41422 lines
1.4 MiB
41422 lines
1.4 MiB
rules:
|
|
- id: generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host
|
|
paths:
|
|
include:
|
|
- '*.conf'
|
|
- '*.vhost'
|
|
- '**/sites-available/*'
|
|
- '**/sites-enabled/*'
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
message: The host for this proxy URL is dynamically determined. This can be dangerous
|
|
if the host can be injected by an attacker because it may forcibly alter destination
|
|
of the proxy. Consider hardcoding acceptable destinations and retrieving them
|
|
with 'map' or something similar.
|
|
metadata:
|
|
source-rule-url: https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md
|
|
references:
|
|
- https://nginx.org/en/docs/http/ngx_http_map_module.html
|
|
category: security
|
|
technology:
|
|
- nginx
|
|
confidence: MEDIUM
|
|
cwe:
|
|
- 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host
|
|
shortlink: https://sg.run/ndpb
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9036
|
|
rv_id: 1262671
|
|
rule_id: GdU7yl
|
|
version_id: kbTzG2j
|
|
url: https://semgrep.dev/playground/r/kbTzG2j/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: proxy_pass $SCHEME://$$HOST ...;
|
|
- pattern: proxy_pass $$SCHEME://$$HOST ...;
|
|
- id: generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme
|
|
paths:
|
|
include:
|
|
- '*.conf'
|
|
- '*.vhost'
|
|
- '**/sites-available/*'
|
|
- '**/sites-enabled/*'
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
message: The protocol scheme for this proxy is dynamically determined. This can
|
|
be dangerous if the scheme can be injected by an attacker because it may forcibly
|
|
alter the connection scheme. Consider hardcoding a scheme for this proxy.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-16: CWE CATEGORY: Configuration'
|
|
references:
|
|
- https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md
|
|
category: security
|
|
technology:
|
|
- nginx
|
|
confidence: MEDIUM
|
|
owasp:
|
|
- A06:2017 - Security Misconfiguration
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme
|
|
shortlink: https://sg.run/EkAo
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9037
|
|
rv_id: 1262672
|
|
rule_id: ReUg7n
|
|
version_id: w8TRoAJ
|
|
url: https://semgrep.dev/playground/r/w8TRoAJ/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme
|
|
origin: community
|
|
pattern: proxy_pass $$SCHEME:// ...;
|
|
- id: generic.nginx.security.header-injection.header-injection
|
|
pattern: |
|
|
location ... <$VARIABLE> ... {
|
|
...
|
|
add_header ... $$VARIABLE
|
|
...
|
|
}
|
|
paths:
|
|
include:
|
|
- '*.conf'
|
|
- '*.vhost'
|
|
- '**/sites-available/*'
|
|
- '**/sites-enabled/*'
|
|
languages:
|
|
- generic
|
|
severity: ERROR
|
|
message: 'The $$VARIABLE path parameter is added as a header in the response. This
|
|
could allow an attacker to inject a newline and add a new header into the response.
|
|
This is called HTTP response splitting. To fix, do not allow whitespace in the
|
|
path parameter: ''[^\s]+''.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP
|
|
Request/Response Splitting'')'
|
|
references:
|
|
- https://github.com/yandex/gixy/blob/master/docs/en/plugins/httpsplitting.md
|
|
- https://owasp.org/www-community/attacks/HTTP_Response_Splitting
|
|
category: security
|
|
technology:
|
|
- nginx
|
|
confidence: MEDIUM
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/generic.nginx.security.header-injection.header-injection
|
|
shortlink: https://sg.run/7oj4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9038
|
|
rv_id: 1262673
|
|
rule_id: AbUz8p
|
|
version_id: xyTjzNW
|
|
url: https://semgrep.dev/playground/r/xyTjzNW/generic.nginx.security.header-injection.header-injection
|
|
origin: community
|
|
- id: generic.nginx.security.insecure-ssl-version.insecure-ssl-version
|
|
patterns:
|
|
- pattern-not: ssl_protocols TLSv1.2 TLSv1.3;
|
|
- pattern-not: ssl_protocols TLSv1.3 TLSv1.2;
|
|
- pattern-not: ssl_protocols TLSv1.2;
|
|
- pattern-not: ssl_protocols TLSv1.3;
|
|
- pattern: ssl_protocols ...;
|
|
paths:
|
|
include:
|
|
- '*.conf'
|
|
- '*.vhost'
|
|
- '**/sites-available/*'
|
|
- '**/sites-enabled/*'
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
message: Detected use of an insecure SSL version. Secure SSL versions are TLSv1.2
|
|
and TLS1.3; older versions are known to be broken and are susceptible to attacks.
|
|
Prefer use of TLSv1.2 or later.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
references:
|
|
- https://www.acunetix.com/blog/web-security-zone/hardening-nginx/
|
|
- https://www.acunetix.com/blog/articles/tls-ssl-cipher-hardening/
|
|
category: security
|
|
technology:
|
|
- nginx
|
|
confidence: HIGH
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/generic.nginx.security.insecure-ssl-version.insecure-ssl-version
|
|
shortlink: https://sg.run/gLKy
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9041
|
|
rv_id: 1262676
|
|
rule_id: WAUo9k
|
|
version_id: vdT06O4
|
|
url: https://semgrep.dev/playground/r/vdT06O4/generic.nginx.security.insecure-ssl-version.insecure-ssl-version
|
|
origin: community
|
|
- id: generic.nginx.security.missing-ssl-version.missing-ssl-version
|
|
patterns:
|
|
- pattern: server { ... listen $PORT ssl; ... }
|
|
- pattern-not-inside: server { ... ssl_protocols ... }
|
|
paths:
|
|
include:
|
|
- '*.conf'
|
|
- '*.vhost'
|
|
- '**/sites-available/*'
|
|
- '**/sites-enabled/*'
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
message: This server configuration is missing the 'ssl_protocols' directive. By
|
|
default, this server will use 'ssl_protocols TLSv1 TLSv1.1 TLSv1.2', and versions
|
|
older than TLSv1.2 are known to be broken. Explicitly specify 'ssl_protocols TLSv1.2
|
|
TLSv1.3' to use secure TLS versions.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
references:
|
|
- https://www.acunetix.com/blog/web-security-zone/hardening-nginx/
|
|
- https://nginx.org/en/docs/http/configuring_https_servers.html
|
|
category: security
|
|
technology:
|
|
- nginx
|
|
confidence: MEDIUM
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/generic.nginx.security.missing-ssl-version.missing-ssl-version
|
|
shortlink: https://sg.run/3xzl
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9043
|
|
rv_id: 1262678
|
|
rule_id: KxUbeA
|
|
version_id: ZRTKAle
|
|
url: https://semgrep.dev/playground/r/ZRTKAle/generic.nginx.security.missing-ssl-version.missing-ssl-version
|
|
origin: community
|
|
- id: generic.nginx.security.request-host-used.request-host-used
|
|
pattern-either:
|
|
- pattern: $http_host
|
|
- pattern: $host
|
|
paths:
|
|
include:
|
|
- '*conf*'
|
|
- '*nginx*'
|
|
- '*vhost*'
|
|
- '**/sites-available/*'
|
|
- '**/sites-enabled/*'
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
message: '''$http_host'' and ''$host'' variables may contain a malicious value from
|
|
attacker controlled ''Host'' request header. Use an explicitly configured host
|
|
value or a allow list for validation.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-290: Authentication Bypass by Spoofing'
|
|
references:
|
|
- https://github.com/yandex/gixy/blob/master/docs/en/plugins/hostspoofing.md
|
|
- https://portswigger.net/web-security/host-header
|
|
category: security
|
|
technology:
|
|
- nginx
|
|
confidence: MEDIUM
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/generic.nginx.security.request-host-used.request-host-used
|
|
shortlink: https://sg.run/4x3Z
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9044
|
|
rv_id: 1262680
|
|
rule_id: qNUjGg
|
|
version_id: ExTExrN
|
|
url: https://semgrep.dev/playground/r/ExTExrN/generic.nginx.security.request-host-used.request-host-used
|
|
origin: community
|
|
- id: generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key
|
|
pattern-regex: rk_live_[0-9a-zA-Z]{24}
|
|
languages:
|
|
- regex
|
|
message: Stripe Restricted API Key detected
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json
|
|
category: security
|
|
technology:
|
|
- secrets
|
|
- stripe
|
|
confidence: MEDIUM
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
references:
|
|
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key
|
|
shortlink: https://sg.run/ZvdL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9079
|
|
rv_id: 1262900
|
|
rule_id: 5rUOWq
|
|
version_id: K3TKkKj
|
|
url: https://semgrep.dev/playground/r/K3TKkKj/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key
|
|
origin: community
|
|
- id: generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri
|
|
patterns:
|
|
- pattern: $PROTOCOL://$...USERNAME:$...PASSWORD@$END
|
|
- metavariable-regex:
|
|
metavariable: $...USERNAME
|
|
regex: \A({?)([A-Za-z])([A-Za-z0-9_-]){5,31}(}?)\Z
|
|
- metavariable-regex:
|
|
metavariable: $...PASSWORD
|
|
regex: (?!.*[\s])(?=.*[0-9])(?=.*[a-z])(?=.*[A-Z])(?=.*[!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~]){6,32}
|
|
- metavariable-regex:
|
|
metavariable: $PROTOCOL
|
|
regex: (.*http.*)|(.*sql.*)|(.*ftp.*)|(.*smtp.*)
|
|
languages:
|
|
- generic
|
|
message: Username and password in URI detected
|
|
severity: ERROR
|
|
metadata:
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go
|
|
category: security
|
|
technology:
|
|
- secrets
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri
|
|
shortlink: https://sg.run/8yA4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9084
|
|
rv_id: 1262903
|
|
rule_id: DbUple
|
|
version_id: YDTZeZE
|
|
url: https://semgrep.dev/playground/r/YDTZeZE/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri
|
|
origin: community
|
|
- id: go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
&sessions.Options{
|
|
...,
|
|
HttpOnly: true,
|
|
...,
|
|
}
|
|
- pattern: |
|
|
&sessions.Options{
|
|
...,
|
|
}
|
|
message: A session cookie was detected without setting the 'HttpOnly' flag. The
|
|
'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts
|
|
from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by
|
|
setting 'HttpOnly' to 'true' in the Options struct.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69
|
|
category: security
|
|
technology:
|
|
- gorilla
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly
|
|
shortlink: https://sg.run/4xJZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9088
|
|
rv_id: 1262911
|
|
rule_id: qNUj6g
|
|
version_id: WrTqKqe
|
|
url: https://semgrep.dev/playground/r/WrTqKqe/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly
|
|
origin: community
|
|
fix-regex:
|
|
regex: (HttpOnly\s*:\s+)false
|
|
replacement: \1true
|
|
severity: WARNING
|
|
languages:
|
|
- go
|
|
- id: go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
&sessions.Options{
|
|
...,
|
|
Secure: true,
|
|
...,
|
|
}
|
|
- pattern: |
|
|
&sessions.Options{
|
|
...,
|
|
}
|
|
message: A session cookie was detected without setting the 'Secure' flag. The 'secure'
|
|
flag for cookies prevents the client from transmitting the cookie over insecure
|
|
channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in
|
|
the Options struct.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69
|
|
category: security
|
|
technology:
|
|
- gorilla
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure
|
|
shortlink: https://sg.run/PJdE
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9089
|
|
rv_id: 1262912
|
|
rule_id: lBU9kw
|
|
version_id: 0bTKzKk
|
|
url: https://semgrep.dev/playground/r/0bTKzKk/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure
|
|
origin: community
|
|
fix-regex:
|
|
regex: (Secure\s*:\s+)false
|
|
replacement: \1true
|
|
severity: WARNING
|
|
languages:
|
|
- go
|
|
- id: go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-300: Channel Accessible by Non-Endpoint'
|
|
references:
|
|
- https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption
|
|
category: security
|
|
technology:
|
|
- grpc
|
|
confidence: HIGH
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection
|
|
shortlink: https://sg.run/J9yZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9090
|
|
rv_id: 1262916
|
|
rule_id: PeUZ4X
|
|
version_id: YDTZeZB
|
|
url: https://semgrep.dev/playground/r/YDTZeZB/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection
|
|
origin: community
|
|
message: 'Found an insecure gRPC connection using ''grpc.WithInsecure()''. This
|
|
creates a connection without encryption to a gRPC server. A malicious attacker
|
|
could tamper with the gRPC message, which could compromise the machine. Instead,
|
|
establish a secure connection with an SSL certificate using the ''grpc.WithTransportCredentials()''
|
|
function. You can create a create credentials using a ''tls.Config{}'' struct
|
|
with ''credentials.NewTLS()''. The final fix looks like this: ''grpc.WithTransportCredentials(credentials.NewTLS(<config>))''.'
