
|
- id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher
|
|
message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered
|
|
weak. Use the function 'tls.CipherSuites()' to get a list of good cipher suites.
|
|
See https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other
|
|
cipher suites to use.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go
|
|
references:
|
|
- https://golang.org/pkg/crypto/tls/#InsecureCipherSuites
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher
|
|
shortlink: https://sg.run/px8N
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9118
|
|
rv_id: 1262927
|
|
rule_id: wdUJYk
|
|
version_id: rxTAKAZ
|
|
url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}
|
|
- id: go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key
|
|
message: RSA keys should be at least 2048 bits
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/securego/gosec/blob/master/rules/rsa.go
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key
|
|
shortlink: https://sg.run/9oY4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9123
|
|
rv_id: 1262932
|
|
rule_id: d8UjY3
|
|
version_id: xyTjz8L
|
|
url: https://semgrep.dev/playground/r/xyTjz8L/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
rsa.GenerateKey(..., $BITS)
|
|
- pattern: |
|
|
rsa.GenerateMultiPrimeKey(..., $BITS)
|
|
- metavariable-comparison:
|
|
metavariable: $BITS
|
|
comparison: $BITS < 2048
|
|
- focus-metavariable:
|
|
- $BITS
|
|
fix: |
|
|
2048
|
|
- id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces
|
|
message: Detected a network listener listening on 0.0.0.0 or an empty string. This
|
|
could unexpectedly expose the server publicly as it binds to all available interfaces.
|
|
Instead, specify another IP address that is not 0.0.0.0 nor the empty string.
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
source-rule-url: https://github.com/securego/gosec
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces
|
|
shortlink: https://sg.run/rdE0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9125
|
|
rv_id: 1262939
|
|
rule_id: nJUz3J
|
|
version_id: ExTExoK
|
|
url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...)
|
|
- pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...)
|
|
- pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...)
|
|
- pattern: net.Listen($NETWORK, "=~/^:.*$/", ...)
|
|
- id: java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
technology:
|
|
- java
|
|
- secrets
|
|
- jwt
|
|
category: security
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret
|
|
shortlink: https://sg.run/RoDK
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9149
|
|
rv_id: 1262980
|
|
rule_id: oqUeAn
|
|
version_id: d6Tyx8j
|
|
url: https://semgrep.dev/playground/r/d6Tyx8j/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret
|
|
origin: community
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(Algorithm $ALG) = $ALGO.$HMAC("$Y");
|
|
- pattern: |
|
|
$SECRET = "$Y";
|
|
...
|
|
(Algorithm $ALG) = $ALGO.$HMAC($SECRET);
|
|
- pattern: |
|
|
class $CLASS {
|
|
...
|
|
$TYPE $SECRET = "$Y";
|
|
...
|
|
$RETURNTYPE $FUNC (...) {
|
|
...
|
|
(Algorithm $ALG) = $ALGO.$HMAC($SECRET);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- focus-metavariable: $Y
|
|
- metavariable-regex:
|
|
metavariable: $HMAC
|
|
regex: (HMAC384|HMAC256|HMAC512)
|
|
- id: java.java-jwt.security.jwt-none-alg.java-jwt-none-alg
|
|
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
|
|
assumes the integrity of the token has already been verified. This would allow
|
|
a malicious actor to forge a JWT token that will automatically be verified. Do
|
|
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg
|
|
shortlink: https://sg.run/Av14
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9150
|
|
rv_id: 1262981
|
|
rule_id: zdUkzR
|
|
version_id: ZRTKADq
|
|
url: https://semgrep.dev/playground/r/ZRTKADq/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg
|
|
origin: community
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
pattern-either:
|
|
- pattern: |
|
|
$JWT.sign(com.auth0.jwt.algorithms.Algorithm.none());
|
|
- pattern: |
|
|
$NONE = com.auth0.jwt.algorithms.Algorithm.none();
|
|
...
|
|
$JWT.sign($NONE);
|
|
- pattern: |-
|
|
class $CLASS {
|
|
...
|
|
$TYPE $NONE = com.auth0.jwt.algorithms.Algorithm.none();
|
|
...
|
|
$RETURNTYPE $FUNC (...) {
|
|
...
|
|
$JWT.sign($NONE);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- id: java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BLOWFISH_KEY_SIZE
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size
|
|
shortlink: https://sg.run/9o74
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9167
|
|
rv_id: 1262989
|
|
rule_id: d8UjJ3
|
|
version_id: 3ZT4X2r
|
|
url: https://semgrep.dev/playground/r/3ZT4X2r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size
|
|
origin: community
|
|
message: Using less than 128 bits for Blowfish is considered insecure. Use 128 bits
|
|
or more, or switch to use AES instead.
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
patterns:
|
|
- pattern: |
|
|
$KEYGEN = KeyGenerator.getInstance("Blowfish");
|
|
...
|
|
$KEYGEN.init($SIZE);
|
|
- metavariable-comparison:
|
|
metavariable: $SIZE
|
|
comparison: $SIZE < 128
|
|
- id: java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle
|
|
message: Using CBC with PKCS5Padding is susceptible to padding oracle attacks. A
|
|
malicious actor could discern the difference between plaintext with valid or invalid
|
|
padding. Further, CBC mode does not include any integrity checks. Use 'AES/GCM/NoPadding'
|
|
instead.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PADDING_ORACLE
|
|
references:
|
|
- https://capec.mitre.org/data/definitions/463.html
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes
|
|
- https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle
|
|
shortlink: https://sg.run/ydxr
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9168
|
|
rv_id: 1262990
|
|
rule_id: ZqU5oD
|
|
version_id: 44TEjbE
|
|
url: https://semgrep.dev/playground/r/44TEjbE/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle
|
|
origin: community
|
|
severity: WARNING
|
|
fix: |
|
|
"AES/GCM/NoPadding"
|
|
languages:
|
|
- java
|
|
patterns:
|
|
- pattern-inside: Cipher.getInstance("=~/.*\/CBC\/PKCS5Padding/")
|
|
- pattern: |
|
|
"=~/.*\/CBC\/PKCS5Padding/"
|
|
- id: java.lang.security.audit.weak-ssl-context.weak-ssl-context
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source_rule_url: https://find-sec-bugs.github.io/bugs.htm#SSL_CONTEXT
|
|
references:
|
|
- https://tools.ietf.org/html/rfc7568
|
|
- https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.weak-ssl-context.weak-ssl-context
|
|
shortlink: https://sg.run/4x7E
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9188
|
|
rv_id: 1263050
|
|
rule_id: KxUb1k
|
|
version_id: 5PTo1rW
|
|
url: https://semgrep.dev/playground/r/5PTo1rW/java.lang.security.audit.weak-ssl-context.weak-ssl-context
|
|
origin: community
|
|
message: An insecure SSL context was detected. TLS versions 1.0, 1.1, and all SSL
|
|
versions are considered weak encryption and are deprecated. Use SSLContext.getInstance("TLSv1.2")
|
|
for the best security.
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
patterns:
|
|
- pattern-not: SSLContext.getInstance("TLSv1.3")
|
|
- pattern-not: SSLContext.getInstance("TLSv1.2")
|
|
- pattern: SSLContext.getInstance("...")
|
|
fix-regex:
|
|
regex: (.*?)\.getInstance\(.*?\)
|
|
replacement: \1.getInstance("TLSv1.2")
|
|
- id: java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated
|
|
message: DES is considered deprecated. AES is the recommended cipher. Upgrade to
|
|
use AES. See https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard
|
|
for more information.
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::javax.crypto
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DES_USAGE
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
references:
|
|
- https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated
|
|
shortlink: https://sg.run/5Q73
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9191
|
|
rv_id: 1262996
|
|
rule_id: PeUZNg
|
|
version_id: A8TgdEn
|
|
url: https://semgrep.dev/playground/r/A8TgdEn/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated
|
|
origin: community
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $CIPHER.getInstance("=~/DES/.*/")
|
|
- pattern-inside: $CIPHER.getInstance("DES")
|
|
- pattern-either:
|
|
- pattern: |
|
|
"=~/DES/.*/"
|
|
- pattern: |
|
|
"DES"
|
|
fix: |
|
|
"AES/GCM/NoPadding"
|
|
languages:
|
|
- java
|
|
- kt
|
|
- id: java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated
|
|
message: Triple DES (3DES or DESede) is considered deprecated. AES is the recommended
|
|
cipher. Upgrade to use AES.
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::javax.crypto
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#TDES_USAGE
|
|
references:
|
|
- https://csrc.nist.gov/News/2017/Update-to-Current-Use-and-Deprecation-of-TDEA
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated
|
|
shortlink: https://sg.run/Geqn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9192
|
|
rv_id: 1262997
|
|
rule_id: JDUy8J
|
|
version_id: BjTkZyQ
|
|
url: https://semgrep.dev/playground/r/BjTkZyQ/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated
|
|
origin: community
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$CIPHER.getInstance("=~/DESede.*/")
|
|
- pattern: |
|
|
$CRYPTO.KeyGenerator.getInstance("DES")
|
|
languages:
|
|
- java
|
|
- kt
|
|
- id: java.lang.security.audit.crypto.ecb-cipher.ecb-cipher
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::mode::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher
|
|
shortlink: https://sg.run/Ro9K
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9193
|
|
rv_id: 1262998
|
|
rule_id: 5rUOb6
|
|
version_id: DkTRbwL
|
|
url: https://semgrep.dev/playground/r/DkTRbwL/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher
|
|
origin: community
|
|
message: Cipher in ECB mode is detected. ECB mode produces the same output for the
|
|
same input each time which allows an attacker to intercept and replay the data.
|
|
Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY.
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
patterns:
|
|
- pattern: |
|
|
Cipher $VAR = $CIPHER.getInstance($MODE);
|
|
- metavariable-regex:
|
|
metavariable: $MODE
|
|
regex: .*ECB.*
|
|
- id: java.lang.security.audit.crypto.no-null-cipher.no-null-cipher
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: new NullCipher(...);
|
|
- pattern: new javax.crypto.NullCipher(...);
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher
|
|
shortlink: https://sg.run/AvA4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9194
|
|
rv_id: 1263001
|
|
rule_id: GdU7pw
|
|
version_id: K3TKkgB
|
|
url: https://semgrep.dev/playground/r/K3TKkgB/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher
|
|
origin: community
|
|
message: 'NullCipher was detected. This will not encrypt anything; the cipher text
|
|
will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING").
|
|
See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for
|
|
more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector
|
|
message: Initialization Vectors (IVs) for block ciphers should be randomly generated
|
|
each time they are used. Using a static IV means the same plaintext encrypts to
|
|
the same ciphertext every time, weakening the strength of the encryption.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-329: Generation of Predictable IV with CBC Mode'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#STATIC_IV
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/329.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector
|
|
shortlink: https://sg.run/BkB5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9195
|
|
rv_id: 1263002
|
|
rule_id: ReUgj1
|
|
version_id: qkTR7vP
|
|
url: https://semgrep.dev/playground/r/qkTR7vP/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
pattern-either:
|
|
- pattern: |
|
|
byte[] $IV = {
|
|
...
|
|
};
|
|
...
|
|
new IvParameterSpec($IV, ...);
|
|
- pattern: |
|
|
class $CLASS {
|
|
byte[] $IV = {
|
|
...
|
|
};
|
|
...
|
|
$METHOD(...) {
|
|
...
|
|
new IvParameterSpec($IV, ...);
|
|
...
|
|
}
|
|
}
|
|
- id: java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::mode::javax.crypto
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_NO_PADDING
|
|
references:
|
|
- https://rdist.root.org/2009/10/06/why-rsa-encryption-padding-is-critical/
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
- kotlin
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding
|
|
shortlink: https://sg.run/DoOj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9196
|
|
rv_id: 1263003
|
|
rule_id: AbUzoj
|
|
version_id: l4TJRpK
|
|
url: https://semgrep.dev/playground/r/l4TJRpK/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding
|
|
origin: community
|
|
message: Using RSA without OAEP mode weakens the encryption.
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- kt
|
|
pattern: $CIPHER.getInstance("=~/RSA/[Nn][Oo][Nn][Ee]/NoPadding/")
|
|
- id: java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket
|
|
metadata:
|
|
functional-categories:
|
|
- net::search::crypto-config::java.net
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket
|
|
shortlink: https://sg.run/W8zA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9197
|
|
rv_id: 1263008
|
|
rule_id: BYUN3X
|
|
version_id: RGT0LEj
|
|
url: https://semgrep.dev/playground/r/RGT0LEj/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket
|
|
origin: community
|
|
message: Detected use of a Java socket that is not encrypted. As a result, the traffic
|
|
could be read by an attacker intercepting the network traffic. Use an SSLSocket
|
|
created by 'SSLSocketFactory' or 'SSLServerSocketFactory' instead.
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
pattern-either:
|
|
- pattern: new ServerSocket(...)
|
|
- pattern: new Socket(...)
|
|
- id: java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key
|
|
message: RSA keys should be at least 2048 bits based on NIST recommendation.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::key-length::java.security
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key
|
|
shortlink: https://sg.run/4x6x
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9200
|
|
rv_id: 1263019
|
|
rule_id: 0oU5P5
|
|
version_id: o5TbDLY
|
|
url: https://semgrep.dev/playground/r/o5TbDLY/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key
|
|
origin: community
|
|
patterns:
|
|
- pattern: |
|
|
KeyPairGenerator $KEY = $G.getInstance("RSA");
|
|
...
|
|
$KEY.initialize($BITS);
|
|
- metavariable-comparison:
|
|
metavariable: $BITS
|
|
comparison: $BITS < 2048
|
|
- id: javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled
|
|
message: $sceProvider is set to false. Disabling Strict Contextual escaping (SCE)
|
|
in an AngularJS application could provide additional attack surface for XSS vulnerabilities.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
references:
|
|
- https://docs.angularjs.org/api/ng/service/$sce
|
|
- https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf
|
|
category: security
|
|
technology:
|
|
- angular
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled
|
|
shortlink: https://sg.run/N4DG
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9227
|
|
rv_id: 1263094
|
|
rule_id: EwU20Z
|
|
version_id: 5PTo1EW
|
|
url: https://semgrep.dev/playground/r/5PTo1EW/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
pattern: |
|
|
$sceProvider.enabled(false);
|
|
- id: javascript.browser.security.open-redirect.js-open-redirect
|
|
message: The application accepts potentially user-controlled input `$PROP` which
|
|
can control the location of the current window context. This can lead two types
|
|
of vulnerabilities open-redirection and Cross-Site-Scripting (XSS) with JavaScript
|
|
URIs. It is recommended to validate user-controllable input before allowing it
|
|
to control the redirection.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
cwe:
|
|
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.1 Insecue Redirect
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation
|
|
version: '4'
|
|
category: security
|
|
confidence: HIGH
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html
|
|
technology:
|
|
- browser
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Open Redirect
|
|
source: https://semgrep.dev/r/javascript.browser.security.open-redirect.js-open-redirect
|
|
shortlink: https://sg.run/3xRe
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9243
|
|
rv_id: 1263122
|
|
rule_id: WAUopl
|
|
version_id: pZT03x0
|
|
url: https://semgrep.dev/playground/r/pZT03x0/javascript.browser.security.open-redirect.js-open-redirect
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
new URLSearchParams($WINDOW. ... .location.search).get('...')
|
|
- pattern: |
|
|
new URLSearchParams(location.search).get('...')
|
|
- pattern: |
|
|
new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...')
|
|
- pattern: |
|
|
new URLSearchParams(location.hash.substring(1)).get('...')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PROPS = new URLSearchParams($WINDOW. ... .location.search)
|
|
...
|
|
- pattern-inside: |
|
|
$PROPS = new URLSearchParams(location.search)
|
|
...
|
|
- pattern-inside: |
|
|
$PROPS = new URLSearchParams($WINDOW. ... .location.hash.substring(1))
|
|
...
|
|
- pattern-inside: |
|
|
$PROPS = new URLSearchParams(location.hash.substring(1))
|
|
...
|
|
- pattern: $PROPS.get('...')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PROPS = new URL($WINDOW. ... .location.href)
|
|
...
|
|
- pattern-inside: |
|
|
$PROPS = new URL(location.href)
|
|
...
|
|
- pattern: $PROPS.searchParams.get('...')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
new URL($WINDOW. ... .location.href).searchParams.get('...')
|
|
- pattern: |
|
|
new URL(location.href).searchParams.get('...')
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: location.href = $SINK
|
|
- pattern: $THIS. ... .location.href = $SINK
|
|
- pattern: location.replace($SINK)
|
|
- pattern: $THIS. ... .location.replace($SINK)
|
|
- pattern: location = $SINK
|
|
- pattern: $WINDOW. ... .location = $SINK
|
|
- focus-metavariable: $SINK
|
|
- metavariable-pattern:
|
|
patterns:
|
|
- pattern-not: |
|
|
"..." + $VALUE
|
|
- pattern-not: |
|
|
`...${$VALUE}`
|
|
metavariable: $SINK
|
|
- id: javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
category: security
|
|
technology:
|
|
- express
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret
|
|
shortlink: https://sg.run/Do1d
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9252
|
|
rv_id: 1263166
|
|
rule_id: pKUOjy
|
|
version_id: pZT03Q0
|
|
url: https://semgrep.dev/playground/r/pZT03Q0/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$JWT = require('express-jwt');
|
|
...
|
|
- pattern-inside: |
|
|
import $JWT from 'express-jwt';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $JWT from 'express-jwt';
|
|
...
|
|
- pattern-inside: |
|
|
import { ..., $JWT, ... } from 'express-jwt';
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
$JWT({...,secret: "$Y",...},...)
|
|
- pattern: |
|
|
$OPTS = "$Y";
|
|
...
|
|
$JWT({...,secret: $OPTS},...);
|
|
- focus-metavariable: $Y
|
|
- id: javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
metadata:
|
|
interfile: true
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
asvs:
|
|
section: 'V3: Session Management Verification Requirements'
|
|
control_id: 3.5.2 Static API keys or secret
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- jose
|
|
- jwt
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret
|
|
shortlink: https://sg.run/Ro1g
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9293
|
|
rv_id: 1263182
|
|
rule_id: JDUyRl
|
|
version_id: d6TyxbX
|
|
url: https://semgrep.dev/playground/r/d6TyxbX/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
$JOSE = require("jose");
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
var {JWT} = $JOSE;
|
|
...
|
|
- pattern-inside: |
|
|
var {JWK, JWT} = $JOSE;
|
|
...
|
|
- pattern-inside: |
|
|
const {JWT} = $JOSE;
|
|
...
|
|
- pattern-inside: |
|
|
const {JWK, JWT} = $JOSE;
|
|
...
|
|
- pattern-inside: |
|
|
let {JWT} = $JOSE;
|
|
...
|
|
- pattern-inside: |
|
|
let {JWK, JWT} = $JOSE;
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
JWT.verify($P, "...", ...);
|
|
- pattern: |
|
|
JWT.sign($P, "...", ...);
|
|
- pattern: "JWT.verify($P, JWK.asKey(\"...\"), ...); \n"
|
|
- pattern: |
|
|
$JWT.sign($P, JWK.asKey("..."), ...);
|
|
options:
|
|
symbolic_propagation: true
|
|
interfile: true
|
|
- id: javascript.jose.security.jwt-none-alg.jwt-none-alg
|
|
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
|
|
assumes the integrity of the token has already been verified. This would allow
|
|
a malicious actor to forge a JWT token that will automatically be verified. Do
|
|
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
asvs:
|
|
section: 'V3: Session Management Verification Requirements'
|
|
control_id: 3.5.3 Insecue Stateless Session Tokens
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- jose
|
|
- jwt
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.jose.security.jwt-none-alg.jwt-none-alg
|
|
shortlink: https://sg.run/AvRL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9294
|
|
rv_id: 1263183
|
|
rule_id: 5rUOGN
|
|
version_id: ZRTKAyb
|
|
url: https://semgrep.dev/playground/r/ZRTKAyb/javascript.jose.security.jwt-none-alg.jwt-none-alg
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
pattern-either:
|
|
- pattern: |
|
|
var $JOSE = require("jose");
|
|
...
|
|
var { JWK, JWT } = $JOSE;
|
|
...
|
|
var $T = JWT.verify($P, JWK.None,...);
|
|
- pattern: |
|
|
var $JOSE = require("jose");
|
|
...
|
|
var { JWK, JWT } = $JOSE;
|
|
...
|
|
$T = JWT.verify($P, JWK.None,...);
|
|
- pattern: |
|
|
var $JOSE = require("jose");
|
|
...
|
|
var { JWK, JWT } = $JOSE;
|
|
...
|
|
JWT.verify($P, JWK.None,...);
|
|
- id: javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
asvs:
|
|
section: 'V3: Session Management Verification Requirements'
|
|
control_id: 3.5.2 Static API keys or secret
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
- javascript
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret
|
|
shortlink: https://sg.run/4xN9
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9300
|
|
rv_id: 1263189
|
|
rule_id: WAUon7
|
|
version_id: gETB75D
|
|
url: https://semgrep.dev/playground/r/gETB75D/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: "$X = '...' \n"
|
|
- pattern: "$X = '$Y' \n"
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$JWT.sign($DATA,"...",...);
|
|
- pattern-inside: |
|
|
$JWT.verify($DATA,"...",...);
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$JWT = require("jsonwebtoken")
|
|
...
|
|
- pattern-inside: |
|
|
import $JWT from "jsonwebtoken"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $JWT from "jsonwebtoken"
|
|
...
|
|
- pattern-inside: |
|
|
import {...,$JWT,...} from "jsonwebtoken"
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$JWT.sign($DATA,$VALUE,...);
|
|
- pattern-inside: |
|
|
$JWT.verify($DATA,$VALUE,...);
|
|
- focus-metavariable: $VALUE
|
|
- id: javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
asvs:
|
|
section: 'V3: Session Management Verification Requirements'
|
|
control_id: 3.5.2 Static API keys or secret
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
- nodejs
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret
|
|
shortlink: https://sg.run/vz70
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9333
|
|
rv_id: 1263225
|
|
rule_id: QrUzq6
|
|
version_id: X0TzyoE
|
|
url: https://semgrep.dev/playground/r/X0TzyoE/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- by-side-effect: true
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
{..., clientSecret: "...", ...}
|
|
- pattern: |
|
|
{..., secretOrKey: "...", ...}
|
|
- pattern: |
|
|
{..., consumerSecret: "...", ...}
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$OBJ = {}
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
$OBJ.clientSecret = "..."
|
|
- pattern: |
|
|
$OBJ.secretOrKey = "..."
|
|
- pattern: |
|
|
$OBJ.consumerSecret = "..."
|
|
- pattern: $OBJ
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$SECRET = '...'
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
{..., clientSecret: $SECRET, ...}
|
|
- pattern: |
|
|
{..., secretOrKey: $SECRET, ...}
|
|
- pattern: |
|
|
{..., consumerSecret: $SECRET, ...}
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$SECRET = '...'
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$VALUE = {..., clientSecret: $SECRET, ...}
|
|
...
|
|
- pattern-inside: |
|
|
$VALUE = {..., secretOrKey: $SECRET, ...}
|
|
...
|
|
- pattern-inside: |
|
|
$VALUE = {..., consumerSecret: $SECRET, ...}
|
|
...
|
|
- pattern: $VALUE
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$F = require("$I").Strategy
|
|
...
|
|
- pattern-inside: |
|
|
$F = require("$I")
|
|
...
|
|
- pattern-inside: |
|
|
import { $STRAT as $F } from '$I'
|
|
...
|
|
- pattern-inside: |
|
|
import $F from '$I'
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $I
|
|
regex: (passport-.*)
|
|
- pattern-inside: |
|
|
new $F($VALUE,...)
|
|
- focus-metavariable: $VALUE
|
|
- id: php.lang.security.assert-use.assert-use
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
- pattern: $_COOKIE
|
|
- pattern: $_REQUEST
|
|
- pattern: $_SERVER
|
|
- patterns:
|
|
- pattern: |
|
|
Route::$METHOD($ROUTENAME, function(..., $ARG, ...) { ... })
|
|
- focus-metavariable: $ARG
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: assert($SINK, ...);
|
|
- pattern-not: assert("...", ...);
|
|
- pattern: $SINK
|
|
message: Calling assert with user input is equivalent to eval'ing.
|
|
metadata:
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
references:
|
|
- https://www.php.net/manual/en/function.assert
|
|
- https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/AssertsSniff.php
|
|
category: security
|
|
technology:
|
|
- php
|
|
confidence: HIGH
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/php.lang.security.assert-use.assert-use
|
|
shortlink: https://sg.run/3xXW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9387
|
|
rv_id: 1263272
|
|
rule_id: DbUpjk
|
|
version_id: 9lT4bLx
|
|
url: https://semgrep.dev/playground/r/9lT4bLx/php.lang.security.assert-use.assert-use
|
|
origin: community
|
|
languages:
|
|
- php
|
|
severity: ERROR
|
|
- id: python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host
|
|
message: Running flask app with host 0.0.0.0 could expose the server publicly.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-668: Exposure of Resource to Wrong Sphere'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- flask
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host
|
|
shortlink: https://sg.run/eLby
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9532
|
|
rv_id: 1263414
|
|
rule_id: L1Uy1n
|
|
version_id: BjTkZOY
|
|
url: https://semgrep.dev/playground/r/BjTkZOY/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern: app.run(..., host="0.0.0.0", ...)
|
|
- pattern: app.run(..., "0.0.0.0", ...)
|
|
- id: python.flask.security.audit.debug-enabled.debug-enabled
|
|
patterns:
|
|
- pattern-inside: |
|
|
import flask
|
|
...
|
|
- pattern: $APP.run(..., debug=True, ...)
|
|
message: Detected Flask app with debug=True. Do not deploy to production with this
|
|
flag enabled as it will leak sensitive information. Instead, consider using Flask
|
|
configuration variables or setting 'debug' using system environment variables.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-489: Active Debug Code'
|
|
owasp: A06:2017 - Security Misconfiguration
|
|
references:
|
|
- https://labs.detectify.com/2015/10/02/how-patreon-got-hacked-publicly-exposed-werkzeug-debugger/
|
|
category: security
|
|
technology:
|
|
- flask
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Active Debug Code
|
|
source: https://semgrep.dev/r/python.flask.security.audit.debug-enabled.debug-enabled
|
|
shortlink: https://sg.run/dKrd
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9534
|
|
rv_id: 946206
|
|
rule_id: gxU1bd
|
|
version_id: 8KTKjwR
|
|
url: https://semgrep.dev/playground/r/8KTKjwR/python.flask.security.audit.debug-enabled.debug-enabled
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
- id: python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret
|
|
message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently
|
|
Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html
|
|
Consider using an appropriate security mechanism to protect the credentials (e.g.
|
|
keeping secrets in environment variables)'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
references:
|
|
- https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret
|
|
shortlink: https://sg.run/l2E9
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9557
|
|
rv_id: 1263452
|
|
rule_id: X5U8P5
|
|
version_id: PkTR3X3
|
|
url: https://semgrep.dev/playground/r/PkTR3X3/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret
|
|
origin: community
|
|
patterns:
|
|
- pattern: |
|
|
jwt.encode($_, "...", ...)
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces
|
|
message: Running `socket.bind` to 0.0.0.0, or empty string could unexpectedly expose
|
|
the server publicly as it binds to all available interfaces. Consider instead
|
|
getting correct address from an environment variable or configuration file.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- python
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces
|
|
shortlink: https://sg.run/rdln
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9669
|
|
rv_id: 1263505
|
|
rule_id: OrU3og
|
|
version_id: 0bTKzDL
|
|
url: https://semgrep.dev/playground/r/0bTKzDL/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: INFO
|
|
pattern-either:
|
|
- pattern: |
|
|
$S = socket.socket(...)
|
|
...
|
|
$S.bind(("0.0.0.0", ...))
|
|
- pattern: |
|
|
$S = socket.socket(...)
|
|
...
|
|
$S.bind(("::", ...))
|
|
- pattern: |
|
|
$S = socket.socket(...)
|
|
...
|
|
$S.bind(("", ...))
|
|
- id: python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size
|
|
message: Detected an insufficient key size for DSA. NIST recommends a key size of
|
|
2048 or higher.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
|
|
references:
|
|
- https://www.pycryptodome.org/src/public_key/dsa
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::key-length::pycryptodome
|
|
- crypto::search::key-length::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size
|
|
shortlink: https://sg.run/4y8l
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9688
|
|
rv_id: 1263554
|
|
rule_id: AbUWje
|
|
version_id: JdTzxbQ
|
|
url: https://semgrep.dev/playground/r/JdTzxbQ/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: Crypto.PublicKey.DSA.generate(..., bits=$SIZE, ...)
|
|
- pattern: Crypto.PublicKey.DSA.generate($SIZE, ...)
|
|
- pattern: Cryptodome.PublicKey.DSA.generate(..., bits=$SIZE, ...)
|
|
- pattern: Cryptodome.PublicKey.DSA.generate($SIZE, ...)
|
|
- metavariable-comparison:
|
|
metavariable: $SIZE
|
|
comparison: $SIZE < 2048
|
|
- id: python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
message: Detected an insufficient key size for RSA. NIST recommends a key size of
|
|
3072 or higher.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
|
|
references:
|
|
- https://www.pycryptodome.org/src/public_key/rsa#rsa
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::key-length::pycryptodome
|
|
- crypto::search::key-length::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
shortlink: https://sg.run/PprY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9689
|
|
rv_id: 1263555
|
|
rule_id: BYUBWe
|
|
version_id: 5PTo1jL
|
|
url: https://semgrep.dev/playground/r/5PTo1jL/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: Crypto.PublicKey.RSA.generate(..., bits=$SIZE, ...)
|
|
- pattern: Crypto.PublicKey.RSA.generate($SIZE, ...)
|
|
- pattern: Cryptodome.PublicKey.RSA.generate(..., bits=$SIZE, ...)
|
|
- pattern: Cryptodome.PublicKey.RSA.generate($SIZE, ...)
|
|
- metavariable-comparison:
|
|
metavariable: $SIZE
|
|
comparison: $SIZE < 3072
|
|
- id: ruby.lang.security.force-ssl-false.force-ssl-false
|
|
message: Checks for configuration setting of force_ssl to false. Force_ssl forces
|
|
usage of HTTPS, which could lead to network interception of unencrypted application
|
|
traffic. To fix, set config.force_ssl = true.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-311: Missing Encryption of Sensitive Data'
|
|
references:
|
|
- https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_force_ssl.rb
|
|
category: security
|
|
technology:
|
|
- ruby
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/ruby.lang.security.force-ssl-false.force-ssl-false
|
|
shortlink: https://sg.run/YgkW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9714
|
|
rv_id: 1263605
|
|
rule_id: 2ZU4lx
|
|
version_id: WrTqKB3
|
|
url: https://semgrep.dev/playground/r/WrTqKB3/ruby.lang.security.force-ssl-false.force-ssl-false
|
|
origin: community
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
pattern: config.force_ssl = false
|
|
fix-regex:
|
|
regex: =\s*false
|
|
replacement: = true
|
|
- id: ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller
|
|
patterns:
|
|
- pattern-inside: |
|
|
class $CONTROLLER < ApplicationController
|
|
...
|
|
http_basic_authenticate_with ..., :password => "$SECRET", ...
|
|
end
|
|
- focus-metavariable: $SECRET
|
|
message: Detected hardcoded password used in basic authentication in a controller
|
|
class. Including this password in version control could expose this credential.
|
|
Consider refactoring to use environment variables or configuration files.
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/basic_auth/index.markdown
|
|
category: security
|
|
technology:
|
|
- ruby
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller
|
|
shortlink: https://sg.run/6r0w
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9715
|
|
rv_id: 1263606
|
|
rule_id: X5UZWK
|
|
version_id: 0bTKzNK
|
|
url: https://semgrep.dev/playground/r/0bTKzNK/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller
|
|
origin: community
|
|
languages:
|
|
- ruby
|
|
- id: yaml.docker-compose.security.privileged-service.privileged-service
|
|
patterns:
|
|
- pattern-inside: |
|
|
version: ...
|
|
...
|
|
services:
|
|
...
|
|
$SERVICE:
|
|
...
|
|
privileged: $TRUE
|
|
- focus-metavariable: $TRUE
|
|
- metavariable-regex:
|
|
metavariable: $TRUE
|
|
regex: (true)
|
|
fix: |
|
|
false
|
|
message: Service '$SERVICE' is running in privileged mode. This grants the container
|
|
the equivalent of root capabilities on the host machine. This can lead to container
|
|
escapes, privilege escalation, and other security concerns. Remove the 'privileged'
|
|
key to disable this capability.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-250: Execution with Unnecessary Privileges'
|
|
owasp:
|
|
- A06:2017 - Security Misconfiguration
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://www.trendmicro.com/en_us/research/19/l/why-running-a-privileged-container-in-docker-is-a-bad-idea.html
|
|
- https://containerjournal.com/topics/container-security/why-running-a-privileged-container-is-not-a-good-idea/
|
|
category: security
|
|
technology:
|
|
- docker-compose
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.docker-compose.security.privileged-service.privileged-service
|
|
shortlink: https://sg.run/AlX0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 10006
|
|
rv_id: 1263922
|
|
rule_id: DbUW17
|
|
version_id: 0bTKzXZ
|
|
url: https://semgrep.dev/playground/r/0bTKzXZ/yaml.docker-compose.security.privileged-service.privileged-service
|
|
origin: community
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
- id: csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization
|
|
severity: WARNING
|
|
languages:
|
|
- C#
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
references:
|
|
- https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide
|
|
category: security
|
|
technology:
|
|
- .net
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization
|
|
shortlink: https://sg.run/ZeXW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 11135
|
|
rv_id: 1262635
|
|
rule_id: bwUOjK
|
|
version_id: nWT2LGp
|
|
url: https://semgrep.dev/playground/r/nWT2LGp/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization
|
|
origin: community
|
|
message: The BinaryFormatter type is dangerous and is not recommended for data processing.
|
|
Applications should stop using BinaryFormatter as soon as possible, even if they
|
|
believe the data they're processing to be trustworthy. BinaryFormatter is insecure
|
|
and can't be made secure
|
|
patterns:
|
|
- pattern-inside: |
|
|
using System.Runtime.Serialization.Formatters.Binary;
|
|
...
|
|
- pattern: |
|
|
new BinaryFormatter();
|
|
- id: java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::randomness::javax.crypto
|
|
cwe:
|
|
- 'CWE-323: Reusing a Nonce, Key Pair in Encryption'
|
|
category: security
|
|
source-rule-url: https://www.youtube.com/watch?v=r1awgAl90wM
|
|
technology:
|
|
- java
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse
|
|
shortlink: https://sg.run/Dww2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 11908
|
|
rv_id: 1263000
|
|
rule_id: GdUZZ3
|
|
version_id: 0bTKzGk
|
|
url: https://semgrep.dev/playground/r/0bTKzGk/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse
|
|
origin: community
|
|
languages:
|
|
- java
|
|
message: 'GCM IV/nonce is reused: encryption can be totally useless'
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: new GCMParameterSpec(..., "...".getBytes(...), ...);
|
|
- pattern: byte[] $NONCE = "...".getBytes(...); ... new GCMParameterSpec(...,
|
|
$NONCE, ...);
|
|
severity: ERROR
|
|
- id: javascript.lang.security.audit.code-string-concat.code-string-concat
|
|
message: Found data from an Express or Next web request flowing to `eval`. If this
|
|
data is user-controllable this can lead to execution of arbitrary system commands
|
|
in the context of your application process. Avoid `eval` whenever possible.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
confidence: HIGH
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
references:
|
|
- https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval
|
|
- https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback
|
|
- https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/
|
|
- https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html
|
|
category: security
|
|
technology:
|
|
- node.js
|
|
- Express
|
|
- Next.js
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat
|
|
shortlink: https://sg.run/96Yk
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13023
|
|
rv_id: 1263192
|
|
rule_id: DbUKEz
|
|
version_id: 44TEjYX
|
|
url: https://semgrep.dev/playground/r/44TEjYX/javascript.lang.security.audit.code-string-concat.code-string-concat
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT)
|
|
{...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import { ...,$IMPORT,... } from 'next/router'
|
|
...
|
|
- pattern-inside: |
|
|
import $IMPORT from 'next/router';
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ROUTER = $IMPORT()
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
const { ...,$PROPS,... } = $ROUTER.query
|
|
...
|
|
- pattern-inside: |
|
|
var { ...,$PROPS,... } = $ROUTER.query
|
|
...
|
|
- pattern-inside: |
|
|
let { ...,$PROPS,... } = $ROUTER.query
|
|
...
|
|
- focus-metavariable: $PROPS
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ROUTER = $IMPORT()
|
|
...
|
|
- pattern: "$ROUTER.query.$VALUE \n"
|
|
- patterns:
|
|
- pattern: $IMPORT().query.$VALUE
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
eval(...)
|
|
- id: yaml.github-actions.security.run-shell-injection.run-shell-injection
|
|
languages:
|
|
- yaml
|
|
message: 'Using variable interpolation `${{...}}` with `github` context data in
|
|
a `run:` step could allow an attacker to inject their own code into the runner.
|
|
This would allow them to steal secrets and code. `github` context data can have
|
|
arbitrary user input and should be treated as untrusted. Instead, use an intermediate
|
|
environment variable with `env:` to store the data and use the environment variable
|
|
in the `run:` script. Be sure to use double-quotes the environment variable, like
|
|
this: "$ENVVAR".'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections
|
|
- https://securitylab.github.com/research/github-actions-untrusted-input/
|
|
technology:
|
|
- github-actions
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.run-shell-injection.run-shell-injection
|
|
shortlink: https://sg.run/pkzk
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13162
|
|
rv_id: 1423395
|
|
rule_id: v8UjQj
|
|
version_id: GxTl1DQ
|
|
url: https://semgrep.dev/playground/r/GxTl1DQ/yaml.github-actions.security.run-shell-injection.run-shell-injection
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: 'steps: [...]'
|
|
- pattern-inside: |
|
|
- run: ...
|
|
...
|
|
- pattern: 'run: $SHELL'
|
|
- metavariable-pattern:
|
|
language: generic
|
|
metavariable: $SHELL
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: ${{ ... github.event.issue.title ... }}
|
|
- pattern: ${{ ... github.event.issue.body ... }}
|
|
- pattern: ${{ ... github.event.pull_request.title ... }}
|
|
- pattern: ${{ ... github.event.pull_request.body ... }}
|
|
- pattern: ${{ ... github.event.comment.body ... }}
|
|
- pattern: ${{ ... github.event.review.body ... }}
|
|
- pattern: ${{ ... github.event.review_comment.body ... }}
|
|
- pattern: ${{ ... github.event.pages ... .page_name ... }}
|
|
- pattern: ${{ ... github.event.head_commit.message ... }}
|
|
- pattern: ${{ ... github.event.head_commit.author.email ... }}
|
|
- pattern: ${{ ... github.event.head_commit.author.name ... }}
|
|
- pattern: ${{ ... github.event.commits ... .author.email ... }}
|
|
- pattern: ${{ ... github.event.commits ... .author.name ... }}
|
|
- pattern: ${{ ... github.event.commits ... .message ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.ref ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.label ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.repo.default_branch ...
|
|
}}
|
|
- pattern: ${{ ... github.ref ... }}
|
|
- pattern: ${{ ... github.base_ref ... }}
|
|
- pattern: ${{ ... github.head_ref ... }}
|
|
- pattern: ${{ ... github.ref_name ... }}
|
|
- pattern: ${{ ... github.workflow ... }}
|
|
- pattern: ${{ ... github.event.inputs ... }}
|
|
- pattern: ${{ ... github.event.discussion.title ... }}
|
|
- pattern: ${{ ... github.event.discussion.body ... }}
|
|
- pattern: ${{ ... github.event.workflow_run.head_branch ... }}
|
|
- pattern: ${{ ... github.event.workflow_run.head_commit.message ... }}
|
|
- pattern: ${{ ... github.event.milestone.title ... }}
|
|
- pattern: ${{ ... github.event.milestone.description ... }}
|
|
- pattern: ${{ ... github.event.project_card.note ... }}
|
|
- pattern: ${{ ... github.event.project.name ... }}
|
|
- pattern: ${{ ... github.event.project_column.name ... }}
|
|
- pattern: ${{ ... github.event.release.name ... }}
|
|
- pattern: ${{ ... github.event.release.body ... }}
|
|
- pattern: ${{ ... github.event.deployment.ref ... }}
|
|
- pattern: ${{ ... inputs ... }}
|
|
- pattern-not: ${{ ... github.event.issue.title && ... }}
|
|
- pattern-not: ${{ ... github.event.issue.body && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.title && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.body && ... }}
|
|
- pattern-not: ${{ ... github.event.comment.body && ... }}
|
|
- pattern-not: ${{ ... github.event.review.body && ... }}
|
|
- pattern-not: ${{ ... github.event.review_comment.body && ... }}
|
|
- pattern-not: ${{ ... github.event.pages ... .page_name && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.message && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.author.email && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.author.name && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .author.email && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .author.name && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .message && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.ref && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.label && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch &&
|
|
... }}
|
|
- pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ...
|
|
}}
|
|
- pattern-not: ${{ ... github.ref && ... }}
|
|
- pattern-not: ${{ ... github.base_ref && ... }}
|
|
- pattern-not: ${{ ... github.head_ref && ... }}
|
|
- pattern-not: ${{ ... github.ref_name && ... }}
|
|
- pattern-not: ${{ ... github.workflow && ... }}
|
|
- pattern-not: ${{ ... github.event.inputs && ... }}
|
|
- pattern-not: ${{ ... github.event.discussion.title && ... }}
|
|
- pattern-not: ${{ ... github.event.discussion.body && ... }}
|
|
- pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }}
|
|
- pattern-not: ${{ ... github.event.milestone.title && ... }}
|
|
- pattern-not: ${{ ... github.event.milestone.description && ... }}
|
|
- pattern-not: ${{ ... github.event.project_card.note && ... }}
|
|
- pattern-not: ${{ ... github.event.project.name && ... }}
|
|
- pattern-not: ${{ ... github.event.project_column.name && ... }}
|
|
- pattern-not: ${{ ... github.event.release.name && ... }}
|
|
- pattern-not: ${{ ... github.event.release.body && ... }}
|
|
- pattern-not: ${{ ... github.event.deployment.ref && ... }}
|
|
severity: ERROR
|
|
- id: yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout
|
|
languages:
|
|
- yaml
|
|
message: This GitHub Actions workflow file uses `pull_request_target` and checks
|
|
out code from the incoming pull request. When using `pull_request_target`, the
|
|
Action runs in the context of the target repository, which includes access to
|
|
all repository secrets. Normally, this is safe because the Action only runs code
|
|
from the target repository, not the incoming PR. However, by checking out the
|
|
incoming PR code, you're now using the incoming code for the rest of the action.
|
|
You may be inadvertently executing arbitrary code from the incoming PR with access
|
|
to repository secrets, which would let an attacker steal repository secrets. This
|
|
normally happens by running build scripts (e.g., `npm build` and `make`) or dependency
|
|
installation scripts (e.g., `python setup.py install`). Audit your workflow file
|
|
to make sure no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
|
|
for additional mitigations.
|
|
metadata:
|
|
category: security
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software and Data Integrity Failures
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
references:
|
|
- https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
|
|
- https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target
|
|
- https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md
|
|
technology:
|
|
- github-actions
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout
|
|
shortlink: https://sg.run/jkdn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13365
|
|
rv_id: 1413423
|
|
rule_id: d8Ulkd
|
|
version_id: O9TQ2nX
|
|
url: https://semgrep.dev/playground/r/O9TQ2nX/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
on:
|
|
...
|
|
pull_request_target: ...
|
|
...
|
|
...
|
|
- pattern-inside: |
|
|
on: [..., pull_request_target, ...]
|
|
...
|
|
- pattern-inside: |
|
|
on: pull_request_target
|
|
...
|
|
- pattern-inside: |
|
|
jobs:
|
|
...
|
|
$JOBNAME:
|
|
...
|
|
steps:
|
|
...
|
|
- pattern: |
|
|
...
|
|
uses: "$ACTION"
|
|
with:
|
|
...
|
|
ref: $EXPR
|
|
- metavariable-regex:
|
|
metavariable: $ACTION
|
|
regex: actions/checkout@.*
|
|
- metavariable-pattern:
|
|
language: generic
|
|
metavariable: $EXPR
|
|
patterns:
|
|
- pattern-inside: ${{ ... }}
|
|
- pattern-either:
|
|
- pattern: github.event.pull_request ...
|
|
- pattern: github.head_ref ...
|
|
severity: ERROR
|
|
- id: go.lang.security.injection.tainted-url-host.tainted-url-host
|
|
languages:
|
|
- go
|
|
message: A request was found to be crafted from user-input `$REQUEST`. This can
|
|
lead to Server-Side Request Forgery (SSRF) vulnerabilities, potentially exposing
|
|
sensitive data. It is recommend where possible to not allow user-input to craft
|
|
the base request, but to be treated as part of the path or query parameter. When
|
|
user-input is necessary to craft the request, it is recommended to follow OWASP
|
|
best practices to prevent abuse, including using an allowlist.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://goteleport.com/blog/ssrf-attacks/
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host
|
|
shortlink: https://sg.run/5DjW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14391
|
|
rv_id: 1262970
|
|
rule_id: AbUQLr
|
|
version_id: yeTxpOj
|
|
url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- label: INPUT
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
($REQUEST : *http.Request).$ANYTHING
|
|
- pattern: |
|
|
($REQUEST : http.Request).$ANYTHING
|
|
- metavariable-regex:
|
|
metavariable: $ANYTHING
|
|
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
|
|
- label: CLEAN
|
|
requires: INPUT
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$URLSTR" + $INPUT
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...)
|
|
- pattern: fmt.Sprintf("$URLSTR", $INPUT, ...)
|
|
- pattern: fmt.Printf("$URLSTR", $INPUT, ...)
|
|
- metavariable-regex:
|
|
metavariable: $URLSTR
|
|
regex: .*//[a-zA-Z0-10]+\..*
|
|
pattern-sinks:
|
|
- requires: INPUT and not CLEAN
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$CLIENT := &http.Client{...}
|
|
...
|
|
- pattern: $CLIENT.$METHOD($URL, ...)
|
|
- pattern: http.$METHOD($URL, ...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(Get|Head|Post|PostForm)$
|
|
- patterns:
|
|
- pattern: |
|
|
http.NewRequest("$METHOD", $URL, ...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(GET|HEAD|POST|POSTFORM)$
|
|
- focus-metavariable: $URL
|
|
severity: WARNING
|
|
- id: go.lang.security.injection.tainted-sql-string.tainted-sql-string
|
|
languages:
|
|
- go
|
|
message: User data flows into this manually-constructed SQL string. User data can
|
|
be safely inserted into SQL strings using prepared statements or an object-relational
|
|
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
|
|
injection, which could let an attacker steal or manipulate data from the database.
|
|
Instead, use prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`)
|
|
or a safe library.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://golang.org/doc/database/sql-injection
|
|
- https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string
|
|
shortlink: https://sg.run/PbEq
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14689
|
|
rv_id: 1409388
|
|
rule_id: PeUoqy
|
|
version_id: nWTQ5qD
|
|
url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string
|
|
origin: community
|
|
mode: taint
|
|
severity: ERROR
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
($REQUEST : *http.Request).$ANYTHING
|
|
- pattern: |
|
|
($REQUEST : http.Request).$ANYTHING
|
|
- metavariable-regex:
|
|
metavariable: $ANYTHING
|
|
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$SQLSTR" + ...
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VAR = "$SQLSTR";
|
|
...
|
|
- pattern: $VAR += ...
|
|
- patterns:
|
|
- pattern-inside: |
|
|
var $SB strings.Builder
|
|
...
|
|
- pattern-inside: |
|
|
$SB.WriteString("$SQLSTR")
|
|
...
|
|
$SB.String(...)
|
|
- pattern: |
|
|
$SB.WriteString(...)
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(select|delete|insert|create|update|alter|drop).*
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: fmt.Fprintf($F, "$SQLSTR", ...)
|
|
- pattern: fmt.Sprintf("$SQLSTR", ...)
|
|
- pattern: fmt.Printf("$SQLSTR", ...)