|
|
languages:
|
|
- go
|
|
severity: ERROR
|
|
pattern: $GRPC.Dial($ADDR, ..., $GRPC.WithInsecure(...), ...)
|
|
fix-regex:
|
|
regex: (.*)WithInsecure\(.*?\)
|
|
replacement: \1WithTransportCredentials(credentials.NewTLS(<your_tls_config_here>))
|
|
- id: go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-300: Channel Accessible by Non-Endpoint'
|
|
references:
|
|
- https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption
|
|
category: security
|
|
technology:
|
|
- grpc
|
|
confidence: HIGH
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection
|
|
shortlink: https://sg.run/5Q5l
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9091
|
|
rv_id: 1262917
|
|
rule_id: JDUy0B
|
|
version_id: 6xT2923
|
|
url: https://semgrep.dev/playground/r/6xT2923/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection
|
|
origin: community
|
|
message: Found an insecure gRPC server without 'grpc.Creds()' or options with credentials.
|
|
This allows for a connection without encryption to this server. A malicious attacker
|
|
could tamper with the gRPC message, which could compromise the machine. Include
|
|
credentials derived from an SSL certificate in order to create a secure gRPC connection.
|
|
You can create credentials using 'credentials.NewServerTLSFromFile("cert.pem",
|
|
"cert.key")'.
|
|
languages:
|
|
- go
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sinks:
|
|
- requires: OPTIONS and not CREDS
|
|
pattern: grpc.NewServer($OPT, ...)
|
|
- requires: EMPTY_CONSTRUCTOR
|
|
pattern: grpc.NewServer()
|
|
pattern-sources:
|
|
- label: OPTIONS
|
|
pattern: grpc.ServerOption{ ... }
|
|
- label: CREDS
|
|
pattern: grpc.Creds(...)
|
|
- label: EMPTY_CONSTRUCTOR
|
|
pattern: grpc.NewServer()
|
|
- id: go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm
|
|
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
|
|
assumes the integrity of the token has already been verified. This would allow
|
|
a malicious actor to forge a JWT token that will automatically be verified. Do
|
|
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm
|
|
shortlink: https://sg.run/Gej1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9092
|
|
rv_id: 1262919
|
|
rule_id: 5rUOWQ
|
|
version_id: zyTb2bz
|
|
url: https://semgrep.dev/playground/r/zyTb2bz/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import "github.com/golang-jwt/jwt"
|
|
...
|
|
- pattern-inside: |
|
|
import "github.com/dgrijalva/jwt-go"
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
jwt.SigningMethodNone
|
|
- pattern: jwt.UnsafeAllowNoneSignatureType
|
|
- id: go.jwt-go.security.jwt.hardcoded-jwt-key
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
- secrets
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/go.jwt-go.security.jwt.hardcoded-jwt-key
|
|
shortlink: https://sg.run/Rod2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9093
|
|
rv_id: 1262920
|
|
rule_id: GdU7Ny
|
|
version_id: pZT0305
|
|
url: https://semgrep.dev/playground/r/pZT0305/go.jwt-go.security.jwt.hardcoded-jwt-key
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- go
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
[]byte("$F")
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$TOKEN.SignedString($F)
|
|
- focus-metavariable: $F
|
|
- id: go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified
|
|
message: Detected the decoding of a JWT token without a verify step. Don't use `ParseUnverified`
|
|
unless you know what you're doing This method parses the token but doesn't validate
|
|
the signature. It's only ever useful in cases where you know the signature is
|
|
valid (because it has been checked previously in the stack) and you want to extract
|
|
values from it.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-345: Insufficient Verification of Data Authenticity'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified
|
|
shortlink: https://sg.run/Av66
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9094
|
|
rv_id: 1262918
|
|
rule_id: ReUgJJ
|
|
version_id: o5TbDbq
|
|
url: https://semgrep.dev/playground/r/o5TbDbq/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
import "github.com/dgrijalva/jwt-go"
|
|
...
|
|
- pattern: |
|
|
$JWT.ParseUnverified(...)
|
|
- id: go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
exec.Cmd {...,Path: $CMD,...}
|
|
- pattern-not: |
|
|
exec.Cmd {...,Path: "...",...}
|
|
- pattern-not-inside: |
|
|
$CMD,$ERR := exec.LookPath("...");
|
|
...
|
|
- pattern-not-inside: |
|
|
$CMD = "...";
|
|
...
|
|
- patterns:
|
|
- pattern: |
|
|
exec.Cmd {...,Args: $ARGS,...}
|
|
- pattern-not: |
|
|
exec.Cmd {...,Args: []string{...},...}
|
|
- pattern-not-inside: |
|
|
$ARGS = []string{"...",...};
|
|
...
|
|
- pattern-not-inside: |
|
|
$CMD = "...";
|
|
...
|
|
$ARGS = []string{$CMD,...};
|
|
...
|
|
- pattern-not-inside: |
|
|
$CMD = exec.LookPath("...");
|
|
...
|
|
$ARGS = []string{$CMD,...};
|
|
...
|
|
- patterns:
|
|
- pattern: |
|
|
exec.Cmd {...,Args: []string{$CMD,...},...}
|
|
- pattern-not: |
|
|
exec.Cmd {...,Args: []string{"...",...},...}
|
|
- pattern-not-inside: |
|
|
$CMD,$ERR := exec.LookPath("...");
|
|
...
|
|
- pattern-not-inside: |
|
|
$CMD = "...";
|
|
...
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
exec.Cmd {...,Args: []string{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$EXE,...},...}
|
|
- patterns:
|
|
- pattern: |
|
|
exec.Cmd {...,Args: []string{$CMD,"-c",$EXE,...},...}
|
|
- pattern-inside: |
|
|
$CMD,$ERR := exec.LookPath("=~/(sh|bash|ksh|csh|tcsh|zsh)/");
|
|
...
|
|
- pattern-not: |
|
|
exec.Cmd {...,Args: []string{"...","...","...",...},...}
|
|
- pattern-not-inside: |
|
|
$EXE = "...";
|
|
...
|
|
- pattern-inside: |
|
|
import "os/exec"
|
|
...
|
|
message: Detected non-static command inside exec.Cmd. Audit the input to 'exec.Cmd'.
|
|
If unverified user data can reach this call site, this is a code injection vulnerability.
|
|
A malicious actor can inject a malicious script to execute arbitrary code.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd
|
|
shortlink: https://sg.run/Dorj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9108
|
|
rv_id: 1262934
|
|
rule_id: 2ZUb8l
|
|
version_id: e1Tyjeg
|
|
url: https://semgrep.dev/playground/r/e1Tyjeg/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd
|
|
origin: community
|
|
severity: ERROR
|
|
languages:
|
|
- go
|
|
- id: go.lang.security.audit.crypto.bad_imports.insecure-module-used
|
|
message: The package `net/http/cgi` is on the import blocklist. The package is
|
|
vulnerable to httpoxy attacks (CVE-2015-5386). It is recommended to use `net/http`
|
|
or a web framework to build a web application instead.
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
source-rule-url: https://github.com/securego/gosec
|
|
references:
|
|
- https://godoc.org/golang.org/x/crypto/sha3
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.bad_imports.insecure-module-used
|
|
shortlink: https://sg.run/l2gj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9113
|
|
rv_id: 1262921
|
|
rule_id: yyUnov
|
|
version_id: 2KTv2vJ
|
|
url: https://semgrep.dev/playground/r/2KTv2vJ/go.lang.security.audit.crypto.bad_imports.insecure-module-used
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import "net/http/cgi"
|
|
...
|
|
- pattern: |
|
|
cgi.$FUNC(...)
|
|
- id: go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key
|
|
message: Disabled host key verification detected. This allows man-in-the-middle
|
|
attacks. Use the 'golang.org/x/crypto/ssh/knownhosts' package to do host key verification.
|
|
See https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ to
|
|
learn more about the problem and how to fix it.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-322: Key Exchange without Entity Authentication'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/securego/gosec
|
|
references:
|
|
- https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/
|
|
- https://gist.github.com/Skarlso/34321a230cf0245018288686c9e70b2d
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key
|
|
shortlink: https://sg.run/Yv6X
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9114
|
|
rv_id: 1262922
|
|
rule_id: r6UrW9
|
|
version_id: X0TzyzN
|
|
url: https://semgrep.dev/playground/r/X0TzyzN/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
pattern: ssh.InsecureIgnoreHostKey()
|
|
- id: go.lang.security.audit.crypto.math_random.math-random-used
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#secure-random-number-generation
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.math_random.math-random-used
|
|
shortlink: https://sg.run/6nK6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9115
|
|
rv_id: 1262923
|
|
rule_id: bwUwy8
|
|
version_id: jQTn5nj
|
|
url: https://semgrep.dev/playground/r/jQTn5nj/go.lang.security.audit.crypto.math_random.math-random-used
|
|
origin: community
|
|
message: Do not use `math/rand`. Use `crypto/rand` instead.
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
import $RAND "$MATH"
|
|
- pattern: |
|
|
import "$MATH"
|
|
- metavariable-regex:
|
|
metavariable: $MATH
|
|
regex: ^(math/rand(\/v[0-9]+)*)$
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
...
|
|
rand.$FUNC(...)
|
|
- pattern-inside: |
|
|
...
|
|
$RAND.$FUNC(...)
|
|
- focus-metavariable:
|
|
- $MATH
|
|
fix: |
|
|
crypto/rand
|
|
- id: go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion
|
|
message: '`MinVersion` is missing from this TLS configuration. By default, as of
|
|
Go 1.22, TLS 1.2 is currently used as the minimum. General purpose web applications
|
|
should default to TLS 1.3 with all other protocols disabled. Only where it is
|
|
known that a web server must support legacy clients with unsupported an insecure
|
|
browsers (such as Internet Explorer 10), it may be necessary to enable TLS 1.0
|
|
to provide support. Add `MinVersion: tls.VersionTLS13'' to the TLS configuration
|
|
to bump the minimum version to TLS 1.3.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go
|
|
references:
|
|
- https://go.dev/doc/go1.22#minor_library_changes
|
|
- https://pkg.go.dev/crypto/tls#:~:text=MinVersion
|
|
- https://www.us-cert.gov/ncas/alerts/TA14-290A
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion
|
|
shortlink: https://sg.run/oxEN
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9116
|
|
rv_id: 1262924
|
|
rule_id: NbUk4X
|
|
version_id: 1QTypyp
|
|
url: https://semgrep.dev/playground/r/1QTypyp/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern: |
|
|
tls.Config{ $...CONF }
|
|
- pattern-not: |
|
|
tls.Config{..., MinVersion: ..., ...}
|
|
fix: |
|
|
tls.Config{ $...CONF, MinVersion: tls.VersionTLS13 }
|
|
- id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure
|
|
message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14,
|
|
SSLv3 will be removed. Instead, use 'tls.VersionTLS13'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go
|
|
references:
|
|
- https://golang.org/doc/go1.14#crypto/tls
|
|
- https://www.us-cert.gov/ncas/alerts/TA14-290A
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure
|
|
shortlink: https://sg.run/zvE1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9117
|
|
rv_id: 1262926
|
|
rule_id: kxUkJ2
|
|
version_id: yeTxpxj
|
|
url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
fix-regex:
|
|
regex: VersionSSL30
|
|
replacement: VersionTLS13
|
|
pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}'
|
|
- id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher
|
|
message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered
|
|
weak. Use the function 'tls.CipherSuites()' to get a list of good cipher suites.
|
|
See https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other
|
|
cipher suites to use.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go
|
|
references:
|
|
- https://golang.org/pkg/crypto/tls/#InsecureCipherSuites
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher
|
|
shortlink: https://sg.run/px8N
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9118
|
|
rv_id: 1262927
|
|
rule_id: wdUJYk
|
|
version_id: rxTAKAZ
|
|
url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}}
|
|
- pattern: |
|
|
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}
|
|
- pattern: |
|
|
tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}
|
|
- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5
|
|
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use SHA256
|
|
or SHA3 instead.