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).*
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: strconv.Atoi(...)
|
|
- pattern: |
|
|
($X: bool)
|
|
- id: scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret
|
|
languages:
|
|
- scala
|
|
message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently
|
|
Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html
|
|
Consider using an appropriate security mechanism to protect the credentials (e.g.
|
|
keeping secrets in environment variables)'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
technology:
|
|
- jwt
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret
|
|
shortlink: https://sg.run/Z40o
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15079
|
|
rv_id: 1263691
|
|
rule_id: OrU6W1
|
|
version_id: 7ZTE3kr
|
|
url: https://semgrep.dev/playground/r/7ZTE3kr/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: |
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC256("...");
|
|
- pattern: |
|
|
$SECRET = "...";
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET);
|
|
- pattern: |
|
|
class $CLASS {
|
|
...
|
|
$DECL $SECRET = "...";
|
|
...
|
|
def $FUNC (...): $RETURNTYPE = {
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: |
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC384("...");
|
|
- pattern: |
|
|
$SECRET = "...";
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET);
|
|
- pattern: |
|
|
class $CLASS {
|
|
...
|
|
$DECL $SECRET = "...";
|
|
...
|
|
def $FUNC (...): $RETURNTYPE = {
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: |
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC512("...");
|
|
- pattern: |
|
|
$SECRET = "...";
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET);
|
|
- pattern: |
|
|
class $CLASS {
|
|
...
|
|
$DECL $SECRET = "...";
|
|
...
|
|
def $FUNC (...): $RETURNTYPE = {
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
severity: ERROR
|
|
- id: terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy
|
|
message: Detected an AppService that was not configured to use TLS 1.2. Add `site_config.min_tls_version
|
|
= "1.2"` in your resource block.
|
|
patterns:
|
|
- pattern: min_tls_version = $ANYTHING
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "$NAME" {
|
|
...
|
|
}
|
|
- pattern-not-inside: min_tls_version = "1.2"
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#min_tls_version
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy
|
|
shortlink: https://sg.run/AXRp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15106
|
|
rv_id: 1263759
|
|
rule_id: YGUDbZ
|
|
version_id: RGT0L4x
|
|
url: https://semgrep.dev/playground/r/RGT0L4x/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: kotlin.lang.security.weak-rsa.use-of-weak-rsa-key
|
|
message: RSA keys should be at least 2048 bits based on NIST recommendation.
|
|
languages:
|
|
- kt
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
|
|
category: security
|
|
technology:
|
|
- kotlin
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key
|
|
shortlink: https://sg.run/krq7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15128
|
|
rv_id: 1263269
|
|
rule_id: nJUZNL
|
|
version_id: X0TzypE
|
|
url: https://semgrep.dev/playground/r/X0TzypE/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$KEY = $G.getInstance("RSA")
|
|
...
|
|
$KEY.initialize($BITS)
|
|
- metavariable-comparison:
|
|
metavariable: $BITS
|
|
comparison: $BITS < 2048
|
|
- id: scala.lang.security.audit.rsa-padding-set.rsa-padding-set
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-780: Use of RSA Algorithm without OAEP'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- scala
|
|
- cryptography
|
|
resources:
|
|
- https://blog.codacy.com/9-scala-security-issues/
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/scala.lang.security.audit.rsa-padding-set.rsa-padding-set
|
|
shortlink: https://sg.run/GO5p
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15192
|
|
rv_id: 1263677
|
|
rule_id: 3qUj1Q
|
|
version_id: yeTxpoX
|
|
url: https://semgrep.dev/playground/r/yeTxpoX/scala.lang.security.audit.rsa-padding-set.rsa-padding-set
|
|
origin: community
|
|
message: Usage of RSA without OAEP (Optimal Asymmetric Encryption Padding) may weaken
|
|
encryption. This could lead to sensitive data exposure. Instead, use RSA with
|
|
`OAEPWithMD5AndMGF1Padding` instead.
|
|
severity: WARNING
|
|
languages:
|
|
- scala
|
|
patterns:
|
|
- pattern: |
|
|
$VAR = $CIPHER.getInstance($MODE)
|
|
- metavariable-regex:
|
|
metavariable: $MODE
|
|
regex: .*RSA/.*/NoPadding.*
|
|
- id: generic.ci.security.bash-reverse-shell.bash_reverse_shell
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
category: security
|
|
technology:
|
|
- ci
|
|
confidence: HIGH
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/generic.ci.security.bash-reverse-shell.bash_reverse_shell
|
|
shortlink: https://sg.run/4l9l
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 16200
|
|
rv_id: 1262664
|
|
rule_id: gxUJrJ
|
|
version_id: jQTn5QE
|
|
url: https://semgrep.dev/playground/r/jQTn5QE/generic.ci.security.bash-reverse-shell.bash_reverse_shell
|
|
origin: community
|
|
message: Semgrep found a bash reverse shell
|
|
severity: ERROR
|
|
languages:
|
|
- generic
|
|
pattern-either:
|
|
- pattern: |
|
|
sh -i >& /dev/udp/.../... 0>&1
|
|
- pattern: |
|
|
<...>/dev/tcp/.../...; sh <&... >&... 2>&
|
|
- pattern: |
|
|
<...>/dev/tcp/.../...; cat <&... | while read line; do $line 2>&... >&...;done
|
|
- pattern: |
|
|
sh -i ...<...> /dev/tcp/.../... ...<&... 1>&... 2>&
|
|
- id: java.lang.security.audit.crypto.use-of-md5.use-of-md5
|
|
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use HMAC
|
|
instead.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::java.security
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5.use-of-md5
|
|
shortlink: https://sg.run/ryJn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17325
|
|
rv_id: 1263013
|
|
rule_id: KxU5lW
|
|
version_id: 0bTKzGX
|
|
url: https://semgrep.dev/playground/r/0bTKzGX/java.lang.security.audit.crypto.use-of-md5.use-of-md5
|
|
origin: community
|
|
patterns:
|
|
- pattern: |
|
|
java.security.MessageDigest.getInstance($ALGO, ...);
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: (?i)(.MD5.)
|
|
- focus-metavariable: $ALGO
|
|
fix: |
|
|
"SHA-512"
|
|
- id: java.lang.security.audit.crypto.use-of-sha1.use-of-sha1
|
|
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
|
|
collision resistant and is therefore not suitable as a cryptographic signature.
|
|
Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function
|
|
applications.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::javax.crypto
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1
|
|
shortlink: https://sg.run/bXNp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17326
|
|
rv_id: 1263016
|
|
rule_id: qNUWNn
|
|
version_id: l4TJRpL
|
|
url: https://semgrep.dev/playground/r/l4TJRpL/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1
|
|
origin: community
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
java.security.MessageDigest.getInstance("$ALGO", ...);
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: (SHA1|SHA-1)
|
|
- pattern: |
|
|
$DU.getSha1Digest().digest(...)
|
|
- id: java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
message: Detected input from a HTTPServletRequest going into a SQL sink or statement.
|
|
This could lead to SQL injection if variables in the SQL statement are not properly
|
|
sanitized. Use parameterized SQL queries or properly sanitize user input instead.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
category: security
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
cwe2021-top25: true
|
|
cwe2022-top25: true
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
|
|
- https://owasp.org/www-community/attacks/SQL_Injection
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- sql
|
|
- java
|
|
- servlets
|
|
- spring
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
shortlink: https://sg.run/Lg56
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18239
|
|
rv_id: 1409390
|
|
rule_id: oqUBJG
|
|
version_id: 7ZTKJNj
|
|
url: https://semgrep.dev/playground/r/7ZTKJNj/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
origin: community
|
|
languages:
|
|
- java
|
|
mode: taint
|
|
options:
|
|
taint_assume_safe_numbers: true
|
|
taint_assume_safe_booleans: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(HttpServletRequest $REQ).$REQFUNC(...)
|
|
- pattern: "(ServletRequest $REQ).$REQFUNC(...) \n"
|
|
- metavariable-regex:
|
|
metavariable: $REQFUNC
|
|
regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: "(java.sql.CallableStatement $STMT) = ...; \n"
|
|
- pattern: |
|
|
(java.sql.Statement $STMT) = ...;
|
|
...
|
|
$OUTPUT = $STMT.$FUNC(...);
|
|
- pattern: |
|
|
(java.sql.PreparedStatement $STMT) = ...;
|
|
- pattern: |
|
|
$VAR = $CONN.prepareStatement(...)
|
|
- pattern: |
|
|
$PATH.queryForObject(...);
|
|
- pattern: |
|
|
(java.util.Map<String, Object> $STMT) = $PATH.queryForMap(...);
|
|
- pattern: |
|
|
(org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...;
|
|
- pattern: |
|
|
(org.springframework.jdbc.core.JdbcTemplate $TEMPL).batchUpdate(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
(String $SQL) = "$SQLSTR" + ...;
|
|
...
|
|
- pattern: $PATH.$SQLCMD(..., $SQL, ...);
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*)
|
|
- metavariable-regex:
|
|
metavariable: $SQLCMD
|
|
regex: (execute|query|executeUpdate|batchUpdate)
|
|
- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
- https://xerces.apache.org/xerces2-j/features.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false
|
|
shortlink: https://sg.run/4Dv5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18244
|
|
rv_id: 1263057
|
|
rule_id: j2UrJ8
|
|
version_id: 0bTKzgX
|
|
url: https://semgrep.dev/playground/r/0bTKzgX/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false
|
|
origin: community
|
|
message: DOCTYPE declarations are enabled for $DBFACTORY. Without prohibiting external
|
|
entity declarations, this is vulnerable to XML external entity attacks. Disable
|
|
this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl"
|
|
to true. Alternatively, allow DOCTYPE declarations and only prohibit external
|
|
entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities"
|
|
and "http://xml.org/sax/features/external-parameter-entities" to false.
|
|
patterns:
|
|
- pattern: $DBFACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl",
|
|
false);
|
|
- pattern-not-inside: |
|
|
$RETURNTYPE $METHOD(...){
|
|
...
|
|
$DBF.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
$RETURNTYPE $METHOD(...){
|
|
...
|
|
$DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$DBF.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
$RETURNTYPE $METHOD(...){
|
|
...
|
|
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, "");
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
$RETURNTYPE $METHOD(...){
|
|
...
|
|
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, "");
|
|
...
|
|
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
}
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
- https://xerces.apache.org/xerces2-j/features.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing
|
|
shortlink: https://sg.run/PYBz
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18245
|
|
rv_id: 1263058
|
|
rule_id: 10UPQB
|
|
version_id: K3TKk80
|
|
url: https://semgrep.dev/playground/r/K3TKk80/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing
|
|
origin: community
|
|
message: DOCTYPE declarations are enabled for this DocumentBuilderFactory. This
|
|
is vulnerable to XML external entity attacks. Disable this by setting the feature
|
|
"http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively,
|
|
allow DOCTYPE declarations and only prohibit external entities declarations. This
|
|
can be done by setting the features "http://xml.org/sax/features/external-general-entities"
|
|
and "http://xml.org/sax/features/external-parameter-entities" to false.
|
|
mode: taint
|
|
pattern-sources:
|
|
- by-side-effect: true
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY = DocumentBuilderFactory.newInstance();
|
|
- patterns:
|
|
- pattern: $FACTORY
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = DocumentBuilderFactory.newInstance();
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = DocumentBuilderFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = DocumentBuilderFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = DocumentBuilderFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $FACTORY.newDocumentBuilder();
|
|
pattern-sanitizers:
|
|
- by-side-effect: true
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
- focus-metavariable: $FACTORY
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl",
|
|
true);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: $M($X)
|
|
- focus-metavariable: $X
|
|
fix: |
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
$FACTORY.newDocumentBuilder();
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true
|
|
shortlink: https://sg.run/JgPy
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18246
|
|
rv_id: 1263059
|
|
rule_id: 9AUJ6r
|
|
version_id: qkTR7Lk
|
|
url: https://semgrep.dev/playground/r/qkTR7Lk/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true
|
|
origin: community
|
|
message: External entities are allowed for $DBFACTORY. This is vulnerable to XML
|
|
external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-general-entities"
|
|
to false.
|
|
pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities",
|
|
true);
|
|
fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities",
|
|
false);
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true
|
|
shortlink: https://sg.run/5Lv0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18247
|
|
rv_id: 1263060
|
|
rule_id: yyUNeo
|
|
version_id: l4TJRoL
|
|
url: https://semgrep.dev/playground/r/l4TJRoL/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true
|
|
origin: community
|
|
message: External entities are allowed for $DBFACTORY. This is vulnerable to XML
|
|
external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-parameter-entities"
|
|
to false.
|
|
pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities",
|
|
true);
|
|
fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities",
|
|
false);
|
|
languages:
|
|
- java
|
|
- id: scala.play.security.tainted-slick-sqli.tainted-slick-sqli
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://scala-slick.org/doc/3.3.3/sql.html#splicing-literal-values
|
|
- https://scala-slick.org/doc/3.2.0/sql-to-slick.html#non-optimal-sql-code
|
|
category: security
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
technology:
|
|
- scala
|
|
- slick
|
|
- play
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/scala.play.security.tainted-slick-sqli.tainted-slick-sqli
|
|
shortlink: https://sg.run/k9K2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18328
|
|
rv_id: 1263687
|
|
rule_id: GdUDWO
|
|
version_id: d6TyxJe
|
|
url: https://semgrep.dev/playground/r/d6TyxJe/scala.play.security.tainted-slick-sqli.tainted-slick-sqli
|
|
origin: community
|
|
message: Detected a tainted SQL statement. This could lead to SQL injection if variables
|
|
in the SQL statement are not properly sanitized. Avoid using using user input
|
|
for generating SQL strings.
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: $REQ
|
|
- pattern-either:
|
|
- pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- patterns:
|
|
- pattern: $PARAM
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) {
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $MODEL.overrideSql(...)
|
|
- pattern: sql"..."
|
|
- pattern-inside: |
|
|
import slick.$DEPS
|
|
...
|
|
severity: ERROR
|
|
languages:
|
|
- scala
|
|
- id: php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: openssl_encrypt($D, $M, $K, $FLAGS, "...",...);
|
|
- pattern: openssl_decrypt($D, $M, $K, $FLAGS, "...",...);
|
|
- metavariable-comparison:
|
|
metavariable: $M
|
|
comparison: re.match(".*-CBC",$M)
|
|
message: Static IV used with AES in CBC mode. Static IVs enable chosen-plaintext
|
|
attacks against encrypted data.
|
|
languages:
|
|
- php
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-329: Generation of Predictable IV with CBC Mode'
|
|
references:
|
|
- https://csrc.nist.gov/publications/detail/sp/800-38a/final
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
technology:
|
|
- php
|
|
- openssl
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv
|
|
shortlink: https://sg.run/LgWJ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19039
|
|
rv_id: 1263295
|
|
rule_id: DbUGbE
|
|
version_id: JdTzxOD
|
|
url: https://semgrep.dev/playground/r/JdTzxOD/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv
|
|
origin: community
|
|
- id: scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode
|
|
patterns:
|
|
- pattern-inside: |
|
|
import pdi.jwt.$DEPS
|
|
...
|
|
- pattern-either:
|
|
- pattern: $JWT.encode($X, "...", ...)
|
|
- pattern: $JWT.decode($X, "...", ...)
|
|
- pattern: $JWT.decodeRawAll($X, "...", ...)
|
|
- pattern: $JWT.decodeRaw($X, "...", ...)
|
|
- pattern: $JWT.decodeAll($X, "...", ...)
|
|
- pattern: $JWT.validate($X, "...", ...)
|
|
- pattern: $JWT.isValid($X, "...", ...)
|
|
- pattern: $JWT.decodeJson($X, "...", ...)
|
|
- pattern: $JWT.decodeJsonAll($X, "...", ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $JWT.encode($X, $KEY, ...)
|
|
- pattern: $JWT.decode($X, $KEY, ...)
|
|
- pattern: $JWT.decodeRawAll($X, $KEY, ...)
|
|
- pattern: $JWT.decodeRaw($X, $KEY, ...)
|
|
- pattern: $JWT.decodeAll($X, $KEY, ...)
|
|
- pattern: $JWT.validate($X, $KEY, ...)
|
|
- pattern: $JWT.isValid($X, $KEY, ...)
|
|
- pattern: $JWT.decodeJson($X, $KEY, ...)
|
|
- pattern: $JWT.decodeJsonAll($X, $KEY, ...)
|
|
- pattern: $JWT.encode($X, this.$KEY, ...)
|
|
- pattern: $JWT.decode($X, this.$KEY, ...)
|
|
- pattern: $JWT.decodeRawAll($X, this.$KEY, ...)
|
|
- pattern: $JWT.decodeRaw($X, this.$KEY, ...)
|
|
- pattern: $JWT.decodeAll($X, this.$KEY, ...)
|
|
- pattern: $JWT.validate($X, this.$KEY, ...)
|
|
- pattern: $JWT.isValid($X, this.$KEY, ...)
|
|
- pattern: $JWT.decodeJson($X, this.$KEY, ...)
|
|
- pattern: $JWT.decodeJsonAll($X, this.$KEY, ...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $CL {
|
|
...
|
|
$KEY = "..."
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
object $CL {
|
|
...
|
|
$KEY = "..."
|
|
...
|
|
}
|
|
- metavariable-pattern:
|
|
metavariable: $JWT
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: Jwt
|
|
- pattern: JwtArgonaut
|
|
- pattern: JwtCirce
|
|
- pattern: JwtJson4s
|
|
- pattern: JwtJson
|
|
- pattern: JwtUpickle
|
|
message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently
|
|
Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html
|
|
Consider using an appropriate security mechanism to protect the credentials (e.g.
|
|
keeping secrets in environment variables)'
|
|
languages:
|
|
- scala
|
|
severity: WARNING
|
|
metadata:
|
|
references:
|
|
- https://jwt-scala.github.io/jwt-scala/
|
|
category: security
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
technology:
|
|
- scala
|
|
confidence: HIGH
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode
|
|
shortlink: https://sg.run/8zE7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19040
|
|
rv_id: 1263669
|
|
rule_id: WAUdK0
|
|
version_id: o5TbDA8
|
|
url: https://semgrep.dev/playground/r/o5TbDA8/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode
|
|
origin: community
|
|
- id: scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$DF = DocumentBuilderFactory.newInstance(...)
|
|
...
|
|
$DB = $DF.newDocumentBuilder(...)
|
|
- patterns:
|
|
- pattern: $DB = DocumentBuilderFactory.newInstance(...)
|
|
- pattern-not-inside: |
|
|
...
|
|
$X = $DB.newDocumentBuilder(...)
|
|
- pattern: $DB = DocumentBuilderFactory.newInstance(...).newDocumentBuilder(...)
|
|
- pattern-not-inside: |
|
|
...
|
|
$DB.setXIncludeAware(true)
|
|
...
|
|
$DB.setNamespaceAware(true)
|
|
...
|
|
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$DB.setXIncludeAware(true)
|
|
...
|
|
$DB.setNamespaceAware(true)
|
|
...
|
|
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$DB.setXIncludeAware(true)
|
|
...
|
|
$DB.setNamespaceAware(true)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$DB.setXIncludeAware(true)
|
|
...
|
|
$DB.setNamespaceAware(true)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
...
|
|
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
message: Document Builder being instantiated without calling the `setFeature` functions
|
|
that are generally used for disabling entity processing. User controlled data
|
|
in XML Document builder can result in XML Internal Entity Processing vulnerabilities
|
|
like the disclosure of confidential data, denial of service, Server Side Request
|
|
Forgery (SSRF), port scanning. Make sure to disable entity processing functionality.
|
|
languages:
|
|
- scala
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
technology:
|
|
- scala
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled
|
|
shortlink: https://sg.run/gRQn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19041
|
|
rv_id: 1263673
|
|
rule_id: 0oUwzP
|
|
version_id: X0TzyRq
|
|
url: https://semgrep.dev/playground/r/X0TzyRq/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled
|
|
origin: community
|
|
- id: scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: $SR = new SAXReader(...)
|
|
- pattern: |
|
|
$SF = SAXParserFactory.newInstance(...)
|
|
...
|
|
$SR = $SF.newSAXParser(...)
|
|
- patterns:
|
|
- pattern: $SR = SAXParserFactory.newInstance(...)
|
|
- pattern-not-inside: |
|
|
...
|
|
$X = $SR.newSAXParser(...)
|
|
- pattern: $SR = SAXParserFactory.newInstance(...).newSAXParser(...)
|
|
- pattern: $SR = new SAXBuilder(...)
|
|
- pattern-not-inside: |
|
|
...
|
|
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
...
|
|
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
message: XML processor being instantiated without calling the `setFeature` functions
|
|
that are generally used for disabling entity processing. User controlled data
|
|
in XML Parsers can result in XML Internal Entity Processing vulnerabilities like
|
|
the disclosure of confidential data, denial of service, Server Side Request Forgery
|
|
(SSRF), port scanning. Make sure to disable entity processing functionality.
|
|
languages:
|
|
- scala
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
technology:
|
|
- scala
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled
|
|
shortlink: https://sg.run/QbYP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19042
|
|
rv_id: 1263678
|
|
rule_id: KxUrkq
|
|
version_id: rxTAKWY
|
|
url: https://semgrep.dev/playground/r/rxTAKWY/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled
|
|
origin: community
|
|
- id: scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
...
|
|
$XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false)
|
|
- pattern-either:
|
|
- pattern: $XMLFACTORY = XMLInputFactory.newFactory(...)
|
|
- pattern: $XMLFACTORY = XMLInputFactory.newInstance(...)
|
|
- pattern: $XMLFACTORY = new XMLInputFactory(...)
|
|
message: XMLInputFactory being instantiated without calling the setProperty functions
|
|
that are generally used for disabling entity processing. User controlled data
|
|
in XML Document builder can result in XML Internal Entity Processing vulnerabilities
|
|
like the disclosure of confidential data, denial of service, Server Side Request
|
|
Forgery (SSRF), port scanning. Make sure to disable entity processing functionality.
|
|
languages:
|
|
- scala
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
technology:
|
|
- scala
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled
|
|
shortlink: https://sg.run/3BEb
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19043
|
|
rv_id: 1263683
|
|
rule_id: qNUQ7w
|
|
version_id: xyTjzkA
|
|
url: https://semgrep.dev/playground/r/xyTjzkA/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled
|
|
origin: community
|
|
- id: terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version
|
|
pattern: |
|
|
resource "aws_elasticsearch_domain" $ANYTHING {
|
|
...
|
|
domain_endpoint_options {
|
|
...
|
|
enforce_https = true
|
|
tls_security_policy = "Policy-Min-TLS-1-0-2019-07"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
message: Detected an AWS Elasticsearch domain using an insecure version of TLS.
|
|
To fix this, set "tls_security_policy" equal to "Policy-Min-TLS-1-2-2019-07".
|
|
languages:
|
|
- terraform
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version
|
|
shortlink: https://sg.run/PYlq
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19045
|
|
rv_id: 1263718
|
|
rule_id: YGUle7
|
|
version_id: DkTRbA5
|
|
url: https://semgrep.dev/playground/r/DkTRbA5/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version
|
|
origin: community
|
|
- id: scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
languages:
|
|
- scala
|
|
severity: ERROR
|
|
mode: taint
|
|
message: User data flows into this manually-constructed SQL string. User data can
|
|
be safely inserted into SQL strings using prepared statements or an object-relational
|
|
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
|
|
injection, which could let an attacker steal or manipulate data from the database.
|
|
Instead, use prepared statements (`connection.PreparedStatement`) or a safe library.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html
|
|
category: security
|
|
technology:
|
|
- scala
|
|
- play
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
shortlink: https://sg.run/BeW9
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20051
|
|
rv_id: 1263688
|
|
rule_id: 0oUpon
|
|
version_id: ZRTKAoG
|
|
url: https://semgrep.dev/playground/r/ZRTKAoG/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
origin: community
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: $REQ
|
|
- pattern-either:
|
|
- pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- patterns:
|
|
- pattern: $PARAM
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) {
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$SQLSTR" + ...
|
|
- pattern: |
|
|
"$SQLSTR".format(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$SB = new StringBuilder("$SQLSTR");
|
|
...
|
|
- pattern: $SB.append(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VAR = "$SQLSTR"
|
|
...
|
|
- pattern: $VAR += ...
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(select|delete|insert|create|update|alter|drop)\b
|
|
- patterns:
|
|
- pattern: s"..."
|
|
- pattern-regex: |
|
|
.*\b(?i)(select|delete|insert|create|update|alter|drop)\b.*
|
|
- pattern-not-inside: println(...)
|
|
- id: ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase
|
|
message: Found the use of an hardcoded passphrase for RSA. The passphrase can be
|
|
easily discovered, and therefore should not be stored in source-code. It is recommended
|
|
to remove the passphrase from source-code, and use system environment variables
|
|
or a restricted configuration file.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
metadata:
|
|
technology:
|
|
- ruby
|
|
- secrets
|
|
category: security
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/522.html
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase
|
|
shortlink: https://sg.run/xPEe
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20730
|
|
rv_id: 1263607
|
|
rule_id: bwULyN
|
|
version_id: K3TKkEo
|
|
url: https://semgrep.dev/playground/r/K3TKkEo/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: OpenSSL::PKey::RSA.new(..., '...')
|
|
- pattern: OpenSSL::PKey::RSA.new(...).to_pem(..., '...')
|
|
- pattern: OpenSSL::PKey::RSA.new(...).export(..., '...')
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$OPENSSL = OpenSSL::PKey::RSA.new(...)
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
$OPENSSL.export(...,'...')
|
|
- pattern: |
|
|
$OPENSSL.to_pem(...,'...')
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ASSIGN = '...'
|
|
...
|
|
- pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $METHOD1(...)
|
|
...
|
|
$ASSIGN = '...'
|
|
...
|
|
end
|
|
...
|
|
def $METHOD2(...)
|
|
...
|
|
end
|
|
- pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ASSIGN = '...'
|
|
...
|
|
def $METHOD(...)
|
|
$OPENSSL = OpenSSL::PKey::RSA.new(...)
|
|
...
|
|
end
|
|
...
|
|
- pattern-either:
|
|
- pattern: $OPENSSL.export(...,$ASSIGN)
|
|
- pattern: $OPENSSL.to_pem(...,$ASSIGN)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $METHOD1(...)
|
|
...
|
|
$OPENSSL = OpenSSL::PKey::RSA.new(...)
|
|
...
|
|
$ASSIGN = '...'
|
|
...
|
|
end
|
|
...
|
|
- pattern-either:
|
|
- pattern: $OPENSSL.export(...,$ASSIGN)
|
|
- pattern: $OPENSSL.to_pem(...,$ASSIGN)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $METHOD1(...)
|
|
...
|
|
$ASSIGN = '...'
|
|
...
|
|
end
|
|
...
|
|
def $METHOD2(...)
|
|
...
|
|
$OPENSSL = OpenSSL::PKey::RSA.new(...)
|
|
...
|
|
end
|
|
...
|
|
- pattern-either:
|
|
- pattern: $OPENSSL.export(...,$ASSIGN)
|
|
- pattern: $OPENSSL.to_pem(...,$ASSIGN)
|
|
- id: ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
message: The RSA key size $SIZE is insufficent by NIST standards. It is recommended
|
|
to use a key length of 2048 or higher.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
metadata:
|
|
technology:
|
|
- ruby
|
|
category: security
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
shortlink: https://sg.run/O4Re
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20731
|
|
rv_id: 1263608
|
|
rule_id: NbUe4N
|
|
version_id: qkTR76v
|
|
url: https://semgrep.dev/playground/r/qkTR76v/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: OpenSSL::PKey::RSA.generate($SIZE,...)
|
|
- pattern: OpenSSL::PKey::RSA.new($SIZE, ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ASSIGN = $SIZE
|
|
...
|
|
- pattern-either:
|
|
- pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...)
|
|
- pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $METHOD1(...)
|
|
...
|
|
$ASSIGN = $SIZE
|
|
...
|
|
end
|
|
...
|
|
- pattern-either:
|
|
- pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...)
|
|
- pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...)
|
|
- metavariable-comparison:
|
|
metavariable: $SIZE
|
|
comparison: $SIZE < 2048
|
|
- id: java.spring.security.injection.tainted-file-path.tainted-file-path
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
message: Detected user input controlling a file path. An attacker could control
|
|
the location of this file, to include going backwards in the directory with '../'.
|
|
To address this, ensure that user-controlled variables in file paths are sanitized.
|
|
You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...)
|
|
to only retrieve the file name from the path.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-23: Relative Path Traversal'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Path_Traversal
|
|
category: security
|
|
technology:
|
|
- java
|
|
- spring
|
|
subcategory:
|
|
- vuln
|
|
impact: HIGH
|
|
likelihood: MEDIUM
|
|
confidence: HIGH
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/java.spring.security.injection.tainted-file-path.tainted-file-path
|
|
shortlink: https://sg.run/x9o0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22074
|
|
rv_id: 1263084
|
|
rule_id: lBUxok
|
|
version_id: ExTEx6Y
|
|
url: https://semgrep.dev/playground/r/ExTEx6Y/java.spring.security.injection.tainted-file-path.tainted-file-path
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $TYPE
|
|
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
|
|
- metavariable-regex:
|
|
metavariable: $REQ
|
|
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute)
|
|
- focus-metavariable: $SOURCE
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: new File(...)
|
|
- pattern: new java.io.File(...)
|
|
- pattern: new FileReader(...)
|
|
- pattern: new java.io.FileReader(...)
|
|
- pattern: new FileInputStream(...)
|
|
- pattern: new java.io.FileInputStream(...)
|
|
- pattern: (Paths $PATHS).get(...)
|
|
- patterns:
|
|
- pattern: |
|
|
$CLASS.$FUNC(...)
|
|
- metavariable-regex:
|
|
metavariable: $FUNC
|
|
regex: ^(getResourceAsStream|getResource)$
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: new ClassPathResource($FILE, ...)
|
|
- pattern: ResourceUtils.getFile($FILE, ...)
|
|
- pattern: new FileOutputStream($FILE, ...)
|
|
- pattern: new java.io.FileOutputStream($FILE, ...)
|
|
- pattern: new StreamSource($FILE, ...)
|
|
- pattern: new javax.xml.transform.StreamSource($FILE, ...)
|
|
- pattern: FileUtils.openOutputStream($FILE, ...)
|
|
- focus-metavariable: $FILE
|
|
pattern-sanitizers:
|
|
- pattern: org.apache.commons.io.FilenameUtils.getName(...)
|
|
- id: java.spring.security.injection.tainted-system-command.tainted-system-command
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-propagators:
|
|
- pattern: (StringBuilder $STRB).append($INPUT)
|
|
from: $INPUT
|
|
to: $STRB
|
|
label: CONCAT
|
|
requires: INPUT
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $TYPE
|
|
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
|
|
- metavariable-regex:
|
|
metavariable: $REQ
|
|
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute)
|
|
- focus-metavariable: $SOURCE
|
|
label: INPUT
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $X + $SOURCE
|
|
- pattern: $SOURCE + $Y
|
|
- pattern: String.format("...", ..., $SOURCE, ...)
|
|
- pattern: String.join("...", ..., $SOURCE, ...)
|
|
- pattern: (String $STR).concat($SOURCE)
|
|
- pattern: $SOURCE.concat(...)
|
|
- pattern: $X += $SOURCE
|
|
- pattern: $SOURCE += $X
|
|
label: CONCAT
|
|
requires: INPUT
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(Process $P) = new Process(...);
|
|
- pattern: |
|
|
(ProcessBuilder $PB).command(...);
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(Runtime $R).$EXEC(...);
|
|
- pattern: |
|
|
Runtime.getRuntime(...).$EXEC(...);
|
|
- metavariable-regex:
|
|
metavariable: $EXEC
|
|
regex: (exec|loadLibrary|load)
|
|
- patterns:
|
|
- pattern: |
|
|
(ProcessBuilder $PB).command(...).$ADD(...);
|
|
- metavariable-regex:
|
|
metavariable: $ADD
|
|
regex: (add|addAll)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$BUILDER = new ProcessBuilder(...);
|
|
...
|
|
- pattern: $BUILDER.start(...)
|
|
- pattern: |
|
|
new ProcessBuilder(...). ... .start(...);
|
|
requires: CONCAT
|
|
message: 'Detected user input entering a method which executes a system command.
|
|
This could result in a command injection vulnerability, which allows an attacker
|
|
to inject an arbitrary system command onto the server. The attacker could download
|
|
malware onto or steal data from the server. Instead, use ProcessBuilder, separating
|
|
the command into individual arguments, like this: `new ProcessBuilder("ls", "-al",
|
|
targetDirectory)`. Further, make sure you hardcode or allowlist the actual command
|
|
so that attackers can''t run arbitrary commands.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- java
|
|
- spring
|
|
confidence: HIGH
|
|
references:
|
|
- https://www.stackhawk.com/blog/command-injection-java/
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html
|
|
- https://github.com/github/codeql/blob/main/java/ql/src/Security/CWE/CWE-078/ExecUnescaped.java
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/java.spring.security.injection.tainted-system-command.tainted-system-command
|
|
shortlink: https://sg.run/epY0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22076
|
|
rv_id: 1263087
|
|
rule_id: 6JUxGN
|
|
version_id: 8KT5rnP
|
|
url: https://semgrep.dev/playground/r/8KT5rnP/java.spring.security.injection.tainted-system-command.tainted-system-command
|
|
origin: community
|
|
- id: javascript.express.security.audit.express-libxml-noent.express-libxml-noent
|
|
message: The libxml library processes user-input with the `noent` attribute is set
|
|
to `true` which can lead to being vulnerable to XML External Entities (XXE) type
|
|
attacks. It is recommended to set `noent` to `false` when using this feature to
|
|
ensure you are protected.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
|
|
technology:
|
|
- express
|
|
category: security
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-noent.express-libxml-noent
|
|
shortlink: https://sg.run/Z75x
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22079
|
|
rv_id: 1263138
|
|
rule_id: pKUNeD
|
|
version_id: d6TyxpX
|
|
url: https://semgrep.dev/playground/r/d6TyxpX/javascript.express.security.audit.express-libxml-noent.express-libxml-noent
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
|
|
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
- pattern: files.$ANYTHING.data.toString('utf8')
|
|
- pattern: files.$ANYTHING['data'].toString('utf8')
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$XML = require('$IMPORT')
|
|
...
|
|
- pattern-inside: |
|
|
import $XML from '$IMPORT'
|
|
...
|
|
- pattern-inside: |
|
|
import * as $XML from '$IMPORT'
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $IMPORT
|
|
regex: ^(libxmljs|libxmljs2)$
|
|
- pattern-inside: $XML.$FUNC($QUERY, {...,noent:true,...})
|
|
- metavariable-regex:
|
|
metavariable: $FUNC
|
|
regex: ^(parseXmlString|parseXml)$
|
|
- focus-metavariable: $QUERY
|
|
- id: javascript.express.security.audit.express-open-redirect.express-open-redirect
|
|
message: The application redirects to a URL specified by user-supplied input `$REQ`
|
|
that is not validated. This could redirect users to malicious locations. Consider
|
|
using an allow-list approach to validate URLs, or warn users they are being redirected
|
|
to a third-party website.
|
|
metadata:
|
|
technology:
|
|
- express
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html
|
|
cwe:
|
|
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
|
|
category: security
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Open Redirect
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-open-redirect.express-open-redirect
|
|
shortlink: https://sg.run/EpoP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22081
|
|
rv_id: 1263140
|
|
rule_id: X5ULkq
|
|
version_id: nWT2L0v
|
|
url: https://semgrep.dev/playground/r/nWT2L0v/javascript.express.security.audit.express-open-redirect.express-open-redirect
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
options:
|
|
taint_unify_mvars: true
|
|
symbolic_propagation: true
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE)
|
|
- pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE + $...A)
|
|
- pattern: $RES.redirect(`$HTTP${$REQ. ... .$VALUE}...`)
|
|
- pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...])
|
|
- pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...] + $...A)
|
|
- pattern: $RES.redirect(`$HTTP${$REQ.$VALUE[...]}...`)
|
|
- metavariable-regex:
|
|
metavariable: $HTTP
|
|
regex: ^https?:\/\/$
|
|
- pattern-either:
|
|
- pattern: $REQ. ... .$VALUE
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $RES.redirect($REQ. ... .$VALUE)
|
|
- pattern: $RES.redirect($REQ. ... .$VALUE + $...A)
|
|
- pattern: $RES.redirect(`${$REQ. ... .$VALUE}...`)
|
|
- pattern: $REQ. ... .$VALUE
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $RES.redirect($REQ.$VALUE['...'])
|
|
- pattern: $RES.redirect($REQ.$VALUE['...'] + $...A)
|
|
- pattern: $RES.redirect(`${$REQ.$VALUE['...']}...`)
|
|
- pattern: $REQ.$VALUE
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$ASSIGN = $REQ. ... .$VALUE
|
|
...
|
|
- pattern-inside: |
|
|
$ASSIGN = $REQ.$VALUE['...']
|
|
...
|
|
- pattern-inside: |
|
|
$ASSIGN = $REQ. ... .$VALUE + $...A
|
|
...
|
|
- pattern-inside: "$ASSIGN = $REQ.$VALUE['...'] + $...A\n... \n"
|
|
- pattern-inside: |
|
|
$ASSIGN = `${$REQ. ... .$VALUE}...`
|
|
...
|
|
- pattern-inside: "$ASSIGN = `${$REQ.$VALUE['...']}...`\n... \n"
|
|
- pattern-either:
|
|
- pattern: $RES.redirect($ASSIGN)
|
|
- pattern: $RES.redirect($ASSIGN + $...FOO)
|
|
- pattern: $RES.redirect(`${$ASSIGN}...`)
|
|
- focus-metavariable: $ASSIGN
|
|
- id: javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
category: security
|
|
technology:
|
|
- express
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret
|
|
shortlink: https://sg.run/LYvG
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22083
|
|
rv_id: 1263143
|
|
rule_id: 10Uo39
|
|
version_id: LjTkgle
|
|
url: https://semgrep.dev/playground/r/LjTkgle/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$SESSION = require('express-session');
|
|
...
|
|
- pattern-inside: |
|
|
import $SESSION from 'express-session'
|
|
...
|
|
- pattern-inside: |
|
|
import {..., $SESSION, ...} from 'express-session'
|
|
...
|
|
- pattern-inside: |
|
|
import * as $SESSION from 'express-session'
|
|
...
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.use($SESSION({...}))
|
|
- pattern: |
|
|
$SECRET = $VALUE
|
|
...
|
|
$APP.use($SESSION($SECRET))
|
|
- pattern: |
|
|
secret: '$Y'
|
|
- id: javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization
|
|
message: The following function call $SER.$FUNC accepts user controlled data which
|
|
can result in Remote Code Execution (RCE) through Object Deserialization. It is
|
|
recommended to use secure data processing alternatives such as JSON.parse() and
|
|
Buffer.from().
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
technology:
|
|
- express
|
|
category: security
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Deserialization_Cheat_Sheet.html
|
|
source_rule_url:
|
|
- https://github.com/ajinabraham/njsscan/blob/75bfbeb9c8d72999e4d527dfa2548f7f0f3cc48a/njsscan/rules/semantic_grep/eval/eval_deserialize.yaml
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization
|
|
shortlink: https://sg.run/8W5j
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22084
|
|
rv_id: 1263145
|
|
rule_id: 9AUyqj
|
|
version_id: gETB7nD
|
|
url: https://semgrep.dev/playground/r/gETB7nD/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
|
|
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
- pattern: files.$ANYTHING.data.toString('utf8')
|
|
- pattern: files.$ANYTHING['data'].toString('utf8')
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$SER = require('$IMPORT')
|
|
...
|
|
- pattern-inside: |
|
|
import $SER from '$IMPORT'
|
|
...
|
|
- pattern-inside: |
|
|
import * as $SER from '$IMPORT'
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $IMPORT
|
|
regex: ^(node-serialize|serialize-to-js)$
|
|
- pattern: $SER.$FUNC(...)
|
|
- metavariable-regex:
|
|
metavariable: $FUNC
|
|
regex: ^(unserialize|deserialize)$
|
|
- id: javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection
|
|
message: Detected a sequelize statement that is tainted by user-input. This could
|
|
lead to SQL injection if the variable is user-controlled and is not properly sanitized.
|
|
In order to prevent SQL injection, it is recommended to use parameterized queries
|
|
or prepared statements.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
references:
|
|
- https://sequelize.org/docs/v6/core-concepts/raw-queries/#replacements
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection
|
|
shortlink: https://sg.run/gjoe
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22085
|
|
rv_id: 1263241
|
|
rule_id: yyU0GX
|
|
version_id: nWT2Llx
|
|
url: https://semgrep.dev/playground/r/nWT2Llx/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
|
|
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
- pattern: files.$ANYTHING.data.toString('utf8')
|
|
- pattern: files.$ANYTHING['data'].toString('utf8')
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sequelize.query($QUERY,...)
|
|
- pattern: $DB.sequelize.query($QUERY,...)
|
|
- focus-metavariable: $QUERY
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: parseInt(...)
|
|
- pattern: $FUNC. ... .hash(...)
|
|
- id: go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage
|
|
message: Detected usage of dangerous method $METHOD which does not escape inputs
|
|
(see link in references). If the argument is user-controlled, this can lead to
|
|
SQL injection. When using $METHOD function, do not trust user-submitted data and
|
|
only allow approved list of input (possibly, use an allowlist approach).
|
|
severity: WARNING
|
|
languages:
|
|
- go
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
($REQUEST : http.Request).$ANYTHING
|
|
- pattern: |
|
|
($REQUEST : *http.Request).$ANYTHING
|
|
- metavariable-regex:
|
|
metavariable: $ANYTHING
|
|
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import ("gorm.io/gorm")
|
|
...
|
|
- patterns:
|
|
- pattern-inside: |
|
|
func $VAL(..., $GORM *gorm.DB,... ) {
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern: |
|
|
$GORM. ... .$METHOD($VALUE)
|
|
- pattern: |
|
|
$DB := $GORM. ... .$ANYTHING(...)
|
|
...
|
|
$DB. ... .$METHOD($VALUE)
|
|
- focus-metavariable: $VALUE
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(Order|Exec|Raw|Group|Having|Distinct|Select|Pluck)$
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: strconv.Atoi(...)
|
|
- pattern: |
|
|
($X: bool)
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- gorm
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://gorm.io/docs/security.html#SQL-injection-Methods
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage
|
|
shortlink: https://sg.run/R4qg
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 24693
|
|
rv_id: 1262915
|
|
rule_id: AbU5o3
|
|
version_id: l4TJRJK
|
|
url: https://semgrep.dev/playground/r/l4TJRJK/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage
|
|
origin: community
|
|
- id: csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure
|
|
patterns:
|
|
- pattern: $APP.UseDeveloperExceptionPage(...);
|
|
- pattern-not-inside: |
|
|
if ($ENV.IsDevelopment(...)) {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
if ($ENV.EnvironmentName == "Development") {
|
|
...
|
|
}
|
|
message: Stacktrace information is displayed in a non-Development environment. Accidentally
|
|
disclosing sensitive stack trace information in a production environment aids
|
|
an attacker in reconnaissance and information gathering.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- csharp
|
|
owasp:
|
|
- A06:2017 - Security Misconfiguration
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
cwe:
|
|
- 'CWE-209: Generation of Error Message Containing Sensitive Information'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/209.html
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design/
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure
|
|
shortlink: https://sg.run/XvkA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 26720
|
|
rv_id: 1262653
|
|
rule_id: lBU6Dv
|
|
version_id: 0bTKzrB
|
|
url: https://semgrep.dev/playground/r/0bTKzrB/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
severity: WARNING
|
|
- id: csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: $LIFETIME = $FALSE
|
|
- pattern-inside: new TokenValidationParameters {...}
|
|
- patterns:
|
|
- pattern: |
|
|
(TokenValidationParameters $OPTS). ... .$LIFETIME = $FALSE
|
|
- metavariable-regex:
|
|
metavariable: $LIFETIME
|
|
regex: (RequireExpirationTime|ValidateLifetime)
|
|
- metavariable-regex:
|
|
metavariable: $FALSE
|
|
regex: (false)
|
|
- focus-metavariable: $FALSE
|
|
fix: |
|
|
true
|
|
message: The TokenValidationParameters.$LIFETIME is set to $FALSE, this means the
|
|
JWT tokens lifetime is not validated. This can lead to an JWT token being used
|
|
after it has expired, which has security implications. It is recommended to validate
|
|
the JWT lifetime to ensure only valid tokens are used.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- csharp
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe:
|
|
- 'CWE-613: Insufficient Session Expiration'
|
|
references:
|
|
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/
|
|
- https://cwe.mitre.org/data/definitions/613.html
|
|
- https://docs.microsoft.com/en-us/dotnet/api/microsoft.identitymodel.tokens.tokenvalidationparameters?view=azure-dotnet
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation
|
|
shortlink: https://sg.run/KA0d
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 28955
|
|
rv_id: 1262628
|
|
rule_id: bwU5kK
|
|
version_id: w8TRolJ
|
|
url: https://semgrep.dev/playground/r/w8TRolJ/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
severity: WARNING
|
|
- id: python.django.security.injection.command.subprocess-injection.subprocess-injection
|
|
languages:
|
|
- python
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(..., $REQUEST, ...):
|
|
...
|
|
- focus-metavariable: $REQUEST
|
|
- metavariable-pattern:
|
|
metavariable: $REQUEST
|
|
patterns:
|
|
- pattern: request
|
|
- pattern-not-inside: request.build_absolute_uri
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(...)
|
|
- pattern-not: subprocess.$FUNC("...", ...)
|
|
- pattern-not: subprocess.$FUNC(["...", ...], ...)
|
|
- pattern-not-inside: |
|
|
$CMD = ["...", ...]
|
|
...
|
|
subprocess.$FUNC($CMD, ...)
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...)
|
|
- metavariable-regex:
|
|
metavariable: $SHELL
|
|
regex: ^(sh|bash|ksh|csh|tcsh|zsh)$
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...)
|
|
- metavariable-regex:
|
|
metavariable: $INTERPRETER
|
|
regex: ^(python|python\d)$
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: $DICT[$KEY]
|
|
- focus-metavariable: $KEY
|
|
severity: ERROR
|
|
message: Detected user input entering a `subprocess` call unsafely. This could result
|
|
in a command injection vulnerability. An attacker could use this vulnerability
|
|
to execute arbitrary commands on the host, which allows them to download malware,
|
|
scan sensitive data, or run any command they wish on the server. Do not let users
|
|
choose the command to run. In general, prefer to use Python API versions of system
|
|
commands. If you must use subprocess, use a dictionary to allowlist a set of commands.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- flask
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.django.security.injection.command.subprocess-injection.subprocess-injection
|
|
shortlink: https://sg.run/49BE
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 31144
|
|
rv_id: 1263388
|
|
rule_id: EwUepx
|
|
version_id: 7ZTE3qK
|
|
url: https://semgrep.dev/playground/r/7ZTE3qK/python.django.security.injection.command.subprocess-injection.subprocess-injection
|
|
origin: community
|
|
- id: python.flask.security.injection.subprocess-injection.subprocess-injection
|
|
languages:
|
|
- python
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.form.get(...)
|
|
- pattern: flask.request.form[...]
|
|
- pattern: flask.request.args.get(...)
|
|
- pattern: flask.request.args[...]
|
|
- pattern: flask.request.values.get(...)
|
|
- pattern: flask.request.values[...]
|
|
- pattern: flask.request.cookies.get(...)
|
|
- pattern: flask.request.cookies[...]
|
|
- pattern: flask.request.stream
|
|
- pattern: flask.request.headers.get(...)
|
|
- pattern: flask.request.headers[...]
|
|
- pattern: flask.request.data
|
|
- pattern: flask.request.full_path
|
|
- pattern: flask.request.url
|
|
- pattern: flask.request.json
|
|
- pattern: flask.request.get_json()
|
|
- pattern: flask.request.view_args.get(...)
|
|
- pattern: flask.request.view_args[...]
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- focus-metavariable: $ROUTEVAR
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(...)
|
|
- pattern-not: subprocess.$FUNC("...", ...)
|
|
- pattern-not: subprocess.$FUNC(["...", ...], ...)
|
|
- pattern-not-inside: |
|
|
$CMD = ["...", ...]
|
|
...
|
|
subprocess.$FUNC($CMD, ...)
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...)
|
|
- metavariable-regex:
|
|
metavariable: $SHELL
|
|
regex: ^(sh|bash|ksh|csh|tcsh|zsh)$
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...)
|
|
- metavariable-regex:
|
|
metavariable: $INTERPRETER
|
|
regex: ^(python|python\d)$
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: $DICT[$KEY]
|
|
- focus-metavariable: $KEY
|
|
severity: ERROR
|
|
message: Detected user input entering a `subprocess` call unsafely. This could result
|
|
in a command injection vulnerability. An attacker could use this vulnerability
|
|
to execute arbitrary commands on the host, which allows them to download malware,
|
|
scan sensitive data, or run any command they wish on the server. Do not let users
|
|
choose the command to run. In general, prefer to use Python API versions of system
|
|
commands. If you must use subprocess, use a dictionary to allowlist a set of commands.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- flask
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.flask.security.injection.subprocess-injection.subprocess-injection
|
|
shortlink: https://sg.run/5gW3
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 31147
|
|
rv_id: 1263433
|
|
rule_id: 8GU3qp
|
|
version_id: bZT53gQ
|
|
url: https://semgrep.dev/playground/r/bZT53gQ/python.flask.security.injection.subprocess-injection.subprocess-injection
|
|
origin: community
|
|
- id: yaml.github-actions.security.github-script-injection.github-script-injection
|
|
languages:
|
|
- yaml
|
|
message: 'Using variable interpolation `${{...}}` with `github` context data in
|
|
a `actions/github-script`''s `script:` step could allow an attacker to inject
|
|
their own code into the runner. This would allow them to steal secrets and code.
|
|
`github` context data can have arbitrary user input and should be treated as untrusted.
|
|
Instead, use an intermediate environment variable with `env:` to store the data
|
|
and use the environment variable in the `run:` script. Be sure to use double-quotes
|
|
the environment variable, like this: "$ENVVAR".'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections
|
|
- https://securitylab.github.com/research/github-actions-untrusted-input/
|
|
- https://github.com/actions/github-script
|
|
technology:
|
|
- github-actions
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.github-script-injection.github-script-injection
|
|
shortlink: https://sg.run/g1G0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 31441
|
|
rv_id: 1423394
|
|
rule_id: OrUQvK
|
|
version_id: 5PT7Zyw
|
|
url: https://semgrep.dev/playground/r/5PT7Zyw/yaml.github-actions.security.github-script-injection.github-script-injection
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: 'steps: [...]'
|
|
- pattern-inside: |
|
|
uses: $ACTION
|
|
...
|
|
- pattern-inside: |
|
|
with:
|
|
...
|
|
script: ...
|
|
...
|
|
- pattern: 'script: $SHELL'
|
|
- metavariable-regex:
|
|
metavariable: $ACTION
|
|
regex: actions/github-script@.*
|
|
- metavariable-pattern:
|
|
language: generic
|
|
metavariable: $SHELL
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: ${{ ... github.event.issue.title ... }}
|
|
- pattern: ${{ ... github.event.issue.body ... }}
|
|
- pattern: ${{ ... github.event.pull_request.title ... }}
|
|
- pattern: ${{ ... github.event.pull_request.body ... }}
|
|
- pattern: ${{ ... github.event.comment.body ... }}
|
|
- pattern: ${{ ... github.event.review.body ... }}
|
|
- pattern: ${{ ... github.event.review_comment.body ... }}
|
|
- pattern: ${{ ... github.event.pages ... .page_name ... }}
|
|
- pattern: ${{ ... github.event.head_commit.message ... }}
|
|
- pattern: ${{ ... github.event.head_commit.author.email ... }}
|
|
- pattern: ${{ ... github.event.head_commit.author.name ... }}
|
|
- pattern: ${{ ... github.event.commits ... .author.email ... }}
|
|
- pattern: ${{ ... github.event.commits ... .author.name ... }}
|
|
- pattern: ${{ ... github.event.commits ... .message ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.ref ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.label ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.repo.default_branch ...