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
source-rule-url: https://github.com/securego/gosec#available-rules
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5
|
|
shortlink: https://sg.run/2xB5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9119
|
|
rv_id: 1262928
|
|
rule_id: x8Un6q
|
|
version_id: bZT535Y
|
|
url: https://semgrep.dev/playground/r/bZT535Y/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
import "crypto/md5"
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
md5.New()
|
|
- pattern: |
|
|
md5.Sum(...)
|
|
- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1
|
|
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
|
|
collision resistant and is therefore not suitable as a cryptographic signature.
|
|
Use SHA256 or SHA3 instead.
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
source-rule-url: https://github.com/securego/gosec#available-rules
|
|
category: security
|
|
technology:
|
|
- go
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1
|
|
shortlink: https://sg.run/XBYA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9120
|
|
rv_id: 1262929
|
|
rule_id: OrU31O
|
|
version_id: NdTzyz1
|
|
url: https://semgrep.dev/playground/r/NdTzyz1/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
import "crypto/sha1"
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
sha1.New()
|
|
- pattern: |
|
|
sha1.Sum(...)
|
|
- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES
|
|
message: Detected DES cipher algorithm which is insecure. The algorithm is considered
|
|
weak and has been deprecated. Use AES instead.
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
source-rule-url: https://github.com/securego/gosec#available-rules
|
|
category: security
|
|
technology:
|
|
- go
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES
|
|
shortlink: https://sg.run/jREA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9121
|
|
rv_id: 1262930
|
|
rule_id: eqU8B3
|
|
version_id: kbTzGzA
|
|
url: https://semgrep.dev/playground/r/kbTzGzA/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
import "crypto/des"
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
des.NewTripleDESCipher(...)
|
|
- pattern: |
|
|
des.NewCipher(...)
|
|
- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4
|
|
message: Detected RC4 cipher algorithm which is insecure. The algorithm has many
|
|
known vulnerabilities. Use AES instead.
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
source-rule-url: https://github.com/securego/gosec#available-rules
|
|
category: security
|
|
technology:
|
|
- go
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4
|
|
shortlink: https://sg.run/1ZAD
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9122
|
|
rv_id: 1262931
|
|
rule_id: v8Unl0
|
|
version_id: w8TRoRQ
|
|
url: https://semgrep.dev/playground/r/w8TRoRQ/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
import "crypto/rc4"
|
|
...
|
|
- pattern: rc4.NewCipher(...)
|
|
- id: go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key
|
|
message: RSA keys should be at least 2048 bits
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/securego/gosec/blob/master/rules/rsa.go
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key
|
|
shortlink: https://sg.run/9oY4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9123
|
|
rv_id: 1262932
|
|
rule_id: d8UjY3
|
|
version_id: xyTjz8L
|
|
url: https://semgrep.dev/playground/r/xyTjz8L/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
rsa.GenerateKey(..., $BITS)
|
|
- pattern: |
|
|
rsa.GenerateMultiPrimeKey(..., $BITS)
|
|
- metavariable-comparison:
|
|
metavariable: $BITS
|
|
comparison: $BITS < 2048
|
|
- focus-metavariable:
|
|
- $BITS
|
|
fix: |
|
|
2048
|
|
- id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces
|
|
message: Detected a network listener listening on 0.0.0.0 or an empty string. This
|
|
could unexpectedly expose the server publicly as it binds to all available interfaces.
|
|
Instead, specify another IP address that is not 0.0.0.0 nor the empty string.
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
source-rule-url: https://github.com/securego/gosec
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces
|
|
shortlink: https://sg.run/rdE0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9125
|
|
rv_id: 1262939
|
|
rule_id: nJUz3J
|
|
version_id: ExTExoK
|
|
url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...)
|
|
- pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...)
|
|
- pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...)
|
|
- pattern: net.Listen($NETWORK, "=~/^:.*$/", ...)
|
|
- id: go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
http.Cookie{
|
|
...,
|
|
HttpOnly: true,
|
|
...,
|
|
}
|
|
- pattern: |
|
|
http.Cookie{
|
|
...,
|
|
}
|
|
message: A session cookie was detected without setting the 'HttpOnly' flag. The
|
|
'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts
|
|
from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by
|
|
setting 'HttpOnly' to 'true' in the Cookie.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go
|
|
- https://golang.org/src/net/http/cookie.go
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly
|
|
shortlink: https://sg.run/b73e
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9126
|
|
rv_id: 1262940
|
|
rule_id: EwU2Z6
|
|
version_id: 7ZTE3BW
|
|
url: https://semgrep.dev/playground/r/7ZTE3BW/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly
|
|
origin: community
|
|
fix-regex:
|
|
regex: (HttpOnly\s*:\s+)false
|
|
replacement: \1true
|
|
severity: WARNING
|
|
languages:
|
|
- go
|
|
- id: go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
http.Cookie{
|
|
...,
|
|
Secure: true,
|
|
...,
|
|
}
|
|
- pattern: |
|
|
http.Cookie{
|
|
...,
|
|
}
|
|
message: A session cookie was detected without setting the 'Secure' flag. The 'secure'
|
|
flag for cookies prevents the client from transmitting the cookie over insecure
|
|
channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in
|
|
the Options struct.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go
|
|
- https://golang.org/src/net/http/cookie.go
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure
|
|
shortlink: https://sg.run/N4G7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9127
|
|
rv_id: 1262941
|
|
rule_id: 7KUQ8X
|
|
version_id: LjTkgGE
|
|
url: https://semgrep.dev/playground/r/LjTkgGE/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure
|
|
origin: community
|
|
fix-regex:
|
|
regex: (Secure\s*:\s+)false
|
|
replacement: \1true
|
|
severity: WARNING
|
|
languages:
|
|
- go
|
|
- id: go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace
|
|
message: Detected a potentially dynamic ClientTrace. This occurred because semgrep
|
|
could not find a static definition for '$TRACE'. Dynamic ClientTraces are dangerous
|
|
because they deserialize function code to run when certain Request events occur,
|
|
which could lead to code being run without your knowledge. Ensure that your ClientTrace
|
|
is statically defined.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-913: Improper Control of Dynamically-Managed Code Resources'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://github.com/returntocorp/semgrep-rules/issues/518
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace
|
|
shortlink: https://sg.run/kXEK
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9128
|
|
rv_id: 1262942
|
|
rule_id: L1Uyjp
|
|
version_id: 8KT5rNv
|
|
url: https://semgrep.dev/playground/r/8KT5rNv/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace
|
|
origin: community
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
package $PACKAGE
|
|
...
|
|
&httptrace.ClientTrace { ... }
|
|
...
|
|
- pattern: httptrace.WithClientTrace($ANY, $TRACE)
|
|
severity: WARNING
|
|
languages:
|
|
- go
|
|
- id: go.lang.security.audit.net.formatted-template-string.formatted-template-string
|
|
message: Found a formatted template string passed to 'template.HTML()'. 'template.HTML()'
|
|
does not escape contents. Be absolutely sure there is no user-controlled data
|
|
in this template. If user data can reach this template, you may have a XSS vulnerability.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://golang.org/pkg/html/template/#HTML
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/go.lang.security.audit.net.formatted-template-string.formatted-template-string
|
|
shortlink: https://sg.run/weE0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9129
|
|
rv_id: 1262943
|
|
rule_id: 8GUjDW
|
|
version_id: gETB7Pe
|
|
url: https://semgrep.dev/playground/r/gETB7Pe/go.lang.security.audit.net.formatted-template-string.formatted-template-string
|
|
origin: community
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-not: template.HTML("..." + "...")
|
|
- pattern-either:
|
|
- pattern: template.HTML($T + $X, ...)
|
|
- pattern: template.HTML(fmt.$P("...", ...), ...)
|
|
- pattern: |
|
|
$T = "..."
|
|
...
|
|
$T = $FXN(..., $T, ...)
|
|
...
|
|
template.HTML($T, ...)
|
|
- pattern: |
|
|
$T = fmt.$P("...", ...)
|
|
...
|
|
template.HTML($T, ...)
|
|
- pattern: |
|
|
$T, $ERR = fmt.$P("...", ...)
|
|
...
|
|
template.HTML($T, ...)
|
|
- pattern: |
|
|
$T = $X + $Y
|
|
...
|
|
template.HTML($T, ...)
|
|
- pattern: |-
|
|
$T = "..."
|
|
...
|
|
$OTHER, $ERR = fmt.$P(..., $T, ...)
|
|
...
|
|
template.HTML($OTHER, ...)
|
|
- id: go.lang.security.audit.net.use-tls.use-tls
|
|
pattern: http.ListenAndServe($ADDR, $HANDLER)
|
|
fix: http.ListenAndServeTLS($ADDR, certFile, keyFile, $HANDLER)
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://golang.org/pkg/net/http/#ListenAndServeTLS
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/go.lang.security.audit.net.use-tls.use-tls
|
|
shortlink: https://sg.run/dKbY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9134
|
|
rv_id: 1262948
|
|
rule_id: PeUZ8X
|
|
version_id: JdTzxkn
|
|
url: https://semgrep.dev/playground/r/JdTzxkn/go.lang.security.audit.net.use-tls.use-tls
|
|
origin: community
|
|
message: Found an HTTP server without TLS. Use 'http.ListenAndServeTLS' instead.
|
|
See https://golang.org/pkg/net/http/#ListenAndServeTLS for more information.
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
- id: go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf
|
|
patterns:
|
|
- pattern-inside: |
|
|
func $FUNC(..., $W http.ResponseWriter, ...) {
|
|
...
|
|
var $TEMPLATE = "..."
|
|
...
|
|
$W.Write([]byte(fmt.$PRINTF($TEMPLATE, ...)), ...)