|
|
}}
|
|
- pattern: ${{ ... github.ref ... }}
|
|
- pattern: ${{ ... github.base_ref ... }}
|
|
- pattern: ${{ ... github.head_ref ... }}
|
|
- pattern: ${{ ... github.ref_name ... }}
|
|
- pattern: ${{ ... github.workflow ... }}
|
|
- pattern: ${{ ... github.event.inputs ... }}
|
|
- pattern: ${{ ... github.event.discussion.title ... }}
|
|
- pattern: ${{ ... github.event.discussion.body ... }}
|
|
- pattern: ${{ ... github.event.workflow_run.head_branch ... }}
|
|
- pattern: ${{ ... github.event.workflow_run.head_commit.message ... }}
|
|
- pattern: ${{ ... github.event.milestone.title ... }}
|
|
- pattern: ${{ ... github.event.milestone.description ... }}
|
|
- pattern: ${{ ... github.event.project_card.note ... }}
|
|
- pattern: ${{ ... github.event.project.name ... }}
|
|
- pattern: ${{ ... github.event.project_column.name ... }}
|
|
- pattern: ${{ ... github.event.release.name ... }}
|
|
- pattern: ${{ ... github.event.release.body ... }}
|
|
- pattern: ${{ ... github.event.deployment.ref ... }}
|
|
- pattern: ${{ ... inputs ... }}
|
|
- pattern-not: ${{ ... github.event.issue.title && ... }}
|
|
- pattern-not: ${{ ... github.event.issue.body && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.title && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.body && ... }}
|
|
- pattern-not: ${{ ... github.event.comment.body && ... }}
|
|
- pattern-not: ${{ ... github.event.review.body && ... }}
|
|
- pattern-not: ${{ ... github.event.review_comment.body && ... }}
|
|
- pattern-not: ${{ ... github.event.pages ... .page_name && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.message && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.author.email && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.author.name && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .author.email && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .author.name && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .message && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.ref && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.label && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch &&
|
|
... }}
|
|
- pattern-not: ${{ ... github.ref && ... }}
|
|
- pattern-not: ${{ ... github.base_ref && ... }}
|
|
- pattern-not: ${{ ... github.head_ref && ... }}
|
|
- pattern-not: ${{ ... github.ref_name && ... }}
|
|
- pattern-not: ${{ ... github.workflow && ... }}
|
|
- pattern-not: ${{ ... github.event.inputs && ... }}
|
|
- pattern-not: ${{ ... github.event.discussion.title && ... }}
|
|
- pattern-not: ${{ ... github.event.discussion.body && ... }}
|
|
- pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }}
|
|
- pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ...
|
|
}}
|
|
- pattern-not: ${{ ... github.event.milestone.title && ... }}
|
|
- pattern-not: ${{ ... github.event.milestone.description && ... }}
|
|
- pattern-not: ${{ ... github.event.project_card.note && ... }}
|
|
- pattern-not: ${{ ... github.event.project.name && ... }}
|
|
- pattern-not: ${{ ... github.event.project_column.name && ... }}
|
|
- pattern-not: ${{ ... github.event.release.name && ... }}
|
|
- pattern-not: ${{ ... github.event.release.body && ... }}
|
|
- pattern-not: ${{ ... github.event.deployment.ref && ... }}
|
|
severity: ERROR
|
|
- id: python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish
|
|
message: Detected Blowfish cipher algorithm which is considered insecure. This algorithm
|
|
is not cryptographically secure and can be reversed easily. Use secure stream
|
|
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
|
|
with a block size of 128 bits. When using a block cipher, use a modern mode of
|
|
operation that also provides authentication, such as GCM.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption
|
|
- https://www.pycryptodome.org/src/cipher/cipher
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::pycryptodome
|
|
- crypto::search::symmetric-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish
|
|
shortlink: https://sg.run/dlOE
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33634
|
|
rv_id: 1263545
|
|
rule_id: JDUGnK
|
|
version_id: ExTExln
|
|
url: https://semgrep.dev/playground/r/ExTExln/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Cryptodome.Cipher.Blowfish.new(...)
|
|
- pattern: Crypto.Cipher.Blowfish.new(...)
|
|
- id: python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des
|
|
message: Detected DES cipher or Triple DES algorithm which is considered insecure.
|
|
This algorithm is not cryptographically secure and can be reversed easily. Use
|
|
a secure symmetric cipher from the cryptodome package instead. Use secure stream
|
|
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
|
|
with a block size of 128 bits. When using a block cipher, use a modern mode of
|
|
operation that also provides authentication, such as GCM.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/326.html
|
|
- https://www.pycryptodome.org/src/cipher/cipher
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::pycryptodome
|
|
- crypto::search::symmetric-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des
|
|
shortlink: https://sg.run/Z5bw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33635
|
|
rv_id: 1263546
|
|
rule_id: 5rUr73
|
|
version_id: 7ZTE3G7
|
|
url: https://semgrep.dev/playground/r/7ZTE3G7/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Cryptodome.Cipher.DES.new(...)
|
|
- pattern: Crypto.Cipher.DES.new(...)
|
|
- pattern: Cryptodome.Cipher.DES3.new(...)
|
|
- pattern: Crypto.Cipher.DES3.new(...)
|
|
- id: python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2
|
|
message: Detected RC2 cipher algorithm which is considered insecure. This algorithm
|
|
is not cryptographically secure and can be reversed easily. Use secure stream
|
|
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
|
|
with a block size of 128 bits. When using a block cipher, use a modern mode of
|
|
operation that also provides authentication, such as GCM.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/326.html
|
|
- https://www.pycryptodome.org/src/cipher/cipher
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::pycryptodome
|
|
- crypto::search::symmetric-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2
|
|
shortlink: https://sg.run/nAbY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33636
|
|
rv_id: 1263547
|
|
rule_id: GdUYlW
|
|
version_id: LjTkgn6
|
|
url: https://semgrep.dev/playground/r/LjTkgn6/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Cryptodome.Cipher.ARC2.new(...)
|
|
- pattern: Crypto.Cipher.ARC2.new(...)
|
|
- id: python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4
|
|
message: Detected ARC4 cipher algorithm which is considered insecure. This algorithm
|
|
is not cryptographically secure and can be reversed easily. Use secure stream
|
|
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
|
|
with a block size of 128 bits. When using a block cipher, use a modern mode of
|
|
operation that also provides authentication, such as GCM.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/326.html
|
|
- https://www.pycryptodome.org/src/cipher/cipher
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::pycryptodome
|
|
- crypto::search::symmetric-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4
|
|
shortlink: https://sg.run/Eo6N
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33637
|
|
rv_id: 1263548
|
|
rule_id: ReUnEB
|
|
version_id: 8KT5rXY
|
|
url: https://semgrep.dev/playground/r/8KT5rXY/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Cryptodome.Cipher.ARC4.new(...)
|
|
- pattern: Crypto.Cipher.ARC4.new(...)
|
|
- id: python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2
|
|
message: Detected MD2 hash algorithm which is considered insecure. MD2 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use a modern
|
|
hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms
|
|
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
|
|
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
|
|
- http://2012.sharcs.org/slides/stevens.pdf
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::pycryptodome
|
|
- crypto::search::hash-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2
|
|
shortlink: https://sg.run/7JP2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33638
|
|
rv_id: 1263550
|
|
rule_id: AbU0Ex
|
|
version_id: QkTGqD8
|
|
url: https://semgrep.dev/playground/r/QkTGqD8/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Crypto.Hash.MD2.new(...)
|
|
- pattern: Cryptodome.Hash.MD2.new (...)
|
|
- id: python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4
|
|
message: Detected MD4 hash algorithm which is considered insecure. MD4 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use a modern
|
|
hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms
|
|
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
|
|
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
|
|
- http://2012.sharcs.org/slides/stevens.pdf
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::pycryptodome
|
|
- crypto::search::hash-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4
|
|
shortlink: https://sg.run/Lve6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33639
|
|
rv_id: 1263551
|
|
rule_id: BYUJy4
|
|
version_id: 3ZT4Xnp
|
|
url: https://semgrep.dev/playground/r/3ZT4Xnp/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Crypto.Hash.MD4.new(...)
|
|
- pattern: Cryptodome.Hash.MD4.new (...)
|
|
- id: python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5
|
|
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use a modern
|
|
hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms
|
|
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
|
|
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
|
|
- http://2012.sharcs.org/slides/stevens.pdf
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::pycryptodome
|
|
- crypto::search::hash-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5
|
|
shortlink: https://sg.run/85JN
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33640
|
|
rv_id: 1263552
|
|
rule_id: DbUXwo
|
|
version_id: 44TEjpk
|
|
url: https://semgrep.dev/playground/r/44TEjpk/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Crypto.Hash.MD5.new(...)
|
|
- pattern: Cryptodome.Hash.MD5.new (...)
|
|
- id: csharp.dotnet.security.use_ecb_mode.use_ecb_mode
|
|
message: Usage of the insecure ECB mode detected. You should use an authenticated
|
|
encryption mode instead, which is implemented by the classes AesGcm or ChaCha20Poly1305.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
category: security
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.ciphermode?view=net-6.0
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.use_ecb_mode.use_ecb_mode
|
|
shortlink: https://sg.run/wj9n
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 36773
|
|
rv_id: 1262623
|
|
rule_id: 0oUqWP
|
|
version_id: yeTxpPw
|
|
url: https://semgrep.dev/playground/r/yeTxpPw/csharp.dotnet.security.use_ecb_mode.use_ecb_mode
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: ($KEYTYPE $KEY).EncryptEcb(...);
|
|
- pattern: ($KEYTYPE $KEY).DecryptEcb(...);
|
|
- pattern: ($KEYTYPE $KEY).Mode = CipherMode.ECB;
|
|
- metavariable-pattern:
|
|
metavariable: $KEYTYPE
|
|
pattern-either:
|
|
- pattern: SymmetricAlgorithm
|
|
- pattern: Aes
|
|
- pattern: Rijndael
|
|
- pattern: DES
|
|
- pattern: TripleDES
|
|
- pattern: RC2
|
|
- id: csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration
|
|
message: You are using an insecure random number generator (RNG) to create a cryptographic
|
|
key. System.Random must never be used for cryptographic purposes. Use System.Security.Cryptography.RandomNumberGenerator
|
|
instead.
|
|
severity: ERROR
|
|
metadata:
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
category: security
|
|
cwe:
|
|
- 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://learn.microsoft.com/en-us/dotnet/api/system.random?view=net-6.0#remarks
|
|
- https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.randomnumbergenerator?view=net-6.0
|
|
- https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0#constructors
|
|
- https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.symmetricalgorithm.key?view=net-6.0#system-security-cryptography-symmetricalgorithm-key
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration
|
|
shortlink: https://sg.run/xjrA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 36774
|
|
rv_id: 1262624
|
|
rule_id: KxU3Nq
|
|
version_id: rxTAK2O
|
|
url: https://semgrep.dev/playground/r/rxTAK2O/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: (System.Random $RNG).NextBytes($KEY); ...
|
|
- pattern: $KEY
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: ($KEYTYPE $CIPHER).Key = $SINK;
|
|
- focus-metavariable: $SINK
|
|
- metavariable-pattern:
|
|
metavariable: $KEYTYPE
|
|
pattern-either:
|
|
- pattern: SymmetricAlgorithm
|
|
- pattern: Aes
|
|
- pattern: Rijndael
|
|
- pattern: DES
|
|
- pattern: TripleDES
|
|
- pattern: RC2
|
|
- pattern: new AesGcm(...)
|
|
- pattern: new AesCcm(...)
|
|
- pattern: new ChaCha20Poly1305(...)
|
|
- id: html.security.plaintext-http-link.plaintext-http-link
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- html
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
confidence: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/319.html
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/html.security.plaintext-http-link.plaintext-http-link
|
|
shortlink: https://sg.run/RA5q
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 39193
|
|
rv_id: 1262976
|
|
rule_id: AbUnNo
|
|
version_id: xyTjzRL
|
|
url: https://semgrep.dev/playground/r/xyTjzRL/html.security.plaintext-http-link.plaintext-http-link
|
|
origin: community
|
|
patterns:
|
|
- pattern: <a href="$URL">...</a>
|
|
- metavariable-regex:
|
|
metavariable: $URL
|
|
regex: ^(?i)http://
|
|
message: This link points to a plaintext HTTP URL. Prefer an encrypted HTTPS URL
|
|
if possible.
|
|
severity: WARNING
|
|
languages:
|
|
- html
|
|
- id: java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils
|
|
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use HMAC
|
|
instead.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::org.apache.commons
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils
|
|
shortlink: https://sg.run/AWL2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 39194
|
|
rv_id: 1263012
|
|
rule_id: BYUGK0
|
|
version_id: WrTqK7K
|
|
url: https://semgrep.dev/playground/r/WrTqK7K/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils
|
|
origin: community
|
|
patterns:
|
|
- pattern: |
|
|
$DU.$GET_ALGO().digest(...)
|
|
- metavariable-pattern:
|
|
metavariable: $GET_ALGO
|
|
pattern: getMd5Digest
|
|
- metavariable-pattern:
|
|
metavariable: $DU
|
|
pattern: DigestUtils
|
|
- focus-metavariable: $GET_ALGO
|
|
fix: |
|
|
getSha512Digest
|
|
- id: terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions
|
|
pattern-either:
|
|
- pattern: |
|
|
resource "aws_config_configuration_aggregator" $ANYTHING {
|
|
...
|
|
account_aggregation_source {
|
|
...
|
|
regions = ...
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: |
|
|
resource "aws_config_configuration_aggregator" $ANYTHING {
|
|
...
|
|
organization_aggregation_source {
|
|
...
|
|
regions = ...
|
|
...
|
|
}
|
|
...
|
|
}
|
|
message: The AWS configuration aggregator does not aggregate all AWS Config region.
|
|
This may result in unmonitored configuration in regions that are thought to be
|
|
unused. Configure the aggregator with all_regions for the source.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A09:2021 - Security Logging and Monitoring Failures
|
|
- A09:2025 - Security Logging & Alerting Failures
|
|
cwe:
|
|
- 'CWE-778: Insufficient Logging'
|
|
references:
|
|
- https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insufficient Logging
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions
|
|
shortlink: https://sg.run/O6A7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 47275
|
|
rv_id: 1263703
|
|
rule_id: DbUo7v
|
|
version_id: A8Tgdwv
|
|
url: https://semgrep.dev/playground/r/A8Tgdwv/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions
|
|
origin: community
|
|
- id: java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb
|
|
pattern: $CIPHER.getInstance("=~/AES/ECB.*/")
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::mode::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb
|
|
shortlink: https://sg.run/dB2Y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48734
|
|
rv_id: 1263009
|
|
rule_id: WAU2yA
|
|
version_id: A8TgdEo
|
|
url: https://semgrep.dev/playground/r/A8TgdEo/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb
|
|
origin: community
|
|
message: 'Use of AES with ECB mode detected. ECB doesn''t provide message confidentiality
|
|
and is not semantically secure so should not be used. Instead, use a strong,
|
|
secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions
|
|
for more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish
|
|
pattern: $CIPHER.getInstance("Blowfish")
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish
|
|
shortlink: https://sg.run/ZE4n
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48735
|
|
rv_id: 1263010
|
|
rule_id: 0oUR28
|
|
version_id: BjTkZy0
|
|
url: https://semgrep.dev/playground/r/BjTkZy0/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish
|
|
origin: community
|
|
message: 'Use of Blowfish was detected. Blowfish uses a 64-bit block size that makes
|
|
it vulnerable to birthday attacks, and is therefore considered non-compliant. Instead,
|
|
use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions
|
|
for more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import javax;
|
|
...
|
|
- pattern-either:
|
|
- pattern: javax.crypto.Cipher.getInstance("AES")
|
|
- pattern: (javax.crypto.Cipher $CIPHER).getInstance("AES")
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import javax.*;
|
|
...
|
|
- pattern-inside: |
|
|
import javax.crypto;
|
|
...
|
|
- pattern-either:
|
|
- pattern: crypto.Cipher.getInstance("AES")
|
|
- pattern: (crypto.Cipher $CIPHER).getInstance("AES")
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import javax.crypto.*;
|
|
...
|
|
- pattern-inside: |
|
|
import javax.crypto.Cipher;
|
|
...
|
|
- pattern-either:
|
|
- pattern: Cipher.getInstance("AES")
|
|
- pattern: (Cipher $CIPHER).getInstance("AES")
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::mode::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes
|
|
shortlink: https://sg.run/nzKO
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48736
|
|
rv_id: 1263011
|
|
rule_id: KxUB7Z
|
|
version_id: DkTRbwy
|
|
url: https://semgrep.dev/playground/r/DkTRbwy/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes
|
|
origin: community
|
|
message: 'Use of AES with no settings detected. By default, java.crypto.Cipher uses
|
|
ECB mode. ECB doesn''t provide message confidentiality and is not semantically
|
|
secure so should not be used. Instead, use a strong, secure cipher: java.crypto.Cipher.getInstance("AES/CBC/PKCS7PADDING").
|
|
See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for
|
|
more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.crypto.use-of-rc2.use-of-rc2
|
|
pattern: $CIPHER.getInstance("RC2")
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2
|
|
shortlink: https://sg.run/EEvA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48737
|
|
rv_id: 1263014
|
|
rule_id: qNUzXG
|
|
version_id: K3TKkg0
|
|
url: https://semgrep.dev/playground/r/K3TKkg0/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2
|
|
origin: community
|
|
message: 'Use of RC2 was detected. RC2 is vulnerable to related-key attacks, and
|
|
is therefore considered non-compliant. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING").
|
|
See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for
|
|
more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.crypto.use-of-rc4.use-of-rc4
|
|
pattern: $CIPHER.getInstance("RC4")
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4
|
|
shortlink: https://sg.run/7OYR
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48738
|
|
rv_id: 1263015
|
|
rule_id: lBUw8k
|
|
version_id: qkTR7vk
|
|
url: https://semgrep.dev/playground/r/qkTR7vk/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4
|
|
origin: community
|
|
message: 'Use of RC4 was detected. RC4 is vulnerable to several attacks, including
|
|
stream cipher attacks and bit flipping attacks. Instead, use a strong, secure
|
|
cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions
|
|
for more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: clojure.lang.security.use-of-md5.use-of-md5
|
|
languages:
|
|
- clojure
|
|
severity: WARNING
|
|
message: MD5 hash algorithm detected. This is not collision resistant and leads
|
|
to easily-cracked password hashes. Replace with current recommended hashing algorithms.
|
|
metadata:
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
|
|
technology:
|
|
- clojure
|
|
source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/weak-hash-function-md5.yml
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
author: Gabriel Marquet <gab.marquet@gmail.com>
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/clojure.lang.security.use-of-md5.use-of-md5
|
|
shortlink: https://sg.run/BgPx
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 52195
|
|
rv_id: 1262609
|
|
rule_id: nJU1ep
|
|
version_id: 0bTKz2B
|
|
url: https://semgrep.dev/playground/r/0bTKz2B/clojure.lang.security.use-of-md5.use-of-md5
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: (MessageDigest/getInstance "MD5")
|
|
- pattern: (MessageDigest/getInstance MessageDigestAlgorithms/MD5)
|
|
- pattern: (MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5)
|
|
- pattern: (java.security.MessageDigest/getInstance "MD5")
|
|
- pattern: (java.security.MessageDigest/getInstance MessageDigestAlgorithms/MD5)
|
|
- pattern: (java.security.MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5)
|
|
- id: terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_lambda_permission" $ANYTHING {
|
|
...
|
|
principal = "$PRINCIPAL"
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
resource "aws_lambda_permission" $ANYTHING {
|
|
...
|
|
source_arn = ...
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $PRINCIPAL
|
|
regex: .*[.]amazonaws[.]com$
|
|
message: The AWS Lambda permission has an AWS service principal but does not specify
|
|
a source ARN. If you grant permission to a service principal without specifying
|
|
the source, other accounts could potentially configure resources in their account
|
|
to invoke your Lambda function. Set the source_arn value to the ARN of the AWS
|
|
resource that invokes the function, eg. an S3 bucket, CloudWatch Events Rule,
|
|
API Gateway, or SNS topic.
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/732.html
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_permission
|
|
- https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-lambda-permission.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn
|
|
shortlink: https://sg.run/kOP7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 54772
|
|
rv_id: 1263732
|
|
rule_id: OrU9Ox
|
|
version_id: 1QTypq5
|
|
url: https://semgrep.dev/playground/r/1QTypq5/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn
|
|
origin: community
|
|
- id: java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
- https://xerces.apache.org/xerces2-j/features.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing
|
|
shortlink: https://sg.run/Gj32
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 59048
|
|
rv_id: 1263061
|
|
rule_id: j2Udpk
|
|
version_id: YDTZeko
|
|
url: https://semgrep.dev/playground/r/YDTZeko/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing
|
|
origin: community
|
|
message: DOCTYPE declarations are enabled for this SAXParserFactory. This is vulnerable
|
|
to XML external entity attacks. Disable this by setting the feature `http://apache.org/xml/features/disallow-doctype-decl`
|
|
to true. Alternatively, allow DOCTYPE declarations and only prohibit external
|
|
entities declarations. This can be done by setting the features `http://xml.org/sax/features/external-general-entities`
|
|
and `http://xml.org/sax/features/external-parameter-entities` to false. NOTE -
|
|
The previous links are not meant to be clicked. They are the literal config key
|
|
values that are supposed to be used to disable these features. For more information,
|
|
see https://semgrep.dev/docs/cheat-sheets/java-xxe/#3a-documentbuilderfactory.
|
|
mode: taint
|
|
pattern-sources:
|
|
- by-side-effect: true
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY = SAXParserFactory.newInstance();
|
|
- patterns:
|
|
- pattern: $FACTORY
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = SAXParserFactory.newInstance();
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = SAXParserFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = SAXParserFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = SAXParserFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $FACTORY.newSAXParser();
|
|
pattern-sanitizers:
|
|
- by-side-effect: true
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
- focus-metavariable: $FACTORY
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl",
|
|
true);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: $M($X)
|
|
- focus-metavariable: $X
|
|
fix: |
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
$FACTORY.newSAXParser();
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
- https://xerces.apache.org/xerces2-j/features.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled
|
|
shortlink: https://sg.run/1wyQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 59622
|
|
rv_id: 1263062
|
|
rule_id: v8UeQ1
|
|
version_id: 6xT29GK
|
|
url: https://semgrep.dev/playground/r/6xT29GK/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled
|
|
origin: community
|
|
message: DOCTYPE declarations are enabled for this TransformerFactory. This is vulnerable
|
|
to XML external entity attacks. Disable this by setting the attributes "accessExternalDTD"
|
|
and "accessExternalStylesheet" to "".
|
|
mode: taint
|
|
pattern-sources:
|
|
- by-side-effect: true
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY = TransformerFactory.newInstance();
|
|
- patterns:
|
|
- pattern: $FACTORY
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = TransformerFactory.newInstance();
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = TransformerFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = TransformerFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = TransformerFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = TransformerFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $FACTORY.newTransformer(...);
|
|
pattern-sanitizers:
|
|
- by-side-effect: true
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
- pattern: |
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
- pattern: |
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ...
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
- pattern: |
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
|
|
- focus-metavariable: $FACTORY
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: $M($X)
|
|
- focus-metavariable: $X
|
|
fix: |
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
$FACTORY.newTransformer(...);
|
|
languages:
|
|
- java
|
|
- id: dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile
|
|
patterns:
|
|
- pattern: |
|
|
RUN sudo ...
|
|
message: Avoid using sudo in Dockerfiles. Running processes as a non-root user can
|
|
help reduce the potential impact of configuration errors and security vulnerabilities.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- dockerfile
|
|
cwe:
|
|
- 'CWE-250: Execution with Unnecessary Privileges'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/250.html
|
|
- https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#user
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile
|
|
shortlink: https://sg.run/80Q7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 66384
|
|
rv_id: 1262661
|
|
rule_id: kxUlx1
|
|
version_id: pZT03zY
|
|
url: https://semgrep.dev/playground/r/pZT03zY/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile
|
|
origin: community
|
|
languages:
|
|
- dockerfile
|
|
severity: WARNING
|
|
- id: swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows
|
|
message: Webviews were observed that explictly allow JavaScript in an WKWebview
|
|
to open windows automatically. Consider disabling this functionality if not required,
|
|
following the principle of least privelege.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
category: security
|
|
cwe:
|
|
- 'CWE-272: Least Privilege Violation'
|
|
masvs:
|
|
- 'MASVS-PLATFORM-2: The app uses WebViews securely'
|
|
references:
|
|
- https://mas.owasp.org/MASVS/controls/MASVS-PLATFORM-2/
|
|
- https://developer.apple.com/documentation/webkit/wkpreferences/1536573-javascriptcanopenwindowsautomati
|
|
subcategory:
|
|
- audit
|
|
technology:
|
|
- ios
|
|
- macos
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows
|
|
shortlink: https://sg.run/YWLd
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 66514
|
|
rv_id: 946637
|
|
rule_id: lBUOZk
|
|
version_id: 9lTy1KE
|
|
url: https://semgrep.dev/playground/r/9lTy1KE/swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows
|
|
origin: community
|
|
languages:
|
|
- swift
|
|
patterns:
|
|
- pattern: |
|
|
$P = WKPreferences()
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$P.JavaScriptCanOpenWindowsAutomatically = $FALSE
|
|
...
|
|
$P.JavaScriptCanOpenWindowsAutomatically = $TRUE
|
|
- pattern-not-inside: |
|
|
...
|
|
$P.JavaScriptCanOpenWindowsAutomatically = $TRUE
|
|
...
|
|
$P.JavaScriptCanOpenWindowsAutomatically = $FALSE
|
|
- pattern: |
|
|
$P.JavaScriptCanOpenWindowsAutomatically = true
|
|
- metavariable-regex:
|
|
metavariable: $TRUE
|
|
regex: ^(true)$
|
|
- metavariable-regex:
|
|
metavariable: $TRUE
|
|
regex: (.*(?!true))
|
|
- patterns:
|
|
- pattern: |
|
|
$P.JavaScriptCanOpenWindowsAutomatically = true
|
|
- pattern-not-inside: |
|
|
...
|
|
$P.JavaScriptCanOpenWindowsAutomatically = ...
|
|
...
|
|
$P.JavaScriptCanOpenWindowsAutomatically = ...
|
|
- id: solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens
|
|
message: $VAULT.getPoolTokens() call on a Balancer pool is not protected from the
|
|
read-only reentrancy.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow'
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://quillaudits.medium.com/decoding-sentiment-protocols-1-million-exploit-quillaudits-f36bee77d376
|
|
- https://hackmd.io/@sentimentxyz/SJCySo1z2
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens
|
|
shortlink: https://sg.run/803Q
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67640
|
|
rv_id: 946602
|
|
rule_id: kxUl7x
|
|
version_id: e1T98xQ
|
|
url: https://semgrep.dev/playground/r/e1T98xQ/solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
function $F(...) {
|
|
...
|
|
$RETURN = $VAULT.getPoolTokens(...);
|
|
...
|
|
}
|
|
- metavariable-pattern:
|
|
metavariable: $RETURN
|
|
pattern-regex: .*uint256\[].*
|
|
- pattern-not-inside: |
|
|
contract $C {
|
|
...
|
|
function $CHECKFUNC(...) {
|
|
...
|
|
VaultReentrancyLib.ensureNotInVaultContext(...);
|
|
...
|
|
}
|
|
...
|
|
function $F(...) {
|
|
...
|
|
$CHECKFUNC(...);
|
|
...
|
|
$RETURN = $VAULT.getPoolTokens(...);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract $C {
|
|
...
|
|
function $CHECKFUNC(...) {
|
|
...
|
|
VaultReentrancyLib.ensureNotInVaultContext(...);
|
|
...
|
|
}
|
|
...
|
|
function $F(...) {
|
|
...
|
|
$RETURN = $VAULT.getPoolTokens(...);
|
|
...
|
|
$CHECKFUNC(...);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract $C {
|
|
...
|
|
function $CHECKFUNC(...) {
|
|
...
|
|
$VAULT.manageUserBalance(...);
|
|
...
|
|
}
|
|
...
|
|
function $F(...) {
|
|
...
|
|
$RETURN = $VAULT.getPoolTokens(...);
|
|
...
|
|
$CHECKFUNC(...);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract $C {
|
|
...
|
|
function $CHECKFUNC(...) {
|
|
...
|
|
$VAULT.manageUserBalance(...);
|
|
...
|
|
}
|
|
...
|
|
function $F(...) {
|
|
...
|
|
$CHECKFUNC(...);
|
|
...
|
|
$RETURN = $VAULT.getPoolTokens(...);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
function $F(...) {
|
|
...
|
|
VaultReentrancyLib.ensureNotInVaultContext(...);
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
function $F(...) {
|
|
...
|
|
$VAULT.manageUserBalance(...);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract LinearPool {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract ComposableStablePool {
|
|
...
|
|
}
|
|
- pattern-not-inside: "contract BalancerQueries {\n ...\n} \n"
|
|
- pattern-not-inside: |
|
|
contract ManagedPool {
|
|
...
|
|
}
|
|
- pattern-not-inside: "contract BaseWeightedPool {\n ...\n} \n"
|
|
- pattern-not-inside: |
|
|
contract ComposableStablePoolStorage {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract RecoveryModeHelper {
|
|
...
|
|
}
|
|
- focus-metavariable:
|
|
- $VAULT
|
|
languages:
|
|
- solidity
|
|
severity: ERROR
|
|
- id: solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate
|
|
message: $VAR.getRate() call on a Balancer pool is not protected from the read-only
|
|
reentrancy.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow'
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://forum.balancer.fi/t/reentrancy-vulnerability-scope-expanded/4345
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate
|
|
shortlink: https://sg.run/g9e5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67641
|
|
rv_id: 946603
|
|
rule_id: wdUx3D
|
|
version_id: vdTGn2l
|
|
url: https://semgrep.dev/playground/r/vdTGn2l/solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate
|
|
origin: community
|
|
patterns:
|
|
- pattern: |
|
|
function $F(...) {
|
|
...
|
|
$VAR.getRate();
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
function $F(...) {
|
|
...
|
|
VaultReentrancyLib.ensureNotInVaultContext(...);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
function $F(...) {
|
|
...
|
|
$VAULT.manageUserBalance(...);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
function _updateTokenRateCache(...) {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract PoolRecoveryHelper {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract ComposableStablePoolRates {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract WeightedPoolProtocolFees {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract $C {
|
|
...
|
|
function $CHECKFUNC(...) {
|
|
...
|
|
VaultReentrancyLib.ensureNotInVaultContext(...);
|
|
...
|
|
}
|
|
...
|
|
function $F(...) {
|
|
...
|
|
$CHECKFUNC(...);
|
|
...
|
|
$VAR.getRate();
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract $C {
|
|
...
|
|
function $CHECKFUNC(...) {
|
|
...
|
|
VaultReentrancyLib.ensureNotInVaultContext(...);
|
|
...
|
|
}
|
|
...
|
|
function $F(...) {
|
|
...
|
|
$VAR.getRate();
|
|
...
|
|
$CHECKFUNC(...);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract $C {
|
|
...
|
|
function $CHECKFUNC(...) {
|
|
...
|
|
$VAULT.manageUserBalance(...);
|
|
...
|
|
}
|
|
...
|
|
function $F(...) {
|
|
...
|
|
$VAR.getRate();
|
|
...
|
|
$CHECKFUNC(...);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract $C {
|
|
...
|
|
function $CHECKFUNC(...) {
|
|
...
|
|
$VAULT.manageUserBalance(...);
|
|
...
|
|
}
|
|
...
|
|
function $F(...) {
|
|
...
|
|
$CHECKFUNC(...);
|
|
...
|
|
$VAR.getRate();
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- focus-metavariable: $VAR
|
|
languages:
|
|
- solidity
|
|
severity: ERROR
|
|
- id: solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy
|
|
message: Function borrowFresh() in Compound performs state update after doTransferOut()
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow'
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://twitter.com/peckshield/status/1509431646818234369
|
|
- https://twitter.com/blocksecteam/status/1509466576848064512
|
|
- https://slowmist.medium.com/another-day-another-reentrancy-attack-5cde10bbb2b4
|
|
- https://explorer.fuse.io/address/0x139Eb08579eec664d461f0B754c1F8B569044611
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy
|
|
shortlink: https://sg.run/4A19
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67644
|
|
rv_id: 946606
|
|
rule_id: eqUkx4
|
|
version_id: nWTpz74
|
|
url: https://semgrep.dev/playground/r/nWTpz74/solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
function borrowFresh(...) {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
accountBorrows[borrower].interestIndex = borrowIndex;
|
|
...
|
|
- pattern: doTransferOut(...);
|
|
languages:
|
|
- solidity
|
|
severity: WARNING
|
|
- id: solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy
|
|
message: $POOL.get_virtual_price() call on a Curve pool is not protected from the
|
|
read-only reentrancy.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow'
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://chainsecurity.com/heartbreaks-curve-lp-oracles/
|
|
- https://chainsecurity.com/curve-lp-oracle-manipulation-post-mortem/
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy
|
|
shortlink: https://sg.run/Jk5P
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67646
|
|
rv_id: 946608
|
|
rule_id: d8UGDL
|
|
version_id: 7ZTrQO3
|
|
url: https://semgrep.dev/playground/r/7ZTrQO3/solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy
|
|
origin: community
|
|
patterns:
|
|
- pattern: |
|
|
$POOL.get_virtual_price()
|
|
- pattern-not-inside: |
|
|
function $F(...) {
|
|
...
|
|
$VAR.withdraw_admin_fees(...);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
function $F(...) {
|
|
...
|
|
$VAR.withdraw_admin_fees(...);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract $C {
|
|
...
|
|
function $CHECKFUNC(...) {
|
|
...
|
|
$VAR.withdraw_admin_fees(...);
|
|
...
|
|
}
|
|
...
|
|
function $F(...) {
|
|
...
|
|
$CHECKFUNC(...);
|
|
...
|
|
$POOL.get_virtual_price();
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
contract $C {
|
|
...
|
|
function $CHECKFUNC(...) {
|
|
...
|
|
$VAR.withdraw_admin_fees(...);
|
|
...
|
|
}
|
|
...
|
|
function $F(...) {
|
|
...
|
|
$POOL.get_virtual_price();
|
|
...
|
|
$CHECKFUNC(...);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
languages:
|
|
- solidity
|
|
severity: ERROR
|
|
- id: solidity.security.encode-packed-collision.encode-packed-collision
|
|
message: abi.encodePacked hash collision with variable length arguments in $F()
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-20: Improper Input Validation'
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://swcregistry.io/docs/SWC-133
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/solidity.security.encode-packed-collision.encode-packed-collision
|
|
shortlink: https://sg.run/Gr46
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67648
|
|
rv_id: 946610
|
|
rule_id: nJU47w
|
|
version_id: 8KTKjb1
|
|
url: https://semgrep.dev/playground/r/8KTKjb1/solidity.security.encode-packed-collision.encode-packed-collision
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
function $F(..., bytes $A, ..., bytes $B, ...) public {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $F(..., string $A, ..., string $B, ...) public {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $F(..., bytes $A, ..., string $B, ...) public {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $F(..., string $A, ..., bytes $B, ...) public {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $F(..., address[] $A, ..., address[] $B, ...) public {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $F(..., uint256[] $A, ..., uint256[] $B, ...) public {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $F(..., bytes $A, ..., bytes $B, ...) external {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $F(..., string $A, ..., string $B, ...) external {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $F(..., bytes $A, ..., string $B, ...) external {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $F(..., string $A, ..., bytes $B, ...) external {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $F(..., address[] $A, ..., address[] $B, ...) external {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $F(..., uint256[] $A, ..., uint256[] $B, ...) external {
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern: |
|
|
keccak256(abi.encodePacked(..., $A, $B, ...))
|
|
- pattern: |
|
|
$X = abi.encodePacked(..., $A, $B, ...);
|
|
...
|
|
keccak256($X);
|
|
languages:
|
|
- solidity
|
|
severity: ERROR
|
|
- id: solidity.security.erc677-reentrancy.erc677-reentrancy
|
|
message: ERC677 callAfterTransfer() reentrancy
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow'
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://twitter.com/peckshield/status/1509431646818234369
|
|
- https://twitter.com/blocksecteam/status/1509466576848064512
|
|
- https://explorer.fuse.io/address/0x139Eb08579eec664d461f0B754c1F8B569044611
|
|
- https://explorer.fuse.io/address/0x5De15b5543c178C111915d6B8ae929Af01a8cC58
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.erc677-reentrancy.erc677-reentrancy
|
|
shortlink: https://sg.run/BXnR
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67651
|
|
rv_id: 946613
|
|
rule_id: L1Ub0L
|
|
version_id: 3ZTOPdd
|
|
url: https://semgrep.dev/playground/r/3ZTOPdd/solidity.security.erc677-reentrancy.erc677-reentrancy
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
function transfer(...) {
|
|
...
|
|
}
|
|
- pattern: callAfterTransfer(...);
|
|
languages:
|
|
- solidity
|
|
severity: WARNING
|
|
- id: solidity.security.erc721-reentrancy.erc721-reentrancy
|
|
message: ERC721 onERC721Received() reentrancy
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow'
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://blocksecteam.medium.com/when-safemint-becomes-unsafe-lessons-from-the-hypebears-security-incident-2965209bda2a
|
|
- https://etherscan.io/address/0x14e0a1f310e2b7e321c91f58847e98b8c802f6ef
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.erc721-reentrancy.erc721-reentrancy
|
|
shortlink: https://sg.run/WBoE
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67653
|
|
rv_id: 946615
|
|
rule_id: gxU2qG
|
|
version_id: PkTQZYA
|
|
url: https://semgrep.dev/playground/r/PkTQZYA/solidity.security.erc721-reentrancy.erc721-reentrancy
|
|
origin: community
|
|
patterns:
|
|
- pattern: _checkOnERC721Received(...)
|
|
languages:
|
|
- solidity
|
|
severity: WARNING
|
|
- id: solidity.security.erc777-reentrancy.erc777-reentrancy
|
|
message: ERC777 tokensReceived() reentrancy
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow'
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://mirror.xyz/baconcoin.eth/LHaPiX38mnx8eJ2RVKNXHttHfweQMKNGmEnX4KUksk0
|
|
- https://etherscan.io/address/0xf53f00f844b381963a47fde3325011566870b31f
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.erc777-reentrancy.erc777-reentrancy
|
|
shortlink: https://sg.run/0Jpw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67654
|
|
rv_id: 946616
|
|
rule_id: QrUrJj
|
|
version_id: JdTDyg1
|
|
url: https://semgrep.dev/playground/r/JdTDyg1/solidity.security.erc777-reentrancy.erc777-reentrancy
|
|
origin: community
|
|
patterns:
|
|
- pattern: $X.tokensReceived(...);
|
|
languages:
|
|
- solidity
|
|
severity: WARNING
|
|
- id: solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash
|
|
message: blockhash(block.number) and blockhash(block.number + N) always returns
|
|
0.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-341: Predictable from Observable State'
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://blog.positive.com/predicting-random-numbers-in-ethereum-smart-contracts-e5358c6b8620
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash
|
|
shortlink: https://sg.run/qvPO
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67656
|
|
rv_id: 946618
|
|
rule_id: 4bUPoB
|
|
version_id: GxTP7wj
|
|
url: https://semgrep.dev/playground/r/GxTP7wj/solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: blockhash(block.number)
|
|
- pattern: blockhash(block.number + $N)
|
|
- pattern: blockhash(block.number * $N)
|
|
- pattern: block.blockhash(block.number)
|
|
- pattern: block.blockhash(block.number + $N)
|
|
- pattern: block.blockhash(block.number * $N)
|
|
severity: ERROR
|
|
languages:
|
|
- solidity
|
|
- id: solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation
|
|
message: Keep3rV2.current() call has high data freshness, but it has low security, an
|
|
exploiter simply needs to manipulate 2 data points to be able to impact the feed.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-682: Incorrect Calculation'
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://twitter.com/peckshield/status/1510232640338608131
|
|
- https://twitter.com/FrankResearcher/status/1510239094777032713
|
|
- https://twitter.com/larry0x/status/1510263618180464644
|
|
- https://andrecronje.medium.com/keep3r-network-on-chain-oracle-price-feeds-3c67ed002a9
|
|
- https://etherscan.io/address/0x210ac53b27f16e20a9aa7d16260f84693390258f
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation
|
|
shortlink: https://sg.run/lkEo
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67657
|
|
rv_id: 946619
|
|
rule_id: PeUrYv
|
|
version_id: RGTAgvQ
|
|
url: https://semgrep.dev/playground/r/RGTAgvQ/solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation
|
|
origin: community
|
|
patterns:
|
|
- pattern: $KEEPER.current($TOKENIN, $AMOUNTIN, $TOKENOUT);
|
|
languages:
|
|
- solidity
|
|
severity: WARNING
|
|
- id: solidity.security.no-bidi-characters.no-bidi-characters
|
|
message: The code must not contain any of Unicode Direction Control Characters
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-837: Improper Enforcement of a Single, Unique Action'
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: LOW
|
|
subcategory:
|
|
- audit
|
|
references:
|
|
- https://entethalliance.org/specs/ethtrust-sl/v1/#req-1-unicode-bdo
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.no-bidi-characters.no-bidi-characters
|
|
shortlink: https://sg.run/6DyK
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67659
|
|
rv_id: 946622
|
|
rule_id: 5rUD6Z
|
|
version_id: DkTNp8K
|
|
url: https://semgrep.dev/playground/r/DkTNp8K/solidity.security.no-bidi-characters.no-bidi-characters
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-regex: "\u202A"
|
|
- pattern-regex: "\u202B"
|
|
- pattern-regex: "\u202D"
|
|
- pattern-regex: "\u202E"
|
|
- pattern-regex: "\u2066"
|
|
- pattern-regex: "\u2067"
|
|
- pattern-regex: "\u2068"
|
|
- pattern-regex: "\u202C"
|
|
- pattern-regex: "\u2069"
|
|
languages:
|
|
- solidity
|
|
severity: WARNING
|
|
- id: solidity.security.proxy-storage-collision.proxy-storage-collision
|
|
message: Proxy declares a state var that may override a storage slot of the implementation
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-787: Out-of-bounds Write'
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://blog.audius.co/article/audius-governance-takeover-post-mortem-7-23-22
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.proxy-storage-collision.proxy-storage-collision
|
|
shortlink: https://sg.run/2GXr
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67663
|
|
rv_id: 946626
|
|
rule_id: BYU0EL
|
|
version_id: qkT4jqp
|
|
url: https://semgrep.dev/playground/r/qkT4jqp/solidity.security.proxy-storage-collision.proxy-storage-collision
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
contract $CONTRACT is ..., $PROXY, ... {
|
|
...
|
|
$TYPE $VAR;
|
|
...
|
|
constructor(...) {
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: |
|
|
contract $CONTRACT is ..., $PROXY, ... {
|
|
...
|
|
$TYPE $VAR = ...;
|
|
...
|
|
constructor(...) {
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
contract $CONTRACT is ..., $PROXY, ... {
|
|
$TYPE immutable $VAR;
|
|
...
|
|
constructor(...) {
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
contract $CONTRACT is ..., $PROXY, ... {
|
|
$TYPE immutable $VAR = ...;
|
|
...
|
|
constructor(...) {
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
contract $CONTRACT is ..., $PROXY, ... {
|
|
$TYPE constant $VAR = ...;
|
|
...
|
|
constructor(...) {
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $CONTRACT
|
|
regex: ^(?!AdminUpgradeabilityProxy|OwnedUpgrade*abilityProxy).*$
|
|
- metavariable-regex:
|
|
metavariable: $PROXY
|
|
regex: (UpgradeabilityProxy|AdminUpgradeabilityProxy|OwnedUpgrade*abilityProxy|TransparentUpgradeableProxy|ERC1967Proxy)
|
|
- focus-metavariable: $PROXY
|
|
languages:
|
|
- solidity
|
|
severity: WARNING
|
|
- id: solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug
|
|
message: transferFrom() can steal allowance of other accounts
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-688: Function Call With Incorrect Variable or Reference as Argument'
|
|
confidence: HIGH
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://medium.com/immunefi/redacted-cartel-custom-approval-logic-bugfix-review-9b2d039ca2c5
|
|
- https://etherscan.io/address/0x186E55C0BebD2f69348d94C4A27556d93C5Bd36C
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug
|
|
shortlink: https://sg.run/XDzj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67664
|
|
rv_id: 946627
|
|
rule_id: DbU0Qb
|
|
version_id: l4Tx9Px
|
|
url: https://semgrep.dev/playground/r/l4Tx9Px/solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
function transferFrom(...) {
|
|
...
|
|
}
|
|
- pattern: _approve(..., allowance(sender, recipient).sub(amount, ...), ...);
|
|
languages:
|
|
- solidity
|
|
severity: ERROR
|
|
- id: solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control
|
|
message: setMultipleAllowances() is missing onlyOwner modifier
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-284: Improper Access Control'
|
|
confidence: HIGH
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://twitter.com/danielvf/status/1494317265835147272
|
|
- https://etherscan.io/address/0x876b9ebd725d1fa0b879fcee12560a6453b51dc8
|
|
- https://play.secdim.com/game/dapp/challenge/rigoownsol
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control
|
|
shortlink: https://sg.run/jbZP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67665
|
|
rv_id: 946628
|
|
rule_id: WAUpbw
|
|
version_id: YDTvRP2
|
|
url: https://semgrep.dev/playground/r/YDTvRP2/solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control
|
|
origin: community
|
|
patterns:
|
|
- pattern: function setMultipleAllowances(...) {...}
|
|
- pattern-not: function setMultipleAllowances(...) onlyOwner {...}
|
|
languages:
|
|
- solidity
|
|
severity: ERROR
|
|
- id: solidity.security.superfluid-ctx-injection.superfluid-ctx-injection
|
|
message: A specially crafted calldata may be used to impersonate other accounts
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- solidity
|
|
cwe: 'CWE-20: Improper Input Validation'
|
|
confidence: HIGH
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://rekt.news/superfluid-rekt/
|
|
- https://medium.com/superfluid-blog/08-02-22-exploit-post-mortem-15ff9c97cdd
|
|
- https://polygonscan.com/address/0x07711bb6dfbc99a1df1f2d7f57545a67519941e7
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/solidity.security.superfluid-ctx-injection.superfluid-ctx-injection
|
|
shortlink: https://sg.run/9KNy
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 67667
|
|
rv_id: 946630
|
|
rule_id: KxUqld
|
|
version_id: o5TZexb
|
|
url: https://semgrep.dev/playground/r/o5TZexb/solidity.security.superfluid-ctx-injection.superfluid-ctx-injection
|
|
origin: community
|
|
patterns:
|
|
- pattern: $T.decodeCtx(ctx);
|
|
- pattern-not-inside: |
|
|
require($T.isCtxValid(...), "...");
|
|
...
|
|
languages:
|
|
- solidity
|
|
severity: ERROR
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
provisioner "remote-exec" {
|
|
...
|
|
}
|
|
- pattern: |
|
|
provisioner "local-exec" {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "aws_instance" "..." {
|
|
...
|
|
}
|
|
id: terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec
|
|
message: Provisioners are a tool of last resort and should be avoided where possible.
|
|
Provisioner behavior cannot be mapped by Terraform as part of a plan, and execute
|
|
arbitrary shell commands by design.
|
|
languages:
|
|
- terraform
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A01:2017 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-77: Improper Neutralization of Special Elements used in a Command (''Command
|
|
Injection'')'
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
subcategory:
|
|
- audit
|
|
confidence: HIGH
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
technology:
|
|
- terraform
|
|
references:
|
|
- https://developer.hashicorp.com/terraform/language/resources/provisioners/remote-exec
|
|
- https://developer.hashicorp.com/terraform/language/resources/provisioners/local-exec
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
- Other
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec
|
|
shortlink: https://sg.run/7EjQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 70982
|
|
rv_id: 1263736
|
|
rule_id: EwUxO1
|
|
version_id: bZT53j1
|
|
url: https://semgrep.dev/playground/r/bZT53j1/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec
|
|
origin: community
|
|
- id: clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe
|
|
languages:
|
|
- clojure
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://xerces.apache.org/xerces2-j/features.html
|
|
source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/xxe-clojure-xml/xxe-clojure-xml.yml
|
|
category: security
|
|
technology:
|
|
- clojure
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe
|
|
shortlink: https://sg.run/v7An
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 71533
|
|
rv_id: 1262608
|
|
rule_id: bwU3Gj
|
|
version_id: WrTqKyD
|
|
url: https://semgrep.dev/playground/r/WrTqKyD/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe
|
|
origin: community
|
|
message: DOCTYPE declarations are enabled for javax.xml.parsers.SAXParserFactory.
|
|
Without prohibiting external entity declarations, this is vulnerable to XML external
|
|
entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl"
|
|
to true. Alternatively, allow DOCTYPE declarations and only prohibit external
|
|
entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities"
|
|
and "http://xml.org/sax/features/external-parameter-entities" to false.
|
|
patterns:
|
|
- pattern-inside: |
|
|
(ns ... (:require [clojure.xml :as ...]))