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern: |
|
|
$PARAMS = r.URL.Query()
|
|
...
|
|
$DATA, $ERR := $PARAMS[...]
|
|
...
|
|
$INTERM = $ANYTHING(..., $DATA, ...)
|
|
...
|
|
$W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...)))
|
|
- pattern: |
|
|
$PARAMS = r.URL.Query()
|
|
...
|
|
$DATA, $ERR := $PARAMS[...]
|
|
...
|
|
$INTERM = $DATA[...]
|
|
...
|
|
$W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...)))
|
|
- pattern: |
|
|
$DATA, $ERR := r.URL.Query()[...]
|
|
...
|
|
$INTERM = $DATA[...]
|
|
...
|
|
$W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...)))
|
|
- pattern: |
|
|
$DATA, $ERR := r.URL.Query()[...]
|
|
...
|
|
$INTERM = $ANYTHING(..., $DATA, ...)
|
|
...
|
|
$W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...)))
|
|
- pattern: |
|
|
$PARAMS = r.URL.Query()
|
|
...
|
|
$DATA, $ERR := $PARAMS[...]
|
|
...
|
|
$W.Write([]byte(fmt.$PRINTF(..., $DATA, ...)))
|
|
message: Found data going from url query parameters into formatted data written
|
|
to ResponseWriter. This could be XSS and should not be done. If you must do this,
|
|
ensure your data is sanitized or escaped.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf
|
|
shortlink: https://sg.run/Zvon
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9135
|
|
rv_id: 1262949
|
|
rule_id: JDUyXB
|
|
version_id: 5PTo1qr
|
|
url: https://semgrep.dev/playground/r/5PTo1qr/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- go
|
|
- id: java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
technology:
|
|
- java
|
|
- secrets
|
|
- jwt
|
|
category: security
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret
|
|
shortlink: https://sg.run/RoDK
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9149
|
|
rv_id: 1262980
|
|
rule_id: oqUeAn
|
|
version_id: d6Tyx8j
|
|
url: https://semgrep.dev/playground/r/d6Tyx8j/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret
|
|
origin: community
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(Algorithm $ALG) = $ALGO.$HMAC("$Y");
|
|
- pattern: |
|
|
$SECRET = "$Y";
|
|
...
|
|
(Algorithm $ALG) = $ALGO.$HMAC($SECRET);
|
|
- pattern: |
|
|
class $CLASS {
|
|
...
|
|
$TYPE $SECRET = "$Y";
|
|
...
|
|
$RETURNTYPE $FUNC (...) {
|
|
...
|
|
(Algorithm $ALG) = $ALGO.$HMAC($SECRET);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- focus-metavariable: $Y
|
|
- metavariable-regex:
|
|
metavariable: $HMAC
|
|
regex: (HMAC384|HMAC256|HMAC512)
|
|
- id: java.java-jwt.security.jwt-none-alg.java-jwt-none-alg
|
|
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
|
|
assumes the integrity of the token has already been verified. This would allow
|
|
a malicious actor to forge a JWT token that will automatically be verified. Do
|
|
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg
|
|
shortlink: https://sg.run/Av14
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9150
|
|
rv_id: 1262981
|
|
rule_id: zdUkzR
|
|
version_id: ZRTKADq
|
|
url: https://semgrep.dev/playground/r/ZRTKADq/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg
|
|
origin: community
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
pattern-either:
|
|
- pattern: |
|
|
$JWT.sign(com.auth0.jwt.algorithms.Algorithm.none());
|
|
- pattern: |
|
|
$NONE = com.auth0.jwt.algorithms.Algorithm.none();
|
|
...
|
|
$JWT.sign($NONE);
|
|
- pattern: |-
|
|
class $CLASS {
|
|
...
|
|
$TYPE $NONE = com.auth0.jwt.algorithms.Algorithm.none();
|
|
...
|
|
$RETURNTYPE $FUNC (...) {
|
|
...
|
|
$JWT.sign($NONE);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- id: java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify
|
|
message: Detected the decoding of a JWT token without a verify step. JWT tokens
|
|
must be verified before use, otherwise the token's integrity is unknown. This
|
|
means a malicious actor could forge a JWT token with any claims. Call '.verify()'
|
|
before using the token.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-345: Insufficient Verification of Data Authenticity'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify
|
|
shortlink: https://sg.run/Bk95
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9151
|
|
rv_id: 1262979
|
|
rule_id: pKUOE9
|
|
version_id: vdT06Lp
|
|
url: https://semgrep.dev/playground/r/vdT06Lp/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify
|
|
origin: community
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern: |
|
|
com.auth0.jwt.JWT.decode(...);
|
|
- pattern-not-inside: |-
|
|
class $CLASS {
|
|
...
|
|
$RETURNTYPE $FUNC (...) {
|
|
...
|
|
$VERIFIER.verify(...);
|
|
...
|
|
}
|
|
}
|
|
- id: java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal
|
|
metadata:
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN
|
|
references:
|
|
- https://www.owasp.org/index.php/Path_Traversal
|
|
category: security
|
|
technology:
|
|
- jax-rs
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal
|
|
shortlink: https://sg.run/DoWj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9152
|
|
rv_id: 1262984
|
|
rule_id: 2ZUb9l
|
|
version_id: 7ZTE3KW
|
|
url: https://semgrep.dev/playground/r/7ZTE3KW/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal
|
|
origin: community
|
|
message: Detected a potential path traversal. A malicious actor could control the
|
|
location of this file, to include going backwards in the directory with '../'.
|
|
To address this, ensure that user-controlled variables in file paths are sanitized.
|
|
You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...)
|
|
to only retrieve the file name from the path.
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
pattern-either:
|
|
- pattern: |
|
|
$RETURNTYPE $FUNC (..., @PathParam(...) $TYPE $VAR, ...) {
|
|
...
|
|
new File(..., $VAR, ...);
|
|
...
|
|
}
|
|
- pattern: |-
|
|
$RETURNTYPE $FUNC (..., @javax.ws.rs.PathParam(...) $TYPE $VAR, ...) {
|
|
...
|
|
new File(..., $VAR, ...);
|
|
...
|
|
}
|
|
- id: java.jboss.security.session_sqli.find-sql-string-concatenation
|
|
message: In $METHOD, $X is used to construct a SQL query via string concatenation.
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
pattern-either:
|
|
- pattern: |
|
|
$RETURN $METHOD(...,String $X,...){
|
|
...
|
|
Session $SESSION = ...;
|
|
...
|
|
String $QUERY = ... + $X + ...;
|
|
...
|
|
PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY);
|
|
...
|
|
ResultSet $RESULT = $PS.executeQuery();
|
|
...
|
|
}
|
|
- pattern: |
|
|
$RETURN $METHOD(...,String $X,...){
|
|
...
|
|
String $QUERY = ... + $X + ...;
|
|
...
|
|
Session $SESSION = ...;
|
|
...
|
|
PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY);
|
|
...
|
|
ResultSet $RESULT = $PS.executeQuery();
|
|
...
|
|
}
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- jboss
|
|
confidence: MEDIUM
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/java.jboss.security.session_sqli.find-sql-string-concatenation
|
|
shortlink: https://sg.run/W8kA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9153
|
|
rv_id: 1262986
|
|
rule_id: X5U8rQ
|
|
version_id: 8KT5r3v
|
|
url: https://semgrep.dev/playground/r/8KT5r3v/java.jboss.security.session_sqli.find-sql-string-concatenation
|
|
origin: community
|
|
- id: java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN
|
|
references:
|
|
- https://www.owasp.org/index.php/Path_Traversal
|
|
category: security
|
|
technology:
|
|
- java
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal
|
|
shortlink: https://sg.run/oxXN
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9160
|
|
rv_id: 1263064
|
|
rule_id: NbUk7X
|
|
version_id: zyTb2rq
|
|
url: https://semgrep.dev/playground/r/zyTb2rq/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal
|
|
origin: community
|
|
message: Detected a potential path traversal. A malicious actor could control the
|
|
location of this file, to include going backwards in the directory with '../'.
|
|
To address this, ensure that user-controlled variables in file paths are sanitized.
|
|
You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...)
|
|
to only retrieve the file name from the path.
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(HttpServletRequest $REQ)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);
|
|
...
|
|
for (javax.servlet.http.Cookie $COOKIE: $COOKIES) {
|
|
...
|
|
}
|
|
- pattern: |
|
|
$COOKIE.getValue(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(...);
|
|
...
|
|
- pattern: |
|
|
$PARAM = $VALS[$INDEX];
|
|
pattern-sanitizers:
|
|
- pattern: org.apache.commons.io.FilenameUtils.getName(...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(java.io.File $FILE) = ...
|
|
- pattern: |
|
|
(java.io.FileOutputStream $FOS) = ...
|
|
- pattern: |
|
|
new java.io.FileInputStream(...)
|
|
severity: ERROR
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.3 Insecue Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities-wp.pdf
|
|
category: security
|
|
technology:
|
|
- java
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization
|
|
shortlink: https://sg.run/zvO1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9161
|
|
rv_id: 1263065
|
|
rule_id: kxUk12
|
|
version_id: pZT03A1
|
|
url: https://semgrep.dev/playground/r/pZT03A1/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization
|
|
origin: community
|
|
message: JMS Object messages depend on Java Serialization for marshalling/unmarshalling
|
|
of the message payload when ObjectMessage.getObject() is called. Deserialization
|
|
of untrusted data can lead to security flaws; a remote attacker could via a crafted
|
|
JMS ObjectMessage to execute arbitrary code with the permissions of the application
|
|
listening/consuming JMS Messages. In this case, the JMS MessageListener consume
|
|
an ObjectMessage type received inside the onMessage method, which may lead to
|
|
arbitrary code execution when calling the $Y.getObject method.
|
|
patterns:
|
|
- pattern-inside: |
|
|
public class $JMS_LISTENER implements MessageListener {
|
|
...
|
|
public void onMessage(Message $JMS_MSG) {
|
|
...
|
|
}
|
|
}
|
|
- pattern-either:
|
|
- pattern-inside: $X = $Y.getObject(...);
|
|
- pattern-inside: $X = ($Z) $Y.getObject(...);
|
|
- id: java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss
|
|
message: 'Cross-site scripting detected in HttpServletResponse writer with variable
|
|
''$VAR''. User input was detected going directly from the HttpServletRequest into
|
|
output. Ensure your data is properly encoded using org.owasp.encoder.Encode.forHtml:
|
|
''Encode.forHtml($VAR)''.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_SERVLET
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss
|
|
shortlink: https://sg.run/pxjN
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9162
|
|
rv_id: 1263066
|
|
rule_id: wdUJOk
|
|
version_id: 2KTv2EG
|
|
url: https://semgrep.dev/playground/r/2KTv2EG/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss
|
|
origin: community
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-inside: $TYPE $FUNC(..., HttpServletResponse $RESP, ...) { ... }
|
|
- pattern-inside: $VAR = $REQ.getParameter(...); ...
|
|
- pattern-either:
|
|
- pattern: $RESP.getWriter(...).write(..., $VAR, ...);
|
|
- pattern: |
|
|
$WRITER = $RESP.getWriter(...);
|
|
...
|
|
$WRITER.write(..., $VAR, ...);
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#xmlinputfactory-a-stax-parser
|
|
category: security
|
|
technology:
|
|
- java
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe
|
|
shortlink: https://sg.run/XBwA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9164
|
|
rv_id: 1263069
|
|
rule_id: OrU35O
|
|
version_id: 1QTypQZ
|
|
url: https://semgrep.dev/playground/r/1QTypQZ/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe
|
|
origin: community
|
|
message: XML external entities are not explicitly disabled for this XMLInputFactory.
|
|
This could be vulnerable to XML external entity vulnerabilities. Explicitly disable
|
|
external entities by setting "javax.xml.stream.isSupportingExternalEntities" to
|
|
false.
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
$METHOD(...) {
|
|
...
|
|
$XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
$METHOD(...) {
|
|
...
|
|
$XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, false);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
$METHOD(...) {
|
|
...
|
|
$XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", Boolean.FALSE);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
$METHOD(...) {
|
|
...
|
|
$XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, Boolean.FALSE);
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern: javax.xml.stream.XMLInputFactory.newFactory(...)
|
|
- pattern: new XMLInputFactory(...)
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BLOWFISH_KEY_SIZE
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size
|
|
shortlink: https://sg.run/9o74
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9167
|
|
rv_id: 1262989
|
|
rule_id: d8UjJ3
|
|
version_id: 3ZT4X2r
|
|
url: https://semgrep.dev/playground/r/3ZT4X2r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size
|
|
origin: community
|
|
message: Using less than 128 bits for Blowfish is considered insecure. Use 128 bits
|
|
or more, or switch to use AES instead.
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
patterns:
|
|
- pattern: |
|
|
$KEYGEN = KeyGenerator.getInstance("Blowfish");
|
|
...
|
|
$KEYGEN.init($SIZE);
|
|
- metavariable-comparison:
|
|
metavariable: $SIZE
|
|
comparison: $SIZE < 128
|
|
- id: java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle
|
|
message: Using CBC with PKCS5Padding is susceptible to padding oracle attacks. A
|
|
malicious actor could discern the difference between plaintext with valid or invalid
|
|
padding. Further, CBC mode does not include any integrity checks. Use 'AES/GCM/NoPadding'
|
|
instead.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PADDING_ORACLE
|
|
references:
|
|
- https://capec.mitre.org/data/definitions/463.html
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes
|
|
- https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle
|
|
shortlink: https://sg.run/ydxr
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9168
|
|
rv_id: 1262990
|
|
rule_id: ZqU5oD
|
|
version_id: 44TEjbE
|
|
url: https://semgrep.dev/playground/r/44TEjbE/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle
|
|
origin: community
|
|
severity: WARNING
|
|
fix: |
|
|
"AES/GCM/NoPadding"
|
|
languages:
|
|
- java
|
|
patterns:
|
|
- pattern-inside: Cipher.getInstance("=~/.*\/CBC\/PKCS5Padding/")
|
|
- pattern: |
|
|
"=~/.*\/CBC\/PKCS5Padding/"
|
|
- id: java.lang.security.audit.crlf-injection-logs.crlf-injection-logs
|
|
message: When data from an untrusted source is put into a logger and not neutralized
|
|
correctly, an attacker could forge log entries or include malicious content.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-93: Improper Neutralization of CRLF Sequences (''CRLF Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#CRLF_INJECTION_LOGS
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs
|
|
shortlink: https://sg.run/wek0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9173
|
|
rv_id: 1262995
|
|
rule_id: 8GUjwW
|
|
version_id: RGT0LEr
|
|
url: https://semgrep.dev/playground/r/RGT0LEr/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
class $CLASS {
|
|
...
|
|
Logger $LOG = ...;
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$X $METHOD(...,HttpServletRequest $REQ,...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$X $METHOD(...,ServletRequest $REQ,...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$X $METHOD(...) {
|
|
...
|
|
HttpServletRequest $REQ = ...;
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$X $METHOD(...) {
|
|
...
|
|
ServletRequest $REQ = ...;
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$X $METHOD(...) {
|
|
...
|
|
Logger $LOG = ...;
|
|
...
|
|
HttpServletRequest $REQ = ...;
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$X $METHOD(...) {
|
|
...
|
|
Logger $LOG = ...;
|
|
...
|
|
ServletRequest $REQ = ...;
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern: |
|
|
String $VAL = $REQ.getParameter(...);
|
|
...
|
|
$LOG.$LEVEL(<... $VAL ...>);
|
|
- pattern: |
|
|
String $VAL = $REQ.getParameter(...);
|
|
...
|
|
$LOG.log($LEVEL,<... $VAL ...>);
|
|
- pattern: |
|
|
$LOG.$LEVEL(<... $REQ.getParameter(...) ...>);
|
|
- pattern: |
|
|
$LOG.log($LEVEL,<... $REQ.getParameter(...) ...>);
|
|
- id: java.lang.security.audit.formatted-sql-string.formatted-sql-string
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.5 Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
|
|
- https://docs.oracle.com/javase/tutorial/jdbc/basics/prepared.html#create_ps
|
|
- https://software-security.sans.org/developer-how-to/fix-sql-injection-in-java-using-prepared-callable-statement
|
|
category: security
|
|
technology:
|
|
- java
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.formatted-sql-string.formatted-sql-string
|
|
shortlink: https://sg.run/OPXp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9175
|
|
rv_id: 1409389
|
|
rule_id: QrUzxR
|
|
version_id: ExTeyBP
|
|
url: https://semgrep.dev/playground/r/ExTeyBP/java.lang.security.audit.formatted-sql-string.formatted-sql-string
|
|
origin: community
|
|
options:
|
|
taint_assume_safe_numbers: true
|
|
taint_assume_safe_booleans: true
|
|
message: Detected a formatted string in a SQL statement. This could lead to SQL
|
|
injection if variables in the SQL statement are not properly sanitized. Use a
|
|
prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement
|
|
using 'connection.prepareStatement'.
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(HttpServletRequest $REQ)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ANNOT $FUNC (..., $INPUT, ...) {
|
|
...
|
|
}
|
|
- pattern: (String $INPUT)
|
|
- focus-metavariable: $INPUT
|
|
label: INPUT
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $X + $INPUT
|
|
- pattern: $X += $INPUT
|
|
- pattern: String.format(..., $INPUT, ...)
|
|
- pattern: String.join(..., $INPUT, ...)
|
|
- pattern: (String $STR).concat($INPUT)
|
|
- pattern: $INPUT.concat(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $STRB.append($INPUT)
|
|
- pattern: new $STRB(..., $INPUT, ...)
|
|
- metavariable-type:
|
|
metavariable: $STRB
|
|
type: StringBuilder
|
|
label: CONCAT
|
|
requires: INPUT
|
|
pattern-propagators:
|
|
- pattern: (StringBuffer $S).append($X)
|
|
from: $X
|
|
to: $S
|
|
- pattern: (StringBuilder $S).append($X)
|
|
from: $X
|
|
to: $S
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE *$/" ...>)
|
|
- pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE %s$/" ...>)
|
|
- pattern-either:
|
|
- pattern: (Statement $S).$SQLFUNC(...)
|
|
- pattern: (PreparedStatement $P).$SQLFUNC(...)
|
|
- pattern: (Connection $C).createStatement(...).$SQLFUNC(...)
|
|
- pattern: (Connection $C).prepareStatement(...).$SQLFUNC(...)
|
|
- pattern: (EntityManager $EM).$SQLFUNC(...)
|
|
- metavariable-regex:
|
|
metavariable: $SQLFUNC
|
|
regex: execute|executeQuery|createQuery|query|addBatch|nativeSQL|create|prepare
|
|
requires: CONCAT
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: (CriteriaBuilder $CB).$ANY(...)
|
|
severity: ERROR
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.http-response-splitting.http-response-splitting
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP
|
|
Request/Response Splitting'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTP_RESPONSE_SPLITTING
|
|
references:
|
|
- https://www.owasp.org/index.php/HTTP_Response_Splitting
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/java.lang.security.audit.http-response-splitting.http-response-splitting
|
|
shortlink: https://sg.run/eL0l
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9176
|
|
rv_id: 1263023
|
|
rule_id: 3qUPyK
|
|
version_id: X0Tzykw
|
|
url: https://semgrep.dev/playground/r/X0Tzykw/java.lang.security.audit.http-response-splitting.http-response-splitting
|
|
origin: community
|
|
message: Older Java application servers are vulnerable to HTTP response splitting,
|
|
which may occur if an HTTP request can be injected with CRLF characters. This
|
|
finding is reported for completeness; it is recommended to ensure your environment
|
|
is not affected by testing this yourself.
|
|
severity: INFO
|
|
languages:
|
|
- java
|
|
pattern-either:
|
|
- pattern: |
|
|
$VAR = $REQ.getParameter(...);
|
|
...
|
|
$COOKIE = new Cookie(..., $VAR, ...);
|
|
...
|
|
$RESP.addCookie($COOKIE, ...);
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$RETTYPE $FUNC(...,@PathVariable $TYPE $VAR, ...) {
|
|
...
|
|
}
|
|
- pattern: |
|
|
$COOKIE = new Cookie(..., $VAR, ...);
|
|
...
|
|
$RESP.addCookie($COOKIE, ...);
|
|
- id: java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-297: Improper Validation of Certificate with Host Mismatch'
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_SMTP_SSL
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection
|
|
shortlink: https://sg.run/vzN4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9177
|
|
rv_id: 1263024
|
|
rule_id: 4bUkrW
|
|
version_id: jQTn5Dv
|
|
url: https://semgrep.dev/playground/r/jQTn5Dv/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection
|
|
origin: community
|
|
message: Insecure SMTP connection detected. This connection will trust any SSL certificate.
|
|
Enable certificate verification by setting 'email.setSSLCheckServerIdentity(true)'.
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
$EMAIL.setSSLCheckServerIdentity(true);
|
|
...
|
|
- pattern-inside: |
|
|
$EMAIL = new SimpleEmail(...);
|
|
...
|
|
- pattern: $EMAIL.send(...);
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.unvalidated-redirect.unvalidated-redirect
|
|
message: Application redirects to a destination URL specified by a user-supplied
|
|
parameter that is not validated. This could direct users to malicious locations.
|
|
Consider using an allowlist to validate URLs.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.1.5 Open Redirect
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation-requirements
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
subcategory:
|
|
- vuln
|
|
impact: LOW
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Open Redirect
|
|
source: https://semgrep.dev/r/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect
|
|
shortlink: https://sg.run/Q51P
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9186
|
|
rv_id: 1263048
|
|
rule_id: WAUo0p
|
|
version_id: PkTR329
|
|
url: https://semgrep.dev/playground/r/PkTR329/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
pattern-either:
|
|
- pattern: |
|
|
$X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) {
|
|
...
|
|
$RES.sendRedirect($URL);
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) {
|
|
...
|
|
$RES.sendRedirect($URL);
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {
|
|
...
|
|
String $URL = $REQ.getParameter(...);
|
|
...
|
|
$RES.sendRedirect($URL);
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {
|
|
...
|
|
String $URL = $REQ.getParameter(...);
|
|
...
|
|
$RES.sendRedirect($URL);
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,String $URL,...) {
|
|
...
|
|
HttpServletResponse $RES = ...;
|
|
...
|
|
$RES.sendRedirect($URL);
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {
|
|
...
|
|
$RES.sendRedirect($REQ.getParameter(...));
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {
|
|
...
|
|
$RES.sendRedirect($REQ.getParameter(...));
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) {
|
|
...
|
|
$RES.addHeader("Location",$URL);
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) {
|
|
...
|
|
$RES.addHeader("Location",$URL);
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {
|
|
...
|
|
String $URL = $REQ.getParameter(...);
|
|
...
|
|
$RES.addHeader("Location",$URL);
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {
|
|
...
|
|
String $URL = $REQ.getParameter(...);
|
|
...
|
|
$RES.addHeader("Location",$URL);
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,String $URL,...) {
|
|
...
|
|
HttpServletResponse $RES = ...;
|
|
...
|
|
$RES.addHeader("Location",$URL);
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {
|
|
...
|
|
$RES.addHeader("Location",$REQ.getParameter(...));
|
|
...
|
|
}
|
|
- pattern: |-
|
|
$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {
|
|
...
|
|
$RES.addHeader("Location",$REQ.getParameter(...));
|
|
...
|
|
}
|
|
- id: java.lang.security.audit.weak-ssl-context.weak-ssl-context
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source_rule_url: https://find-sec-bugs.github.io/bugs.htm#SSL_CONTEXT
|
|
references:
|
|
- https://tools.ietf.org/html/rfc7568
|
|
- https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.weak-ssl-context.weak-ssl-context
|
|
shortlink: https://sg.run/4x7E
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9188
|
|
rv_id: 1263050
|
|
rule_id: KxUb1k
|
|
version_id: 5PTo1rW
|
|
url: https://semgrep.dev/playground/r/5PTo1rW/java.lang.security.audit.weak-ssl-context.weak-ssl-context
|
|
origin: community
|
|
message: An insecure SSL context was detected. TLS versions 1.0, 1.1, and all SSL
|
|
versions are considered weak encryption and are deprecated. Use SSLContext.getInstance("TLSv1.2")
|
|
for the best security.
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
patterns:
|
|
- pattern-not: SSLContext.getInstance("TLSv1.3")
|
|
- pattern-not: SSLContext.getInstance("TLSv1.2")
|
|
- pattern: SSLContext.getInstance("...")
|
|
fix-regex:
|
|
regex: (.*?)\.getInstance\(.*?\)
|
|
replacement: \1.getInstance("TLSv1.2")
|
|
- id: java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated
|
|
message: DES is considered deprecated. AES is the recommended cipher. Upgrade to
|
|
use AES. See https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard
|
|
for more information.