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
(def ... ... ( ... ))
|
|
- pattern-inside: |
|
|
(defn ... ... ( ... ))
|
|
- pattern-either:
|
|
- pattern: (clojure.xml/parse $INPUT)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
(doto (javax.xml.parsers.SAXParserFactory/newInstance) ...)
|
|
- pattern: (.setFeature "http://apache.org/xml/features/disallow-doctype-decl"
|
|
false)
|
|
- pattern-not-inside: |
|
|
(doto (javax.xml.parsers.SAXParserFactory/newInstance)
|
|
...
|
|
(.setFeature "http://xml.org/sax/features/external-general-entities" false)
|
|
...
|
|
(.setFeature "http://xml.org/sax/features/external-parameter-entities" false)
|
|
...)
|
|
- pattern-not-inside: |
|
|
(doto (javax.xml.parsers.SAXParserFactory/newInstance)
|
|
...
|
|
(.setFeature "http://xml.org/sax/features/external-parameter-entities" false)
|
|
...
|
|
(.setFeature "http://xml.org/sax/features/external-general-entities" false)
|
|
...)
|
|
- id: clojure.lang.security.use-of-sha1.use-of-sha1
|
|
languages:
|
|
- clojure
|
|
severity: WARNING
|
|
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
|
|
collision resistant and is therefore not suitable as a cryptographic signature.
|
|
Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function
|
|
applications.
|
|
metadata:
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
|
|
technology:
|
|
- clojure
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
- 'CWE-328: Use of Weak Hash'
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/clojure.lang.security.use-of-sha1.use-of-sha1
|
|
shortlink: https://sg.run/dvwX
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 71534
|
|
rv_id: 1262610
|
|
rule_id: NbUy12
|
|
version_id: K3TKk7E
|
|
url: https://semgrep.dev/playground/r/K3TKk7E/clojure.lang.security.use-of-sha1.use-of-sha1
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: (MessageDigest/getInstance $ALGO)
|
|
- pattern: (java.security.MessageDigest/getInstance $ALGO)
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: (((org\.apache\.commons\.codec\.digest\.)?MessageDigestAlgorithms/)?"?(SHA-1|SHA1)"?)
|
|
- id: generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute
|
|
languages:
|
|
- generic
|
|
severity: INFO
|
|
message: Visualforce Pages must have the cspHeader attribute set to true. This attribute
|
|
is available in API version 55 or higher.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://help.salesforce.com/s/articleView?id=sf.csp_trusted_sites.htm&type=5
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- salesforce
|
|
- visualforce
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute
|
|
shortlink: https://sg.run/yoj8
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 72424
|
|
rv_id: 1262907
|
|
rule_id: DbUj7d
|
|
version_id: RGT0L0r
|
|
url: https://semgrep.dev/playground/r/RGT0L0r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute
|
|
origin: community
|
|
patterns:
|
|
- pattern: <apex:page...>...</apex:page>
|
|
- pattern-not: <apex:page...cspHeader="true"...>...</apex:page>
|
|
- pattern-not: <apex:page...>...<!--deprecated-->...</apex:page>
|
|
- pattern-not: <apex:page...>...<!-- deprecated -->...</apex:page>
|
|
paths:
|
|
include:
|
|
- '*.page'
|
|
- id: generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
message: Visualforce Pages must use API version 55 or higher for required use of
|
|
the cspHeader attribute set to true.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://developer.salesforce.com/docs/atlas.en-us.api_meta.meta/api_meta/meta_pages.htm
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- salesforce
|
|
- visualforce
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version
|
|
shortlink: https://sg.run/rWr6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 72425
|
|
rv_id: 1262908
|
|
rule_id: WAUwJW
|
|
version_id: A8Tgdgn
|
|
url: https://semgrep.dev/playground/r/A8Tgdgn/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: <apiVersion.../apiVersion>
|
|
- pattern-either:
|
|
- pattern-regex: '[>][0-9].[0-9][<]'
|
|
- pattern-regex: '[>][1-4][0-9].[0-9][<]'
|
|
- pattern-regex: '[>][5][0-4].[0-9][<]'
|
|
paths:
|
|
include:
|
|
- '*.page-meta.xml'
|
|
- id: python.django.security.hashids-with-django-secret.hashids-with-django-secret
|
|
languages:
|
|
- python
|
|
message: The Django secret key is used as salt in HashIDs. The HashID mechanism
|
|
is not secure. By observing sufficient HashIDs, the salt used to construct them
|
|
can be recovered. This means the Django secret key can be obtained by attackers,
|
|
through the HashIDs.
|
|
metadata:
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- "A02:2021 \u2013 Cryptographic Failures"
|
|
references:
|
|
- https://docs.djangoproject.com/en/4.2/ref/settings/#std-setting-SECRET_KEY
|
|
- http://carnage.github.io/2015/08/cryptanalysis-of-hashids
|
|
technology:
|
|
- django
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.django.security.hashids-with-django-secret.hashids-with-django-secret
|
|
shortlink: https://sg.run/bxeZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 72426
|
|
rv_id: 946163
|
|
rule_id: 0oUXqy
|
|
version_id: 0bT15nn
|
|
url: https://semgrep.dev/playground/r/0bT15nn/python.django.security.hashids-with-django-secret.hashids-with-django-secret
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: hashids.Hashids(..., salt=django.conf.settings.SECRET_KEY, ...)
|
|
- pattern: hashids.Hashids(django.conf.settings.SECRET_KEY, ...)
|
|
severity: ERROR
|
|
- id: python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret
|
|
languages:
|
|
- python
|
|
message: The Flask secret key is used as salt in HashIDs. The HashID mechanism is
|
|
not secure. By observing sufficient HashIDs, the salt used to construct them can
|
|
be recovered. This means the Flask secret key can be obtained by attackers, through
|
|
the HashIDs.
|
|
metadata:
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- "A02:2021 \u2013 Cryptographic Failures"
|
|
references:
|
|
- https://flask.palletsprojects.com/en/2.2.x/config/#SECRET_KEY
|
|
- http://carnage.github.io/2015/08/cryptanalysis-of-hashids
|
|
technology:
|
|
- flask
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret
|
|
shortlink: https://sg.run/N0Rx
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 72427
|
|
rv_id: 946220
|
|
rule_id: KxUX3z
|
|
version_id: 0bT15Px
|
|
url: https://semgrep.dev/playground/r/0bT15Px/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: hashids.Hashids(..., salt=flask.current_app.config['SECRET_KEY'], ...)
|
|
- pattern: hashids.Hashids(flask.current_app.config['SECRET_KEY'], ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$APP = flask.Flask(...)
|
|
...
|
|
- pattern-either:
|
|
- pattern: hashids.Hashids(..., salt=$APP.config['SECRET_KEY'], ...)
|
|
- pattern: hashids.Hashids($APP.config['SECRET_KEY'], ...)
|
|
severity: ERROR
|
|
- id: yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions
|
|
patterns:
|
|
- pattern: |
|
|
"*"
|
|
- pattern-inside: |
|
|
resources: $A
|
|
...
|
|
- pattern-inside: |
|
|
verbs: $A
|
|
...
|
|
- pattern-inside: |
|
|
- apiGroups: [""]
|
|
...
|
|
- pattern-inside: |
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
...
|
|
- pattern-inside: |
|
|
kind: ClusterRole
|
|
...
|
|
message: 'Semgrep detected a Kubernetes core API ClusterRole with excessive permissions.
|
|
Attaching excessive permissions to a ClusterRole associated with the core namespace
|
|
allows the V1 API to perform arbitrary actions on arbitrary resources attached
|
|
to the cluster. Prefer explicit allowlists of verbs/resources when configuring
|
|
the core API namespace. '
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-269: Improper Privilege Management'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A06:2017 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://kubernetes.io/docs/reference/access-authn-authz/rbac/#role-and-clusterrole
|
|
- https://kubernetes.io/docs/concepts/security/rbac-good-practices/#general-good-practice
|
|
- https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#api-groups
|
|
category: security
|
|
technology:
|
|
- kubernetes
|
|
cwe2021-top25: false
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions
|
|
shortlink: https://sg.run/x6Dz
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 73474
|
|
rv_id: 1263935
|
|
rule_id: GdUR2A
|
|
version_id: 9lT4bw7
|
|
url: https://semgrep.dev/playground/r/9lT4bw7/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions
|
|
origin: community
|
|
- id: go.lang.security.injection.open-redirect.open-redirect
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
message: An HTTP redirect was found to be crafted from user-input `$REQUEST`. This
|
|
can lead to open redirect vulnerabilities, potentially allowing attackers to redirect
|
|
users to malicious web sites. It is recommend where possible to not allow user-input
|
|
to craft the redirect URL. When user-input is necessary to craft the request,
|
|
it is recommended to follow OWASP best practices to restrict the URL to domains
|
|
in an allowlist.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
|
|
references:
|
|
- https://knowledge-base.secureflag.com/vulnerabilities/unvalidated_redirects___forwards/open_redirect_go_lang.html
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
description: An HTTP redirect was found to be crafted from user-input leading
|
|
to an open redirect vulnerability
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Open Redirect
|
|
source: https://semgrep.dev/r/go.lang.security.injection.open-redirect.open-redirect
|
|
shortlink: https://sg.run/2ZW45
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 113619
|
|
rv_id: 945608
|
|
rule_id: DbU6RlN
|
|
version_id: GxTP7J7
|
|
url: https://semgrep.dev/playground/r/GxTP7J7/go.lang.security.injection.open-redirect.open-redirect
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- label: INPUT
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
($REQUEST : *http.Request).$ANYTHING
|
|
- pattern: |
|
|
($REQUEST : http.Request).$ANYTHING
|
|
- metavariable-regex:
|
|
metavariable: $ANYTHING
|
|
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
|
|
- label: CLEAN
|
|
requires: INPUT
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$URLSTR" + $INPUT
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...)
|
|
- pattern: fmt.Sprintf("$URLSTR", $INPUT, ...)
|
|
- pattern: fmt.Printf("$URLSTR", $INPUT, ...)
|
|
- metavariable-regex:
|
|
metavariable: $URLSTR
|
|
regex: .*//[a-zA-Z0-10]+\..*
|
|
pattern-sinks:
|
|
- requires: INPUT and not CLEAN
|
|
patterns:
|
|
- pattern: http.Redirect($W, $REQ, $URL, ...)
|
|
- focus-metavariable: $URL
|
|
- id: php.lang.security.base-convert-loses-precision.base-convert-loses-precision
|
|
message: The function base_convert uses 64-bit numbers internally, and does not
|
|
correctly convert large numbers. It is not suitable for random tokens such as
|
|
those used for session tokens or CSRF tokens.
|
|
metadata:
|
|
references:
|
|
- https://www.php.net/base_convert
|
|
- https://www.sjoerdlangkemper.nl/2017/03/15/dont-use-base-convert-on-random-tokens/
|
|
category: security
|
|
technology:
|
|
- php
|
|
cwe:
|
|
- 'CWE-190: Integer Overflow or Wraparound'
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/php.lang.security.base-convert-loses-precision.base-convert-loses-precision
|
|
shortlink: https://sg.run/kxpGo
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 115928
|
|
rv_id: 945988
|
|
rule_id: 7KUgBAk
|
|
version_id: yeT0n4K
|
|
url: https://semgrep.dev/playground/r/yeT0n4K/php.lang.security.base-convert-loses-precision.base-convert-loses-precision
|
|
origin: community
|
|
languages:
|
|
- php
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: hash(...)
|
|
- pattern: hash_hmac(...)
|
|
- pattern: sha1(...)
|
|
- pattern: md5(...)
|
|
- patterns:
|
|
- pattern: random_bytes($N)
|
|
- metavariable-comparison:
|
|
metavariable: $N
|
|
comparison: $N > 7
|
|
- patterns:
|
|
- pattern: openssl_random_pseudo_bytes($N)
|
|
- metavariable-comparison:
|
|
metavariable: $N
|
|
comparison: $N > 7
|
|
- patterns:
|
|
- pattern: $OBJ->get_random_bytes($N)
|
|
- metavariable-comparison:
|
|
metavariable: $N
|
|
comparison: $N > 7
|
|
pattern-sinks:
|
|
- pattern: base_convert(...)
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: substr(..., $LENGTH)
|
|
- metavariable-comparison:
|
|
metavariable: $LENGTH
|
|
comparison: $LENGTH <= 7
|
|
- id: javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify
|
|
message: Detected the decoding of a JWT token without a verify step. JWT tokens
|
|
must be verified before use, otherwise the token's integrity is unknown. This
|
|
means a malicious actor could forge a JWT token with any claims. Set 'verify'
|
|
to `true` before using the token.
|
|
severity: ERROR
|
|
metadata:
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A02:2025 - Security Misconfiguration
|
|
- A07:2025 - Authentication Failures
|
|
cwe:
|
|
- 'CWE-287: Improper Authentication'
|
|
- 'CWE-345: Insufficient Verification of Data Authenticity'
|
|
- 'CWE-347: Improper Verification of Cryptographic Signature'
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- jwt-simple
|
|
- jwt
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
references:
|
|
- https://www.npmjs.com/package/jwt-simple
|
|
- https://cwe.mitre.org/data/definitions/287
|
|
- https://cwe.mitre.org/data/definitions/345
|
|
- https://cwe.mitre.org/data/definitions/347
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify
|
|
shortlink: https://sg.run/zdjod
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 120561
|
|
rv_id: 1263191
|
|
rule_id: r6UyNLy
|
|
version_id: 3ZT4Xxv
|
|
url: https://semgrep.dev/playground/r/3ZT4Xxv/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
patterns:
|
|
- pattern-inside: |
|
|
$JWT = require('jwt-simple');
|
|
...
|
|
- pattern: $JWT.decode($TOKEN, $SECRET, $NOVERIFY, ...)
|
|
- metavariable-pattern:
|
|
metavariable: $NOVERIFY
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
true
|
|
- pattern: |
|
|
"..."
|
|
- id: solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx
|
|
languages:
|
|
- solidity
|
|
message: Missing check for 'from' and 'to' being the same before updating balances
|
|
could lead to incorrect balance manipulation on self-transfers. Include a check
|
|
to ensure 'from' and 'to' are not the same before updating balances to prevent
|
|
balance manipulation during self-transfers.
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- blockchain
|
|
- solidity
|
|
cwe: 'CWE-682: Incorrect Calculation'
|
|
subcategory:
|
|
- vuln
|
|
confidence: HIGH
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
owasp:
|
|
- A7:2021 Identification and Authentication Failures
|
|
references:
|
|
- https://blog.verichains.io/p/miner-project-attacked-by-vulnerabilities
|
|
- https://x.com/shoucccc/status/1757777764646859121
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx
|
|
shortlink: https://sg.run/Or6X7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 133075
|
|
rv_id: 946620
|
|
rule_id: 6JUv7Nz
|
|
version_id: A8TJzYz
|
|
url: https://semgrep.dev/playground/r/A8TJzYz/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
_balances[$FROM] = $FROM_BALANCE - value;
|
|
- pattern: |
|
|
_balances[$TO] = $TO_BALANCE + value;
|
|
- pattern-not-inside: |
|
|
if ($FROM != $TO) {
|
|
...
|
|
_balances[$FROM] = $FROM_BALANCE - value;
|
|
...
|
|
_balances[$TO] = $TO_BALANCE + value;
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function _update(address $FROM, address $TO, uint256 value, bool mint) internal virtual {
|
|
...
|
|
}
|
|
- id: yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication
|
|
languages:
|
|
- yaml
|
|
message: Basic authentication is considered weak and should be avoided. Use a different
|
|
authentication scheme, such of OAuth2, OpenID Connect, or mTLS.
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-inside: |
|
|
openapi: $VERSION
|
|
...
|
|
components:
|
|
...
|
|
securitySchemes:
|
|
...
|
|
$SCHEME:
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $VERSION
|
|
regex: 3.*
|
|
- pattern: |
|
|
type: http
|
|
...
|
|
scheme: basic
|
|
metadata:
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- openapi
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
cwe: 'CWE-287: Improper Authentication'
|
|
owasp:
|
|
- A04:2021 Insecure Design
|
|
- A07:2021 Identification and Authentication Failures
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/287.html
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design/
|
|
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication
|
|
shortlink: https://sg.run/v8wNW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 133077
|
|
rv_id: 947072
|
|
rule_id: zdUKgEX
|
|
version_id: 0bT1ErG
|
|
url: https://semgrep.dev/playground/r/0bT1ErG/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication
|
|
origin: community
|
|
- id: generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token
|
|
pattern-regex: (?:api_live(?:_[a-zA-Z]{2})?\.[a-zA-Z0-9-_]{11}\.[-_a-zA-Z0-9]{32})
|
|
languages:
|
|
- regex
|
|
message: Onfido live API Token detected
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
category: security
|
|
technology:
|
|
- secrets
|
|
- onfido
|
|
confidence: HIGH
|
|
references:
|
|
- https://documentation.onfido.com/api/latest/#api-tokens
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token
|
|
shortlink: https://sg.run/lBoKD
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 141957
|
|
rv_id: 945509
|
|
rule_id: WAUW9q3
|
|
version_id: A8TJzE2
|
|
url: https://semgrep.dev/playground/r/A8TJzE2/generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token
|
|
origin: community
|
|
- id: dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount
|
|
message: The Dockerfile(image) mounts docker.sock to the container which may allow
|
|
an attacker already inside of the container to escape container and execute arbitrary
|
|
commands on the host machine.
|
|
languages:
|
|
- dockerfile
|
|
- yaml
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-862: Missing Authorization'
|
|
- 'CWE-269: Improper Privilege Management'
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
technology:
|
|
- dockerfile
|
|
category: security
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html
|
|
- https://redfoxsec.com/blog/insecure-volume-mounts-in-docker/
|
|
- https://blog.quarkslab.com/why-is-exposing-the-docker-socket-a-really-bad-idea.html
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount
|
|
shortlink: https://sg.run/10AAQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 146566
|
|
rv_id: 945266
|
|
rule_id: oqUgAAk
|
|
version_id: WrTEoEq
|
|
url: https://semgrep.dev/playground/r/WrTEoEq/dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount
|
|
origin: community
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: VOLUME $X
|
|
- metavariable-regex:
|
|
metavariable: $X
|
|
regex: /var/run/docker.sock
|
|
- patterns:
|
|
- pattern-regex: '- "/var/run/docker.sock:.*"'
|
|
- pattern-inside: |
|
|
volumes:
|
|
...
|
|
- id: javascript.node-crypto.security.aead-no-final.aead-no-final
|
|
message: The 'final' call of a Decipher object checks the authentication tag in
|
|
a mode for authenticated encryption. Failing to call 'final' will invalidate all
|
|
integrity guarantees of the released ciphertext.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-310: CWE CATEGORY: Cryptographic Issues'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- node-crypto
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
references:
|
|
- https://nodejs.org/api/crypto.html#deciphersetauthtagbuffer-encoding
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures/
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.node-crypto.security.aead-no-final.aead-no-final
|
|
shortlink: https://sg.run/r6EEA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 146569
|
|
rv_id: 1263222
|
|
rule_id: 2ZUz884
|
|
version_id: zyTb2X0
|
|
url: https://semgrep.dev/playground/r/zyTb2X0/javascript.node-crypto.security.aead-no-final.aead-no-final
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern: |
|
|
$DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...)
|
|
...
|
|
$DECIPHER.update(...)
|
|
- pattern-not-inside: |
|
|
$DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...)
|
|
...
|
|
$DECIPHER.final(...)
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: .*(-gcm|-ccm|-ocb|chacha20-poly1305)$
|
|
- id: javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv
|
|
message: The deprecated functions 'createCipher' and 'createDecipher' generate the
|
|
same initialization vector every time. For counter modes such as CTR, GCM, or
|
|
CCM this leads to break of both confidentiality and integrity, if the key is used
|
|
more than once. Other modes are still affected in their strength, though they're
|
|
not completely broken. Use 'createCipheriv' or 'createDecipheriv' instead.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1204: Generation of Weak Initialization Vector (IV)'
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- node-crypto
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
references:
|
|
- https://nodejs.org/api/crypto.html#cryptocreatecipheralgorithm-password-options
|
|
- https://nodejs.org/api/crypto.html#cryptocreatedecipheralgorithm-password-options
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv
|
|
shortlink: https://sg.run/bw33r
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 146570
|
|
rv_id: 945898
|
|
rule_id: X5UQRR7
|
|
version_id: ZRT3510
|
|
url: https://semgrep.dev/playground/r/ZRT3510/javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$CRYPTO.createCipher(...)
|
|
- pattern: |
|
|
$CRYPTO.createDecipher(...)
|
|
- id: yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false
|
|
languages:
|
|
- yaml
|
|
message: 'Found ''x-openai-isConsequential: false'' in a state-changing HTTP method:
|
|
$METHOD $PATH. This Action configuration will enable the ''Always Allow'' option
|
|
for state-changing HTTP methods, such as POST, PUT, PATCH, or DELETE. The risk
|
|
of a user selecting the ''Always Allow'' button is that the agent could perform
|
|
unintended actions on behalf of the user. When working with sensitive functionality,
|
|
it is always best to include a Human In The Loop (HITL) type of control. Consider
|
|
the trade-off between security and user friction and then make a risk-based decision
|
|
about this function.'
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern-inside: |
|
|
post:
|
|
...
|
|
x-openai-isConsequential: false
|
|
- pattern-inside: |
|
|
put:
|
|
...
|
|
x-openai-isConsequential: false
|
|
- pattern-inside: |
|
|
patch:
|
|
...
|
|
x-openai-isConsequential: false
|
|
- pattern-inside: |
|
|
delete:
|
|
...
|
|
x-openai-isConsequential: false
|
|
metadata:
|
|
category: security
|
|
subcategory:
|
|
- audit
|
|
technology:
|
|
- openapi
|
|
- openai
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
cwe: 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')'
|
|
owasp:
|
|
- A04:2021 Insecure Design
|
|
- LLM08:2023 - Excessive Agency
|
|
references:
|
|
- https://platform.openai.com/docs/actions/consequential-flag
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design/
|
|
- https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false
|
|
shortlink: https://sg.run/x8EEP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 146574
|
|
rv_id: 947071
|
|
rule_id: yyURooD
|
|
version_id: WrTEZN8
|
|
url: https://semgrep.dev/playground/r/WrTEZN8/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false
|
|
origin: community
|
|
- id: go.lang.security.audit.crypto.sha224-hash.sha224-hash
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import "crypto/sha256"
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
sha256.New224()
|
|
- pattern: |
|
|
sha256.Sum224(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import "golang.org/x/crypto/sha3"
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
sha3.New224()
|
|
- pattern: |
|
|
sha3.Sum224(...)
|
|
message: This code uses a 224-bit hash function, which is deprecated or disallowed
|
|
in some security policies. Consider updating to a stronger hash function such
|
|
as SHA-384 or higher to ensure compliance and security.
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
category: security
|
|
technology:
|
|
- go
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
|
|
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.sha224-hash.sha224-hash
|
|
shortlink: https://sg.run/ReJwY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 151749
|
|
rv_id: 1262925
|
|
rule_id: GdUvElR
|
|
version_id: 9lT4b4w
|
|
url: https://semgrep.dev/playground/r/9lT4b4w/go.lang.security.audit.crypto.sha224-hash.sha224-hash
|
|
origin: community
|
|
- id: java.lang.security.audit.crypto.use-of-sha224.use-of-sha224
|
|
message: This code uses a 224-bit hash function, which is deprecated or disallowed
|
|
in some security policies. Consider updating to a stronger hash function such
|
|
as SHA-384 or higher to ensure compliance and security.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::javax.crypto
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
|
|
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224
|
|
shortlink: https://sg.run/Ab2KQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 151750
|
|
rv_id: 1263017
|
|
rule_id: ReUDGEz
|
|
version_id: YDTZewo
|
|
url: https://semgrep.dev/playground/r/YDTZewo/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.getSha3_224Digest()
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.getSha512_224Digest()
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224(...)
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224Hex(...)
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224(...)
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224Hex(...)
|
|
- pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_224)
|
|
- pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_512_224)
|
|
- pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA3_224)
|
|
- patterns:
|
|
- pattern: java.security.MessageDigest.getInstance("$ALGO", ...);
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: .*224
|
|
- id: php.lang.security.audit.sha224-hash.sha224-hash
|
|
pattern-either:
|
|
- pattern: hash('sha224', ...);
|
|
- pattern: hash('sha512/224', ...);
|
|
- pattern: hash('sha3-224', ...);
|
|
- pattern: hash_hmac('sha224', ...);
|
|
- pattern: hash_hmac('sha512/224', ...);
|
|
- pattern: hash_hmac('sha3-224', ...);
|
|
message: This code uses a 224-bit hash function, which is deprecated or disallowed
|
|
in some security policies. Consider updating to a stronger hash function such
|
|
as SHA-384 or higher to ensure compliance and security.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
|
|
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
|
|
category: security
|
|
technology:
|
|
- php
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/php.lang.security.audit.sha224-hash.sha224-hash
|
|
shortlink: https://sg.run/BYXqv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 151751
|
|
rv_id: 1263275
|
|
rule_id: AbU97EA
|
|
version_id: bZT53Jo
|
|
url: https://semgrep.dev/playground/r/bZT53Jo/php.lang.security.audit.sha224-hash.sha224-hash
|
|
origin: community
|
|
languages:
|
|
- php
|
|
severity: WARNING
|
|
- id: python.lang.security.audit.sha224-hash.sha224-hash
|
|
message: This code uses a 224-bit hash function, which is deprecated or disallowed
|
|
in some security policies. Consider updating to a stronger hash function such
|
|
as SHA-384 or higher to ensure compliance and security.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
|
|
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
|
|
category: security
|
|
technology:
|
|
- python
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.lang.security.audit.sha224-hash.sha224-hash
|
|
shortlink: https://sg.run/Db1Yv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 151752
|
|
rv_id: 1263511
|
|
rule_id: BYUX0y9
|
|
version_id: 5PTo1QL
|
|
url: https://semgrep.dev/playground/r/5PTo1QL/python.lang.security.audit.sha224-hash.sha224-hash
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: hashlib.sha224(...)
|
|
- pattern: hashlib.sha3_224(...)
|
|
- id: ruby.lang.security.audit.sha224-hash.sha224-hash
|
|
message: This code uses a 224-bit hash function, which is deprecated or disallowed
|
|
in some security policies. Consider updating to a stronger hash function such
|
|
as SHA-384 or higher to ensure compliance and security.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
|
|
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
|
|
category: security
|
|
technology:
|
|
- ruby
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/ruby.lang.security.audit.sha224-hash.sha224-hash
|
|
shortlink: https://sg.run/WABbo
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 151753
|
|
rv_id: 1263592
|
|
rule_id: DbU60wQ
|
|
version_id: 8KT5rRY
|
|
url: https://semgrep.dev/playground/r/8KT5rRY/ruby.lang.security.audit.sha224-hash.sha224-hash
|
|
origin: community
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern: Digest::SHA224.$FUNC
|
|
- pattern: OpenSSL::Digest::SHA224.$FUNC
|
|
- pattern: SHA3::Digest::SHA224(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: OpenSSL::HMAC.hexdigest("$ALGO", ...)
|
|
- pattern: OpenSSL::HMAC.digest("$ALGO", ...)
|
|
- pattern: OpenSSL::HMAC.new($KEY, "$ALGO")
|
|
- pattern: OpenSSL::Digest.digest("$ALGO", ...)
|
|
- pattern: OpenSSL::Digest.new("$ALGO", ...)