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::javax.crypto
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DES_USAGE
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
references:
|
|
- https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated
|
|
shortlink: https://sg.run/5Q73
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9191
|
|
rv_id: 1262996
|
|
rule_id: PeUZNg
|
|
version_id: A8TgdEn
|
|
url: https://semgrep.dev/playground/r/A8TgdEn/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated
|
|
origin: community
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $CIPHER.getInstance("=~/DES/.*/")
|
|
- pattern-inside: $CIPHER.getInstance("DES")
|
|
- pattern-either:
|
|
- pattern: |
|
|
"=~/DES/.*/"
|
|
- pattern: |
|
|
"DES"
|
|
fix: |
|
|
"AES/GCM/NoPadding"
|
|
languages:
|
|
- java
|
|
- kt
|
|
- id: java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated
|
|
message: Triple DES (3DES or DESede) is considered deprecated. AES is the recommended
|
|
cipher. Upgrade to use AES.
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::javax.crypto
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#TDES_USAGE
|
|
references:
|
|
- https://csrc.nist.gov/News/2017/Update-to-Current-Use-and-Deprecation-of-TDEA
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated
|
|
shortlink: https://sg.run/Geqn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9192
|
|
rv_id: 1262997
|
|
rule_id: JDUy8J
|
|
version_id: BjTkZyQ
|
|
url: https://semgrep.dev/playground/r/BjTkZyQ/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated
|
|
origin: community
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$CIPHER.getInstance("=~/DESede.*/")
|
|
- pattern: |
|
|
$CRYPTO.KeyGenerator.getInstance("DES")
|
|
languages:
|
|
- java
|
|
- kt
|
|
- id: java.lang.security.audit.crypto.ecb-cipher.ecb-cipher
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::mode::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher
|
|
shortlink: https://sg.run/Ro9K
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9193
|
|
rv_id: 1262998
|
|
rule_id: 5rUOb6
|
|
version_id: DkTRbwL
|
|
url: https://semgrep.dev/playground/r/DkTRbwL/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher
|
|
origin: community
|
|
message: Cipher in ECB mode is detected. ECB mode produces the same output for the
|
|
same input each time which allows an attacker to intercept and replay the data.
|
|
Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY.
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
patterns:
|
|
- pattern: |
|
|
Cipher $VAR = $CIPHER.getInstance($MODE);
|
|
- metavariable-regex:
|
|
metavariable: $MODE
|
|
regex: .*ECB.*
|
|
- id: java.lang.security.audit.crypto.no-null-cipher.no-null-cipher
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: new NullCipher(...);
|
|
- pattern: new javax.crypto.NullCipher(...);
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher
|
|
shortlink: https://sg.run/AvA4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9194
|
|
rv_id: 1263001
|
|
rule_id: GdU7pw
|
|
version_id: K3TKkgB
|
|
url: https://semgrep.dev/playground/r/K3TKkgB/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher
|
|
origin: community
|
|
message: 'NullCipher was detected. This will not encrypt anything; the cipher text
|
|
will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING").
|
|
See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for
|
|
more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector
|
|
message: Initialization Vectors (IVs) for block ciphers should be randomly generated
|
|
each time they are used. Using a static IV means the same plaintext encrypts to
|
|
the same ciphertext every time, weakening the strength of the encryption.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-329: Generation of Predictable IV with CBC Mode'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#STATIC_IV
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/329.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector
|
|
shortlink: https://sg.run/BkB5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9195
|
|
rv_id: 1263002
|
|
rule_id: ReUgj1
|
|
version_id: qkTR7vP
|
|
url: https://semgrep.dev/playground/r/qkTR7vP/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
pattern-either:
|
|
- pattern: |
|
|
byte[] $IV = {
|
|
...
|
|
};
|
|
...
|
|
new IvParameterSpec($IV, ...);
|
|
- pattern: |
|
|
class $CLASS {
|
|
byte[] $IV = {
|
|
...
|
|
};
|
|
...
|
|
$METHOD(...) {
|
|
...
|
|
new IvParameterSpec($IV, ...);
|
|
...
|
|
}
|
|
}
|
|
- id: java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::mode::javax.crypto
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_NO_PADDING
|
|
references:
|
|
- https://rdist.root.org/2009/10/06/why-rsa-encryption-padding-is-critical/
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
- kotlin
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding
|
|
shortlink: https://sg.run/DoOj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9196
|
|
rv_id: 1263003
|
|
rule_id: AbUzoj
|
|
version_id: l4TJRpK
|
|
url: https://semgrep.dev/playground/r/l4TJRpK/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding
|
|
origin: community
|
|
message: Using RSA without OAEP mode weakens the encryption.
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- kt
|
|
pattern: $CIPHER.getInstance("=~/RSA/[Nn][Oo][Nn][Ee]/NoPadding/")
|
|
- id: java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket
|
|
metadata:
|
|
functional-categories:
|
|
- net::search::crypto-config::java.net
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket
|
|
shortlink: https://sg.run/W8zA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9197
|
|
rv_id: 1263008
|
|
rule_id: BYUN3X
|
|
version_id: RGT0LEj
|
|
url: https://semgrep.dev/playground/r/RGT0LEj/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket
|
|
origin: community
|
|
message: Detected use of a Java socket that is not encrypted. As a result, the traffic
|
|
could be read by an attacker intercepting the network traffic. Use an SSLSocket
|
|
created by 'SSLSocketFactory' or 'SSLServerSocketFactory' instead.
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
pattern-either:
|
|
- pattern: new ServerSocket(...)
|
|
- pattern: new Socket(...)
|
|
- id: java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key
|
|
message: RSA keys should be at least 2048 bits based on NIST recommendation.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::key-length::java.security
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key
|
|
shortlink: https://sg.run/4x6x
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9200
|
|
rv_id: 1263019
|
|
rule_id: 0oU5P5
|
|
version_id: o5TbDLY
|
|
url: https://semgrep.dev/playground/r/o5TbDLY/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key
|
|
origin: community
|
|
patterns:
|
|
- pattern: |
|
|
KeyPairGenerator $KEY = $G.getInstance("RSA");
|
|
...
|
|
$KEY.initialize($BITS);
|
|
- metavariable-comparison:
|
|
metavariable: $BITS
|
|
comparison: $BITS < 2048
|
|
- id: java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer
|
|
message: Detected a request with potential user-input going into a OutputStream
|
|
or Writer object. This bypasses any view or template environments, including HTML
|
|
escaping, which may expose this application to cross-site scripting (XSS) vulnerabilities.
|
|
Consider using a view technology such as JavaServer Faces (JSFs) which automatically
|
|
escapes HTML views.
|
|
severity: WARNING
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
cwe2021-top25: true
|
|
cwe2022-top25: true
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://www3.ntu.edu.sg/home/ehchua/programming/java/JavaServerFaces.html
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- java
|
|
- servlets
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer
|
|
shortlink: https://sg.run/KlRL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9211
|
|
rv_id: 1263055
|
|
rule_id: j2Uv7B
|
|
version_id: DkTRbXy
|
|
url: https://semgrep.dev/playground/r/DkTRbXy/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer
|
|
origin: community
|
|
languages:
|
|
- java
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(HttpServletRequest $REQ).$REQFUNC(...)
|
|
- pattern: "(ServletRequest $REQ).$REQFUNC(...) \n"
|
|
- metavariable-regex:
|
|
metavariable: $REQFUNC
|
|
regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(HttpServletResponse $RESPONSE).getWriter(...).$WRITE(...)
|
|
- pattern: |
|
|
(HttpServletResponse $RESPONSE).getOutputStream(...).$WRITE(...)
|
|
- pattern: |
|
|
(java.io.PrintWriter $WRITER).$WRITE(...)
|
|
- pattern: |
|
|
(PrintWriter $WRITER).$WRITE(...)
|
|
- pattern: |
|
|
(javax.servlet.ServletOutputStream $WRITER).$WRITE(...)
|
|
- pattern: |
|
|
(ServletOutputStream $WRITER).$WRITE(...)
|
|
- pattern: |
|
|
(java.io.OutputStream $WRITER).$WRITE(...)
|
|
- pattern: |
|
|
(OutputStream $WRITER).$WRITE(...)
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: Encode.forHtml(...)
|
|
- pattern: (PolicyFactory $POLICY).sanitize(...)
|
|
- pattern: (AntiSamy $AS).scan(...)
|
|
- pattern: JSoup.clean(...)
|
|
- pattern: org.apache.commons.lang.StringEscapeUtils.escapeHtml(...)
|
|
- pattern: org.springframework.web.util.HtmlUtils.htmlEscape(...)
|
|
- pattern: org.owasp.esapi.ESAPI.encoder().encodeForHTML(...)
|
|
- id: java.spring.security.audit.spring-sqli.spring-sqli
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: $ARG
|
|
- pattern-inside: |
|
|
public $T $M (..., String $ARG,...){...}
|
|
pattern-sanitizers:
|
|
- not_conflicting: true
|
|
pattern-either:
|
|
- patterns:
|
|
- focus-metavariable: $A
|
|
- pattern-inside: |
|
|
new $TYPE(...,$A,...);
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- focus-metavariable: $A
|
|
- pattern: |
|
|
new PreparedStatementCreatorFactory($A,...);
|
|
- patterns:
|
|
- focus-metavariable: $A
|
|
- pattern: |
|
|
(JdbcTemplate $T).$M($A,...)
|
|
- patterns:
|
|
- pattern: (String $A)
|
|
- pattern-inside: |
|
|
(JdbcTemplate $T).batchUpdate(...)
|
|
- patterns:
|
|
- focus-metavariable: $A
|
|
- pattern: |
|
|
NamedParameterBatchUpdateUtils.$M($A,...)
|
|
- patterns:
|
|
- focus-metavariable: $A
|
|
- pattern: |
|
|
BatchUpdateUtils.$M($A,...)
|
|
message: Detected a string argument from a public method contract in a raw SQL statement.
|
|
This could lead to SQL injection if variables in the SQL statement are not properly
|
|
sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You
|
|
can obtain a PreparedStatement using 'connection.prepareStatement'.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
options:
|
|
taint_assume_safe_numbers: true
|
|
taint_assume_safe_booleans: true
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
category: security
|
|
technology:
|
|
- spring
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/java.spring.security.audit.spring-sqli.spring-sqli
|
|
shortlink: https://sg.run/1Z3x
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9222
|
|
rv_id: 1263082
|
|
rule_id: eqU8N2
|
|
version_id: ZRTKAWW
|
|
url: https://semgrep.dev/playground/r/ZRTKAWW/java.spring.security.audit.spring-sqli.spring-sqli
|
|
origin: community
|
|
- id: java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect
|
|
message: Application redirects a user to a destination URL specified by a user supplied
|
|
parameter that is not validated.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT
|
|
category: security
|
|
technology:
|
|
- spring
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Open Redirect
|
|
source: https://semgrep.dev/r/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect
|
|
shortlink: https://sg.run/9oXz
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9223
|
|
rv_id: 1263083
|
|
rule_id: v8Un7w
|
|
version_id: nWT2Lk0
|
|
url: https://semgrep.dev/playground/r/nWT2Lk0/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
pattern-either:
|
|
- pattern: |
|
|
$X $METHOD(...,String $URL,...) {
|
|
return "redirect:" + $URL;
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,String $URL,...) {
|
|
...
|
|
String $REDIR = "redirect:" + $URL;
|
|
...
|
|
return $REDIR;
|
|
...
|
|
}
|
|
- pattern: |
|
|
$X $METHOD(...,String $URL,...) {
|
|
...
|
|
new ModelAndView("redirect:" + $URL);
|
|
...
|
|
}
|
|
- pattern: |-
|
|
$X $METHOD(...,String $URL,...) {
|
|
...
|
|
String $REDIR = "redirect:" + $URL;
|
|
...
|
|
new ModelAndView($REDIR);
|
|
...
|
|
}
|
|
- id: javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled
|
|
message: $sceProvider is set to false. Disabling Strict Contextual escaping (SCE)
|
|
in an AngularJS application could provide additional attack surface for XSS vulnerabilities.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
references:
|
|
- https://docs.angularjs.org/api/ng/service/$sce
|
|
- https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf
|
|
category: security
|
|
technology:
|
|
- angular
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled
|
|
shortlink: https://sg.run/N4DG
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9227
|
|
rv_id: 1263094
|
|
rule_id: EwU20Z
|
|
version_id: 5PTo1EW
|
|
url: https://semgrep.dev/playground/r/5PTo1EW/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
pattern: |
|
|
$sceProvider.enabled(false);
|
|
- id: javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method
|
|
message: The use of $sce.trustAs can be dangerous if unsanitized user input flows
|
|
through this API.
|
|
metadata:
|
|
references:
|
|
- https://docs.angularjs.org/api/ng/service/$sce
|
|
- https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf
|
|
category: security
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
technology:
|
|
- angular
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method
|
|
shortlink: https://sg.run/OPW2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9231
|
|
rv_id: 1263098
|
|
rule_id: gxU1QX
|
|
version_id: BjTkZv0
|
|
url: https://semgrep.dev/playground/r/BjTkZv0/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
app.controller(..., function($scope,$sce) {
|
|
...
|
|
});
|
|
- pattern: $scope.$X
|
|
pattern-sinks:
|
|
- pattern: $sce.trustAs(...)
|
|
- pattern: $sce.trustAsHtml(...)
|
|
- id: javascript.browser.security.open-redirect.js-open-redirect
|
|
message: The application accepts potentially user-controlled input `$PROP` which
|
|
can control the location of the current window context. This can lead two types
|
|
of vulnerabilities open-redirection and Cross-Site-Scripting (XSS) with JavaScript
|
|
URIs. It is recommended to validate user-controllable input before allowing it
|
|
to control the redirection.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
cwe:
|
|
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.1 Insecue Redirect
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation
|
|
version: '4'
|
|
category: security
|
|
confidence: HIGH
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html
|
|
technology:
|
|
- browser
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Open Redirect
|
|
source: https://semgrep.dev/r/javascript.browser.security.open-redirect.js-open-redirect
|
|
shortlink: https://sg.run/3xRe
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9243
|
|
rv_id: 1263122
|
|
rule_id: WAUopl
|
|
version_id: pZT03x0
|
|
url: https://semgrep.dev/playground/r/pZT03x0/javascript.browser.security.open-redirect.js-open-redirect
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
new URLSearchParams($WINDOW. ... .location.search).get('...')
|
|
- pattern: |
|
|
new URLSearchParams(location.search).get('...')
|
|
- pattern: |
|
|
new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...')
|
|
- pattern: |
|
|
new URLSearchParams(location.hash.substring(1)).get('...')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PROPS = new URLSearchParams($WINDOW. ... .location.search)
|
|
...
|
|
- pattern-inside: |
|
|
$PROPS = new URLSearchParams(location.search)
|
|
...
|
|
- pattern-inside: |
|
|
$PROPS = new URLSearchParams($WINDOW. ... .location.hash.substring(1))
|
|
...
|
|
- pattern-inside: |
|
|
$PROPS = new URLSearchParams(location.hash.substring(1))
|
|
...
|
|
- pattern: $PROPS.get('...')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PROPS = new URL($WINDOW. ... .location.href)
|
|
...
|
|
- pattern-inside: |
|
|
$PROPS = new URL(location.href)
|
|
...
|
|
- pattern: $PROPS.searchParams.get('...')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
new URL($WINDOW. ... .location.href).searchParams.get('...')
|
|
- pattern: |
|
|
new URL(location.href).searchParams.get('...')
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: location.href = $SINK
|
|
- pattern: $THIS. ... .location.href = $SINK
|
|
- pattern: location.replace($SINK)
|
|
- pattern: $THIS. ... .location.replace($SINK)
|
|
- pattern: location = $SINK
|
|
- pattern: $WINDOW. ... .location = $SINK
|
|
- focus-metavariable: $SINK
|
|
- metavariable-pattern:
|
|
patterns:
|
|
- pattern-not: |
|
|
"..." + $VALUE
|
|
- pattern-not: |
|
|
`...${$VALUE}`
|
|
metavariable: $SINK
|
|
- id: javascript.browser.security.raw-html-concat.raw-html-concat
|
|
message: User controlled data in a HTML string may result in XSS
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/www-community/attacks/xss/
|
|
category: security
|
|
technology:
|
|
- browser
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/javascript.browser.security.raw-html-concat.raw-html-concat
|
|
shortlink: https://sg.run/4xAx
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9244
|
|
rv_id: 1263123
|
|
rule_id: 0oU5b5
|
|
version_id: 2KTv2wp
|
|
url: https://semgrep.dev/playground/r/2KTv2wp/javascript.browser.security.raw-html-concat.raw-html-concat
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: location.href
|
|
- pattern: location.hash
|
|
- pattern: location.search
|
|
- pattern: $WINDOW. ... .location.href
|
|
- pattern: $WINDOW. ... .location.hash
|
|
- pattern: $WINDOW. ... .location.search
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: $STRING + $EXPR
|
|
- pattern-not: $STRING + "..."
|
|
- metavariable-pattern:
|
|
patterns:
|
|
- pattern: <$TAG ...
|
|
- pattern-not: <$TAG ...>...</$TAG>...
|
|
metavariable: $STRING
|
|
language: generic
|
|
- patterns:
|
|
- pattern: $EXPR + $STRING
|
|
- pattern-not: '"..." + $STRING'
|
|
- metavariable-pattern:
|
|
patterns:
|
|
- pattern: '... </$TAG'
|
|
metavariable: $STRING
|
|
language: generic
|
|
- patterns:
|
|
- pattern: '[..., $STRING, ...].join(...)'
|
|
- metavariable-pattern:
|
|
patterns:
|
|
- pattern: <$TAG ...
|
|
metavariable: $STRING
|
|
language: generic
|
|
- patterns:
|
|
- pattern: '[..., $STRING, ...].join(...)'
|
|
- metavariable-pattern:
|
|
patterns:
|
|
- pattern: '... </$TAG'
|
|
metavariable: $STRING
|
|
language: generic
|
|
- patterns:
|
|
- pattern: $VAR += $STRING
|
|
- metavariable-pattern:
|
|
patterns:
|
|
- pattern: <$TAG ...
|
|
metavariable: $STRING
|
|
language: generic
|
|
- patterns:
|
|
- pattern: $VAR += $STRING
|
|
- metavariable-pattern:
|
|
patterns:
|
|
- pattern: '... </$TAG'
|
|
metavariable: $STRING
|
|
language: generic
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("underscore.string")
|
|
...
|
|
- pattern-either:
|
|
- pattern: $S.escapeHTML(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import { ..., $S,... } from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("dompurify")
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("isomorphic-dompurify")
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S(...)
|
|
...
|
|
- pattern: $VALUE.sanitize(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S.sanitize
|
|
...
|
|
- pattern: $S(...)
|
|
- pattern: $S.sanitize(...)
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("xss")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'sanitize-html';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "sanitize-html";
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("sanitize-html")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$S = new Remarkable()
|
|
...
|
|
- pattern: $S.render(...)
|
|
- id: javascript.browser.security.wildcard-postmessage-configuration.wildcard-postmessage-configuration
|
|
message: The target origin of the window.postMessage() API is set to "*". This could
|
|
allow for information disclosure due to the possibility of any origin allowed
|
|
to receive the message.
|
|
metadata:
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
cwe:
|
|
- 'CWE-345: Insufficient Verification of Data Authenticity'
|
|
category: security
|
|
technology:
|
|
- browser
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/javascript.browser.security.wildcard-postmessage-configuration.wildcard-postmessage-configuration
|
|
shortlink: https://sg.run/PJ4p
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9245
|
|
rv_id: 1263125
|
|
rule_id: KxUbq4
|
|
version_id: jQTn5ND
|
|
url: https://semgrep.dev/playground/r/jQTn5ND/javascript.browser.security.wildcard-postmessage-configuration.wildcard-postmessage-configuration
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
pattern: $OBJECT.postMessage(...,'*',...)
|
|
- id: javascript.chrome-remote-interface.security.audit.chrome-remote-interface-compilescript-injection.chrome-remote-interface-compilescript-injection
|
|
message: If unverified user data can reach the `compileScript` method it can result
|
|
in Server-Side Request Forgery vulnerabilities
|
|
metadata:
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
category: security
|
|
technology:
|
|
- chrome-remote-interface
|
|
references:
|
|
- https://github.com/cyrus-and/chrome-remote-interface
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/javascript.chrome-remote-interface.security.audit.chrome-remote-interface-compilescript-injection.chrome-remote-interface-compilescript-injection
|
|
shortlink: https://sg.run/J9kj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9246
|
|
rv_id: 1263126
|
|
rule_id: qNUjnb
|
|
version_id: 1QTypkQ
|
|
url: https://semgrep.dev/playground/r/1QTypkQ/javascript.chrome-remote-interface.security.audit.chrome-remote-interface-compilescript-injection.chrome-remote-interface-compilescript-injection
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: function ... (..., $ARG,...) {...}
|
|
- focus-metavariable: $ARG
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('chrome-remote-interface');
|
|
...
|
|
- pattern-inside: |
|
|
import 'chrome-remote-interface';
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
$RUNTIME.compileScript({expression: $SINK},...)
|
|
- pattern: |
|
|
$RUNTIME.evaluate({expression: $SINK},...)
|
|
- pattern: |
|
|
$PAGE.navigate({url: $SINK},...)
|
|
- pattern: |
|
|
$RUNTIME.printToPDF({headerTemplate: $SINK},...)
|
|
- pattern: |
|
|
$RUNTIME.printToPDF({footerTemplate: $SINK},...)
|
|
- pattern: |
|
|
$PAGE.setDocumentContent({html: $SINK},...)
|
|
- focus-metavariable: $SINK
|
|
- id: javascript.express.security.express-expat-xxe.express-expat-xxe
|
|
message: Make sure that unverified user data can not reach the XML Parser, as it
|
|
can result in XML External or Internal Entity (XXE) Processing vulnerabilities.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://github.com/astro/node-expat
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/javascript.express.security.express-expat-xxe.express-expat-xxe
|
|
shortlink: https://sg.run/BkXx
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9251
|
|
rv_id: 1263164
|
|
rule_id: zdUkJl
|
|
version_id: o5TbD5l
|
|
url: https://semgrep.dev/playground/r/o5TbD5l/javascript.express.security.express-expat-xxe.express-expat-xxe
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$XML = require('node-expat')
|
|
...
|
|
- pattern-inside: |
|
|
import $XML from 'node-expat'
|
|
...
|
|
- pattern-inside: |
|
|
import * as $XML from 'node-expat'
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PARSER = new $XML.Parser(...);
|
|
...
|
|
- pattern-either:
|
|
- pattern: $PARSER.parse($QUERY)
|
|
- pattern: $PARSER.write($QUERY)
|
|
- focus-metavariable: $QUERY
|
|
- id: javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
category: security
|
|
technology:
|
|
- express
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret
|
|
shortlink: https://sg.run/Do1d
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9252
|
|
rv_id: 1263166
|
|
rule_id: pKUOjy
|
|
version_id: pZT03Q0
|
|
url: https://semgrep.dev/playground/r/pZT03Q0/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$JWT = require('express-jwt');
|
|
...
|
|
- pattern-inside: |
|
|
import $JWT from 'express-jwt';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $JWT from 'express-jwt';
|
|
...
|
|
- pattern-inside: |
|
|
import { ..., $JWT, ... } from 'express-jwt';
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
$JWT({...,secret: "$Y",...},...)
|
|
- pattern: |
|
|
$OPTS = "$Y";
|
|
...
|
|
$JWT({...,secret: $OPTS},...);
|
|
- focus-metavariable: $Y
|
|
- id: javascript.express.security.express-phantom-injection.express-phantom-injection
|
|
message: If unverified user data can reach the `phantom` methods it can result in
|
|
Server-Side Request Forgery vulnerabilities
|
|
metadata:
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
category: security
|
|
technology:
|
|
- express
|
|
references:
|
|
- https://phantomjs.org/page-automation.html
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/javascript.express.security.express-phantom-injection.express-phantom-injection
|
|
shortlink: https://sg.run/W8BL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9253
|
|
rv_id: 1263167
|
|
rule_id: 2ZUbx3
|
|
version_id: 2KTv26p
|
|
url: https://semgrep.dev/playground/r/2KTv26p/javascript.express.security.express-phantom-injection.express-phantom-injection
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('phantom');
|
|
...