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: .*224
|
|
- id: python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true
|
|
message: Function `flask.url_for` with `_external=True` argument will generate URLs
|
|
using the `Host` header of the HTTP request, which may lead to security risks
|
|
such as Host header injection
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-673: External Influence of Sphere Definition'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- flask
|
|
references:
|
|
- https://flask.palletsprojects.com/en/latest/api/#flask.url_for
|
|
- https://portswigger.net/kb/issues/00500300_host-header-injection
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true
|
|
shortlink: https://sg.run/gEGeR
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 191541
|
|
rv_id: 1263418
|
|
rule_id: JDU5oql
|
|
version_id: K3TKk6n
|
|
url: https://semgrep.dev/playground/r/K3TKk6n/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-not: flask.url_for(..., _external=False, ...)
|
|
- pattern-not: url_for(..., _external=False, ...)
|
|
- pattern-either:
|
|
- pattern: flask.url_for(..., _external=$VAR, ...)
|
|
- pattern: url_for(..., _external=$VAR, ...)
|
|
- id: yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor
|
|
languages:
|
|
- yaml
|
|
message: The Shai-hulud backdoor creates a purposefully vulnerable github action
|
|
with the name `discussion.yaml`.
|
|
paths:
|
|
include:
|
|
- '**/.github/workflows/discussion.yaml'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-509: Replicating Malicious Code (Virus or Worm)'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
technology:
|
|
- github-actions
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source_rule_url: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack
|
|
references:
|
|
- https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor
|
|
shortlink: https://sg.run/JdYPZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 238946
|
|
rv_id: 1263927
|
|
rule_id: 7KUDRPj
|
|
version_id: 6xT29ol
|
|
url: https://semgrep.dev/playground/r/6xT29ol/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: 'steps: [...]'
|
|
- pattern-inside: |
|
|
- run: ...
|
|
...
|
|
- pattern: 'run: $SHELL'
|
|
- metavariable-pattern:
|
|
language: generic
|
|
metavariable: $SHELL
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: ${{ github.event.issue.title }}
|
|
- pattern: ${{ github.event.issue.body }}
|
|
- pattern: ${{ github.event.pull_request.title }}
|
|
- pattern: ${{ github.event.pull_request.body }}
|
|
- pattern: ${{ github.event.comment.body }}
|
|
- pattern: ${{ github.event.review.body }}
|
|
- pattern: ${{ github.event.review_comment.body }}
|
|
- pattern: ${{ github.event.pages. ... .page_name}}
|
|
- pattern: ${{ github.event.head_commit.message }}
|
|
- pattern: ${{ github.event.head_commit.author.email }}
|
|
- pattern: ${{ github.event.head_commit.author.name }}
|
|
- pattern: ${{ github.event.commits ... .author.email }}
|
|
- pattern: ${{ github.event.commits ... .author.name }}
|
|
- pattern: ${{ github.event.pull_request.head.ref }}
|
|
- pattern: ${{ github.event.pull_request.head.label }}
|
|
- pattern: ${{ github.event.pull_request.head.repo.default_branch }}
|
|
- pattern: ${{ github.head_ref }}
|
|
- pattern: ${{ github.event.inputs ... }}
|
|
- pattern: ${{ github.event.discussion.title }}
|
|
- pattern: ${{ github.event.discussion.body }}
|
|
- pattern: ${{ inputs ... }}
|
|
severity: ERROR
|
|
- id: go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface
|
|
languages:
|
|
- go
|
|
message: Deserializing into `interface{}` allows arbitrary data structures and types,
|
|
which can lead to security vulnerabilities (CWE-502). Use a concrete struct type
|
|
instead.
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/502.html
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface
|
|
shortlink: https://sg.run/6WbKL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 274359
|
|
rv_id: 1409387
|
|
rule_id: 4bUAQDG
|
|
version_id: ZRTDkjk
|
|
url: https://semgrep.dev/playground/r/ZRTDkjk/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
var $VAR interface{}
|
|
...
|
|
json.Unmarshal($DATA, &$VAR)
|
|
- pattern: |
|
|
var $VAR interface{}
|
|
...
|
|
yaml.Unmarshal($DATA, &$VAR)
|
|
- pattern: |
|
|
var $VAR interface{}
|
|
...
|
|
xml.Unmarshal($DATA, &$VAR)
|
|
- id: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
|
|
message: "GitHub Actions step uses a mutable tag or branch reference. Tags and branch
|
|
names can be silently repointed by the action owner, enabling supply-chain attacks
|
|
\u2014 as seen in the trivy-action and kics-github-action compromises. Pin the
|
|
reference to a full 40-character commit SHA instead, e.g. `uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`."
|
|
severity: WARNING
|
|
languages:
|
|
- yaml
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-1357: Reliance on Insufficiently Trustworthy Component'
|
|
- 'CWE-353: Missing Support for Integrity Check'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software and Data Integrity Failures
|
|
references:
|
|
- https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions
|
|
technology:
|
|
- github-actions
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
- Other
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
|
|
shortlink: https://sg.run/2LgAL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 288863
|
|
rv_id: 1413422
|
|
rule_id: GdUxYDx
|
|
version_id: xyTRDAd
|
|
url: https://semgrep.dev/playground/r/xyTRDAd/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: '{steps: ...}'
|
|
- pattern: |
|
|
uses: "$ACTION"
|
|
- metavariable-pattern:
|
|
metavariable: $ACTION
|
|
language: generic
|
|
patterns:
|
|
- pattern-not-regex: ^\./
|
|
- pattern-not-regex: ^docker://
|
|
- pattern-not-regex: '@[0-9a-f]{40}(\s|$)'
|
|
- id: yaml.github-actions.security.secrets-inherit.secrets-inherit
|
|
languages:
|
|
- yaml
|
|
severity: ERROR
|
|
message: 'This workflow uses `secrets: inherit` to pass all of the calling workflow''s
|
|
secrets to a reusable workflow. This violates the principle of least privilege
|
|
because the called workflow receives access to every secret in the repository,
|
|
not just the ones it needs. If the called workflow is compromised or sourced from
|
|
a third party, an attacker gains access to all repository secrets. Instead, explicitly
|
|
pass only the secrets that the called workflow requires using the `secrets:` map,
|
|
e.g. `secrets: { MY_SECRET: ${{ secrets.MY_SECRET }} }`.'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-250: Execution with Unnecessary Privileges'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://docs.github.com/en/actions/sharing-automations/reusing-workflows#passing-inputs-and-secrets-to-a-reusable-workflow
|
|
- https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions
|
|
technology:
|
|
- github-actions
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.secrets-inherit.secrets-inherit
|
|
shortlink: https://sg.run/X2PZB
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 288864
|
|
rv_id: 1413424
|
|
rule_id: ReUQnKg
|
|
version_id: e1T42L1
|
|
url: https://semgrep.dev/playground/r/e1T42L1/yaml.github-actions.security.secrets-inherit.secrets-inherit
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
jobs:
|
|
...
|
|
- pattern: 'secrets: inherit'
|
|
- id: package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)\[install\](?P<TARGET>[^\[]*?)(?=\[|\z)
|
|
- metavariable-regex:
|
|
metavariable: $TARGET
|
|
regex: ^(?![\s\S]*minimumReleaseAge)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern-regex: minimumReleaseAge\s*=\s*\d+
|
|
- pattern-regex: =\s*(?P<AGE>\d+)
|
|
- metavariable-comparison:
|
|
metavariable: $AGE
|
|
comparison: int($AGE) < 604800
|
|
- focus-metavariable: $AGE
|
|
- patterns:
|
|
- pattern-regex: (?m)minimumReleaseAge[ \t]*=[ \t]*(?P<VAL>[^\s\d][^\n]*)
|
|
- focus-metavariable: $VAL
|
|
- patterns:
|
|
- pattern-regex: (?m)minimumReleaseAge\s*=\s*$
|
|
message: 'This bunfig.toml does not set a minimum release age or sets it too low.
|
|
Newly published packages can be malicious or unstable. Add `minimumReleaseAge
|
|
= 604800` under the `[install]` section to wait 7 days before resolving newly
|
|
published package versions. Added in: v1.3 Reference: https://bun.sh/docs/runtime/bunfig'
|
|
languages:
|
|
- generic
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/bunfig.toml'
|
|
- '**/.bunfig.toml'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- bun
|
|
- javascript
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://bun.sh/docs/runtime/bunfig
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age
|
|
shortlink: https://sg.run/JqPrR
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291646
|
|
rv_id: 1423385
|
|
rule_id: oqUyJOb
|
|
version_id: BjTyRe5
|
|
url: https://semgrep.dev/playground/r/BjTyRe5/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age
|
|
origin: community
|
|
- id: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
updates:
|
|
...
|
|
- pattern: |
|
|
- package-ecosystem: $ECOSYSTEM
|
|
...
|
|
- pattern-not: |
|
|
- package-ecosystem: $ECOSYSTEM
|
|
...
|
|
cooldown:
|
|
...
|
|
...
|
|
- patterns:
|
|
- pattern-inside: |
|
|
updates:
|
|
...
|
|
- pattern-regex: default-days\s*:\s*(?P<DAYS>\d+)
|
|
- metavariable-comparison:
|
|
metavariable: $DAYS
|
|
comparison: int($DAYS) < 7
|
|
- focus-metavariable: $DAYS
|
|
- patterns:
|
|
- pattern-inside: |
|
|
updates:
|
|
...
|
|
- pattern: |
|
|
cooldown:
|
|
default-days: $DAYS
|
|
- metavariable-regex:
|
|
metavariable: $DAYS
|
|
regex: ^\D
|
|
- focus-metavariable: $DAYS
|
|
message: 'This Dependabot configuration does not set a cooldown period. Newly published
|
|
packages can be malicious or unstable. Add a `cooldown` block with `default-days:
|
|
7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing
|
|
updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown'
|
|
languages:
|
|
- yaml
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/.github/dependabot.yml'
|
|
- '**/.github/dependabot.yaml'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- dependabot
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown
|
|
shortlink: https://sg.run/5WvGK
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291647
|
|
rv_id: 1423386
|
|
rule_id: zdUArOL
|
|
version_id: DkTwEGl
|
|
url: https://semgrep.dev/playground/r/DkTwEGl/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown
|
|
origin: community
|
|
- id: package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?:(?:^---\n)(?:[^\n]*\n)|^)(?P<TARGET>(?:(?!\n---)[\s\S])*\S(?:(?!\n---)[\s\S])*)
|
|
- pattern-not-regex: min-release-age
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern-regex: min-release-age\s*=\s*\d+
|
|
- pattern-regex: =\s*(?P<AGE>\d+)
|
|
- metavariable-comparison:
|
|
metavariable: $AGE
|
|
comparison: int($AGE) < 7
|
|
- focus-metavariable: $AGE
|
|
- patterns:
|
|
- pattern-regex: (?m)min-release-age[ \t]*=[ \t]*(?P<VAL>[^\s\d][^\n]*)
|
|
- focus-metavariable: $VAL
|
|
- patterns:
|
|
- pattern-regex: (?m)min-release-age\s*=\s*$
|
|
message: 'This .npmrc does not set a minimum release age or sets it too low. Newly
|
|
published packages can be malicious or unstable. Add `min-release-age = 7` to
|
|
wait 7 days before resolving newly published package versions. Added in: v11.10
|
|
Reference: https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/'
|
|
languages:
|
|
- generic
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/.npmrc'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- npm
|
|
- javascript
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/
|
|
- https://github.com/npm/cli/pull/8965
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age
|
|
shortlink: https://sg.run/GRo1z
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291648
|
|
rv_id: 1423387
|
|
rule_id: pKU6A82
|
|
version_id: WrT7LdL
|
|
url: https://semgrep.dev/playground/r/WrT7LdL/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age
|
|
origin: community
|
|
- id: package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies
|
|
message: 'Missing or incorrect blockExoticSubdeps. Set `blockExoticSubdeps: true`
|
|
to transitive dependencies from being installed from untrusted sources. Added
|
|
in: v10.26.0 Reference: https://pnpm.io/settings#blockexoticsubdeps'
|
|
languages:
|
|
- yaml
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/pnpm-workspace.yaml'
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:packages|catalog)\s*:)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern: |
|
|
blockExoticSubdeps: $VAL
|
|
- metavariable-regex:
|
|
metavariable: $VAL
|
|
regex: ^(?!true$).+
|
|
- focus-metavariable: $VAL
|
|
- patterns:
|
|
- pattern-regex: (?m)^\s*blockExoticSubdeps\s*:\s*$
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- pnpm
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://pnpm.io/settings#blockexoticsubdeps
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies
|
|
shortlink: https://sg.run/RrWRv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291649
|
|
rv_id: 1423388
|
|
rule_id: 2ZUQEZ5
|
|
version_id: 0bTGnwj
|
|
url: https://semgrep.dev/playground/r/0bTGnwj/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies
|
|
origin: community
|
|
- id: package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age
|
|
message: 'This pnpm workspace configuration does not set a minimum release age.
|
|
Newly published packages can be malicious or unstable. Add `minimumReleaseAge:
|
|
10080` (minutes) to wait at least seven days before installing newly published
|
|
package versions. Added in: v10.16.0 Reference: https://pnpm.io/settings#minimumreleaseage'
|
|
languages:
|
|
- yaml
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/pnpm-workspace.yaml'
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:packages|catalog)\s*:)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern-regex: ^\s*minimumReleaseAge\s*:\s*(?P<AGE>\d+)
|
|
- metavariable-comparison:
|
|
metavariable: $AGE
|
|
comparison: int($AGE) < 10080
|
|
- focus-metavariable: $AGE
|
|
- patterns:
|
|
- pattern: |
|
|
minimumReleaseAge: $AGE
|
|
- metavariable-regex:
|
|
metavariable: $AGE
|
|
regex: ^\D
|
|
- focus-metavariable: $AGE
|
|
- patterns:
|
|
- pattern-regex: (?m)^\s*minimumReleaseAge\s*:\s*$
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- pnpm
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://pnpm.io/settings#minimumreleaseage
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age
|
|
shortlink: https://sg.run/Aj0o0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291650
|
|
rv_id: 1423389
|
|
rule_id: X5Uwn1n
|
|
version_id: K3TgxrW
|
|
url: https://semgrep.dev/playground/r/K3TgxrW/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age
|
|
origin: community
|
|
- id: package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy
|
|
message: 'Missing or incorrect trustPolicy. Set `trustPolicy: no-downgrade` to prevent
|
|
malicious package updates from downgrading security settings. Added in: v10.21.0
|
|
Reference: https://pnpm.io/settings#trustpolicy'
|
|
languages:
|
|
- yaml
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/pnpm-workspace.yaml'
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:packages|catalog)\s*:)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern: |
|
|
trustPolicy: $VAL
|
|
- metavariable-regex:
|
|
metavariable: $VAL
|
|
regex: ^(?!no-downgrade$).+
|
|
- focus-metavariable: $VAL
|
|
- patterns:
|
|
- pattern-regex: (?m)^\s*trustPolicy\s*:\s*$
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- pnpm
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://pnpm.io/settings#minimumreleaseage
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy
|
|
shortlink: https://sg.run/B2Kz7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291651
|
|
rv_id: 1423390
|
|
rule_id: j2U6J8N
|
|
version_id: qkTvDQn
|
|
url: https://semgrep.dev/playground/r/qkTvDQn/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy
|
|
origin: community
|
|
- id: package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
"packageRules": [
|
|
...
|
|
]
|
|
- pattern-either:
|
|
- pattern: |
|
|
{ ..., "matchPackageNames": [...], ... }
|
|
- pattern: |
|
|
{ ..., "matchPackagePatterns": [...], ... }
|
|
- pattern: |
|
|
{ ..., "matchDepTypes": [...], ... }
|
|
- pattern-not: |
|
|
{
|
|
...,
|
|
"minimumReleaseAge": $AGE,
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
{
|
|
...,
|
|
"minimumReleaseAge": false,
|
|
...
|
|
}
|
|
- patterns:
|
|
- pattern-inside: |
|
|
"packageRules": [
|
|
...
|
|
]
|
|
- pattern-regex: '"minimumReleaseAge":\s*"(?P<AGE>\d+) days?"'
|
|
- metavariable-comparison:
|
|
metavariable: $AGE
|
|
comparison: int($AGE) < 7
|
|
- focus-metavariable: $AGE
|
|
- patterns:
|
|
- pattern-inside: |
|
|
"packageRules": [
|
|
...
|
|
]
|
|
- pattern: |
|
|
"minimumReleaseAge": "$AGE"
|
|
- metavariable-regex:
|
|
metavariable: $AGE
|
|
regex: ^(?!\d+ days?$)
|
|
- focus-metavariable: $AGE
|
|
message: 'This Renovate configuration does not set a minimum release age. Newly
|
|
published packages can be malicious or unstable. Add `"minimumReleaseAge": "7
|
|
days"` within a `packageRules` entry to wait 7 days before proposing updates to
|
|
newly published package versions. Set `"minimumReleaseAge": false` to set an exception
|
|
for minimal release age for the package rule. Added in: v42'
|
|
languages:
|
|
- json
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/renovate.json'
|
|
- '**/renovate.json5'
|
|
- '**/.renovaterc'
|
|
- '**/.renovaterc.json'
|
|
- '**/.renovaterc.json5'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- renovate
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://docs.renovatebot.com/configuration-options/#minimumreleaseage
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age
|
|
shortlink: https://sg.run/D8l2q
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291652
|
|
rv_id: 1443454
|
|
rule_id: 10UbQrX
|
|
version_id: jQT1KAX
|
|
url: https://semgrep.dev/playground/r/jQT1KAX/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age
|
|
origin: community
|
|
- id: package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)\[tool\.uv\](?P<TARGET>[^\[]*?)(?=\[|\z)
|
|
- metavariable-regex:
|
|
metavariable: $TARGET
|
|
regex: ^(?![\s\S]*exclude-newer)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern-regex: exclude-newer\s*=\s*"(?P<DAYS>\d+) days?"
|
|
- metavariable-comparison:
|
|
metavariable: $DAYS
|
|
comparison: int($DAYS) < 7
|
|
- focus-metavariable: $DAYS
|
|
- patterns:
|
|
- pattern-regex: exclude-newer\s*=\s*"(?P<VAL>[^"]+)"
|
|
- metavariable-regex:
|
|
metavariable: $VAL
|
|
regex: ^(?!\d+ days?$)(?!\d{4}-\d{2}-\d{2}$)(?!\d{4}-\d{2}-\d{2}T)
|
|
- focus-metavariable: $VAL
|
|
message: 'This pyproject.toml configures uv but does not set a dependency cooldown.
|
|
Newly published packages can be malicious or unstable. Add `exclude-newer = "7
|
|
days"` under `[tool.uv]` to wait 7 days before resolving newly published package
|
|
versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns'
|
|
languages:
|
|
- generic
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/pyproject.toml'
|
|
- '**/uv.toml'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- uv
|
|
- python
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown
|
|
shortlink: https://sg.run/WeY0Z
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291653
|
|
rv_id: 1423392
|
|
rule_id: 9AUo6vE
|
|
version_id: YDTwLle
|
|
url: https://semgrep.dev/playground/r/YDTwLle/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown
|
|
origin: community
|
|
- id: package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:nodeLinker|yarnPath|enableGlobalCache|npmScopes|npmRegistryServer)\s*:)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern-regex: (?m)npmMinimalAgeGate\s*:\s*['"]?(?P<DAYS>\d+)d['"]?
|
|
- metavariable-comparison:
|
|
metavariable: $DAYS
|
|
comparison: int($DAYS) < 7
|
|
- focus-metavariable: $DAYS
|
|
- patterns:
|
|
- pattern-regex: (?m)npmMinimalAgeGate[ \t]*:[ \t]*(?P<VAL>\S+)
|
|
- metavariable-regex:
|
|
metavariable: $VAL
|
|
regex: ^(?!['"]?\d+d['"]?$)
|
|
- focus-metavariable: $VAL
|
|
- patterns:
|
|
- pattern-regex: (?m)^npmMinimalAgeGate\s*:\s*$
|
|
message: 'This .yarnrc.yml does not set a minimal age gate or sets it too low. Newly
|
|
published packages can be malicious or unstable. Add `npmMinimalAgeGate: "7d"`
|
|
to wait 7 days before resolving newly published package versions. Added in: 4.10
|
|
Reference: https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate'
|
|
languages:
|
|
- yaml
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/.yarnrc.yml'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- yarn
|
|
- javascript
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate
|
|
shortlink: https://sg.run/0gvNq
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291654
|
|
rv_id: 1423393
|
|
rule_id: yyUBeEz
|
|
version_id: JdTnXlj
|
|
url: https://semgrep.dev/playground/r/JdTnXlj/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate
|
|
origin: community
|
|
- id: yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell
|
|
languages:
|
|
- yaml
|
|
message: "A `run:` step pipes the output of `curl` or `wget` directly into a shell
|
|
interpreter. This is the \"curl | bash\" install pattern \u2014 if the remote
|
|
server is compromised or the URL is hijacked, an attacker can execute arbitrary
|
|
code in your CI runner. Consider downloading the file first, verifying its checksum
|
|
or signature, and then executing it."
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A03:2025 - Injection
|
|
references:
|
|
- https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions
|
|
- https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/
|
|
technology:
|
|
- github-actions
|
|
- bash
|
|
- curl
|
|
cwe2021-top25: true
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell
|
|
shortlink: https://sg.run/GR8K1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 309392
|
|
rv_id: 1443456
|
|
rule_id: x8UAgrE
|
|
version_id: 9lT3zYb
|
|
url: https://semgrep.dev/playground/r/9lT3zYb/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: 'steps: [...]'
|
|
- pattern-inside: |
|
|
- run: ...
|
|
...
|
|
- pattern: 'run: $SHELL'
|
|
- metavariable-pattern:
|
|
language: bash
|
|
metavariable: $SHELL
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: curl ... | $CMD ...
|
|
- pattern: wget ... | $CMD ...
|
|
- metavariable-regex:
|
|
metavariable: $CMD
|
|
regex: ^(bash|sh|python3?|ruby|perl)$
|
|
severity: ERROR
|
|
- id: rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid
|
|
message: Dangerously accepting invalid TLS information
|
|
pattern-either:
|
|
- pattern: reqwest::Client::builder(). ... .danger_accept_invalid_hostnames(true)
|
|
- pattern: reqwest::Client::builder(). ... .danger_accept_invalid_certs(true)
|
|
metadata:
|
|
references:
|
|
- https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_hostnames
|
|
- https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_certs
|
|
technology:
|
|
- reqwest
|
|
category: security
|
|
cwe: 'CWE-295: Improper Certificate Validation'
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
subcategory: vuln
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid
|
|
shortlink: https://sg.run/DqrG
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 40108
|
|
rv_id: 946551
|
|
rule_id: qNUKDg
|
|
version_id: 7ZTrQLJ
|
|
url: https://semgrep.dev/playground/r/7ZTrQLJ/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid
|
|
origin: community
|
|
languages:
|
|
- rust
|
|
severity: WARNING
|
|
- id: rust.lang.security.rustls-dangerous.rustls-dangerous
|
|
message: Dangerous client config used, ensure SSL verification
|
|
pattern-either:
|
|
- pattern: rustls::client::DangerousClientConfig
|
|
- pattern: $CLIENT.dangerous().set_certificate_verifier(...)
|
|
- pattern: |
|
|
let $CLIENT = rustls::client::ClientConfig::dangerous(...);
|
|
...
|
|
$CLIENT.set_certificate_verifier(...);
|
|
metadata:
|
|
references:
|
|
- https://docs.rs/rustls/latest/rustls/client/struct.DangerousClientConfig.html
|
|
- https://docs.rs/rustls/latest/rustls/client/struct.ClientConfig.html#method.dangerous
|
|
technology:
|
|
- rustls
|
|
category: security
|
|
cwe: 'CWE-295: Improper Certificate Validation'
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
subcategory: vuln
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/rust.lang.security.rustls-dangerous.rustls-dangerous
|
|
shortlink: https://sg.run/01Rw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 40110
|
|
rv_id: 946553
|
|
rule_id: YGU8LK
|
|
version_id: 8KTKjdO
|
|
url: https://semgrep.dev/playground/r/8KTKjdO/rust.lang.security.rustls-dangerous.rustls-dangerous
|
|
origin: community
|
|
languages:
|
|
- rust
|
|
severity: WARNING
|
|
- id: rust.lang.security.ssl-verify-none.ssl-verify-none
|
|
message: SSL verification disabled, this allows for MitM attacks
|
|
pattern: $BUILDER.set_verify(openssl::ssl::SSL_VERIFY_NONE)
|
|
metadata:
|
|
references:
|
|
- https://docs.rs/openssl/latest/openssl/ssl/struct.SslContextBuilder.html#method.set_verify
|
|
technology:
|
|
- openssl
|
|
category: security
|
|
cwe: 'CWE-295: Improper Certificate Validation'
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
subcategory: vuln
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/rust.lang.security.ssl-verify-none.ssl-verify-none
|
|
shortlink: https://sg.run/K2Pn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 40111
|
|
rv_id: 946554
|
|
rule_id: 6JU0Bl
|
|
version_id: gETe1bo
|
|
url: https://semgrep.dev/playground/r/gETe1bo/rust.lang.security.ssl-verify-none.ssl-verify-none
|
|
origin: community
|
|
languages:
|
|
- rust
|
|
severity: WARNING
|