|
|
- pattern-inside: |
|
|
import 'phantom';
|
|
...
|
|
- pattern-either:
|
|
- pattern: $PAGE.open($SINK,...)
|
|
- pattern: $PAGE.setContent($SINK,...)
|
|
- pattern: $PAGE.openUrl($SINK,...)
|
|
- pattern: $PAGE.evaluateJavaScript($SINK,...)
|
|
- pattern: $PAGE.property("content",$SINK,...)
|
|
- focus-metavariable: $SINK
|
|
- id: javascript.express.security.express-puppeteer-injection.express-puppeteer-injection
|
|
message: If unverified user data can reach the `puppeteer` methods it can result
|
|
in Server-Side Request Forgery vulnerabilities
|
|
metadata:
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
category: security
|
|
technology:
|
|
- express
|
|
references:
|
|
- https://pptr.dev/api/puppeteer.page
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection
|
|
shortlink: https://sg.run/0QJB
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9254
|
|
rv_id: 1263168
|
|
rule_id: X5U8Nz
|
|
version_id: X0TzyJY
|
|
url: https://semgrep.dev/playground/r/X0TzyJY/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('puppeteer');
|
|
...
|
|
- pattern-inside: |
|
|
import 'puppeteer';
|
|
...
|
|
- pattern-either:
|
|
- pattern: $PAGE.goto($SINK,...)
|
|
- pattern: $PAGE.setContent($SINK,...)
|
|
- pattern: $PAGE.evaluate($SINK,...)
|
|
- pattern: $PAGE.evaluate($CODE,$SINK,...)
|
|
- pattern: $PAGE.evaluateHandle($SINK,...)
|
|
- pattern: $PAGE.evaluateHandle($CODE,$SINK,...)
|
|
- pattern: $PAGE.evaluateOnNewDocument($SINK,...)
|
|
- pattern: $PAGE.evaluateOnNewDocument($CODE,$SINK,...)
|
|
- focus-metavariable: $SINK
|
|
- id: javascript.express.security.express-sandbox-injection.express-sandbox-code-injection
|
|
message: Make sure that unverified user data can not reach `sandbox`.
|
|
metadata:
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection
|
|
shortlink: https://sg.run/KlwL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9255
|
|
rv_id: 1263169
|
|
rule_id: j2UvXB
|
|
version_id: jQTn59D
|
|
url: https://semgrep.dev/playground/r/jQTn59D/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$SANDBOX = require('sandbox');
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$S = new $SANDBOX(...);
|
|
...
|
|
- pattern: |
|
|
$S.run(...)
|
|
- pattern: |
|
|
new $SANDBOX($OPTS).run(...)
|
|
- pattern: new $SANDBOX().run(...)
|
|
- id: javascript.express.security.express-xml2json-xxe.express-xml2json-xxe
|
|
message: Make sure that unverified user data can not reach the XML Parser, as it
|
|
can result in XML External or Internal Entity (XXE) Processing vulnerabilities
|
|
metadata:
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- express
|
|
references:
|
|
- https://www.npmjs.com/package/xml2json
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe
|
|
shortlink: https://sg.run/XBD4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9264
|
|
rv_id: 1263174
|
|
rule_id: x8Uneb
|
|
version_id: bZT534J
|
|
url: https://semgrep.dev/playground/r/bZT534J/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
|
|
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
- pattern: files.$ANYTHING.data.toString('utf8')
|
|
- pattern: files.$ANYTHING['data'].toString('utf8')
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('xml2json');
|
|
...
|
|
- pattern-inside: |
|
|
import 'xml2json';
|
|
...
|
|
- pattern: $EXPAT.toJson($SINK,...)
|
|
- focus-metavariable: $SINK
|
|
- id: javascript.express.security.require-request.require-request
|
|
message: If an attacker controls the x in require(x) then they can cause code to
|
|
load that was not intended to run on the server.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-706: Use of Incorrectly-Resolved Name or Reference'
|
|
source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html
|
|
category: security
|
|
technology:
|
|
- express
|
|
references:
|
|
- https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/javascript.express.security.require-request.require-request
|
|
shortlink: https://sg.run/jRbl
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9265
|
|
rv_id: 1263177
|
|
rule_id: OrU3WK
|
|
version_id: w8TRo0d
|
|
url: https://semgrep.dev/playground/r/w8TRo0d/javascript.express.security.require-request.require-request
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: require($SINK)
|
|
- focus-metavariable: $SINK
|
|
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name
|
|
message: "Don\u2019t use the default session cookie name Using the default session
|
|
cookie name can open your app to attacks. The security issue posed is similar
|
|
to X-Powered-By: a potential attacker can use it to fingerprint the server and
|
|
target attacks accordingly."
|
|
severity: WARNING
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name
|
|
shortlink: https://sg.run/1Z5x
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9266
|
|
rv_id: 1263130
|
|
rule_id: eqU8k2
|
|
version_id: bZT536J
|
|
url: https://semgrep.dev/playground/r/bZT536J/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$SESSION = require('cookie-session');
|
|
...
|
|
- pattern-inside: |
|
|
$SESSION = require('express-session');
|
|
...
|
|
- pattern: $SESSION(...)
|
|
- pattern-not-inside: $SESSION(<... {name:...} ...>,...)
|
|
- pattern-not-inside: |
|
|
$OPTS = <... {name:...} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$OPTS.name = ...;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure
|
|
message: 'Default session middleware settings: `secure` not set. It ensures the
|
|
browser only sends the cookie over HTTPS.'
|
|
severity: WARNING
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure
|
|
shortlink: https://sg.run/9oKz
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9267
|
|
rv_id: 1263131
|
|
rule_id: v8Unzw
|
|
version_id: NdTzyrv
|
|
url: https://semgrep.dev/playground/r/NdTzyrv/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$SESSION = require('cookie-session');
|
|
...
|
|
- pattern-inside: |
|
|
$SESSION = require('express-session');
|
|
...
|
|
- pattern: $SESSION(...)
|
|
- pattern-not-inside: $SESSION(<... {cookie:{secure:true}} ...>,...)
|
|
- pattern-not-inside: |
|
|
$OPTS = <... {cookie:{secure:true}} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$COOKIE = <... {secure:true} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$OPTS.cookie = <... {secure:true} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$COOKIE.secure = true;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$OPTS.cookie.secure = true;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly
|
|
message: 'Default session middleware settings: `httpOnly` not set. It ensures the
|
|
cookie is sent only over HTTP(S), not client JavaScript, helping to protect against
|
|
cross-site scripting attacks.'
|
|
severity: WARNING
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly
|
|
shortlink: https://sg.run/ydBO
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9268
|
|
rv_id: 1263132
|
|
rule_id: d8UjGo
|
|
version_id: kbTzGev
|
|
url: https://semgrep.dev/playground/r/kbTzGev/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$SESSION = require('cookie-session');
|
|
...
|
|
- pattern-inside: |
|
|
$SESSION = require('express-session');
|
|
...
|
|
- pattern: $SESSION(...)
|
|
- pattern-not-inside: $SESSION(<... {cookie:{httpOnly:true}} ...>,...)
|
|
- pattern-not-inside: |
|
|
$OPTS = <... {cookie:{httpOnly:true}} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$COOKIE = <... {httpOnly:true} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$OPTS.cookie = <... {httpOnly:true} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$COOKIE.httpOnly = true;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$OPTS.cookie.httpOnly = true;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain
|
|
message: 'Default session middleware settings: `domain` not set. It indicates the
|
|
domain of the cookie; use it to compare against the domain of the server in which
|
|
the URL is being requested. If they match, then check the path attribute next.'
|
|
severity: WARNING
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain
|
|
shortlink: https://sg.run/rd41
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9269
|
|
rv_id: 1263133
|
|
rule_id: ZqU5Pn
|
|
version_id: w8TRoyd
|
|
url: https://semgrep.dev/playground/r/w8TRoyd/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$SESSION = require('cookie-session');
|
|
...
|
|
- pattern-inside: |
|
|
$SESSION = require('express-session');
|
|
...
|
|
- pattern: $SESSION(...)
|
|
- pattern-not-inside: $SESSION(<... {cookie:{domain:...}} ...>,...)
|
|
- pattern-not-inside: |
|
|
$OPTS = <... {cookie:{domain:...}} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$COOKIE = <... {domain:...} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$OPTS.cookie = <... {domain:...} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$COOKIE.domain = ...;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$OPTS.cookie.domain = ...;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path
|
|
message: 'Default session middleware settings: `path` not set. It indicates the
|
|
path of the cookie; use it to compare against the request path. If this and domain
|
|
match, then send the cookie in the request.'
|
|
severity: WARNING
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path
|
|
shortlink: https://sg.run/b7pd
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9270
|
|
rv_id: 1263134
|
|
rule_id: nJUz4X
|
|
version_id: xyTjzQD
|
|
url: https://semgrep.dev/playground/r/xyTjzQD/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$SESSION = require('cookie-session');
|
|
...
|
|
- pattern-inside: |
|
|
$SESSION = require('express-session');
|
|
...
|
|
- pattern: $SESSION(...)
|
|
- pattern-not-inside: $SESSION(<... {cookie:{path:...}} ...>,...)
|
|
- pattern-not-inside: |
|
|
$OPTS = <... {cookie:{path:...}} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$COOKIE = <... {path:...} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$OPTS.cookie = <... {path:...} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$COOKIE.path = ...;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$OPTS.cookie.path = ...;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires
|
|
message: 'Default session middleware settings: `expires` not set. Use it to set
|
|
expiration date for persistent cookies.'
|
|
severity: WARNING
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires
|
|
shortlink: https://sg.run/N4eG
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9271
|
|
rv_id: 1263135
|
|
rule_id: EwU2DZ
|
|
version_id: O9TpxRq
|
|
url: https://semgrep.dev/playground/r/O9TpxRq/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$SESSION = require('cookie-session');
|
|
...
|
|
- pattern-inside: |
|
|
$SESSION = require('express-session');
|
|
...
|
|
- pattern: $SESSION(...)
|
|
- pattern-not-inside: $SESSION(<... {cookie:{expires:...}} ...>,...)
|
|
- pattern-not-inside: |
|
|
$OPTS = <... {cookie:{expires:...}} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$COOKIE = <... {expires:...} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$OPTS.cookie = <... {expires:...} ...>;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |
|
|
$OPTS = ...;
|
|
...
|
|
$COOKIE.expires = ...;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- pattern-not-inside: |-
|
|
$OPTS = ...;
|
|
...
|
|
$OPTS.cookie.expires = ...;
|
|
...
|
|
$SESSION($OPTS,...);
|
|
- id: javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked
|
|
message: No token revoking configured for `express-jwt`. A leaked token could still
|
|
be used and unable to be revoked. Consider using function as the `isRevoked` option.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
source-rule-url: https://github.com/goldbergyoni/nodebestpractices/blob/master/sections/security/expirejwt.md
|
|
asvs:
|
|
section: 'V3: Session Management Verification Requirements'
|
|
control_id: 3.5.3 Insecure Stateless Session Tokens
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked
|
|
shortlink: https://sg.run/kXNo
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9272
|
|
rv_id: 1263137
|
|
rule_id: 7KUQ9k
|
|
version_id: vdT06Bg
|
|
url: https://semgrep.dev/playground/r/vdT06Bg/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
$JWT = require('express-jwt');
|
|
...
|
|
- pattern: $JWT(...)
|
|
- pattern-not-inside: $JWT(<... {isRevoked:...} ...>,...)
|
|
- pattern-not-inside: |-
|
|
$OPTS = <... {isRevoked:...} ...>;
|
|
...
|
|
$JWT($OPTS,...);
|
|
- id: javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal
|
|
message: Possible writing outside of the destination, make sure that the target
|
|
path is nested in the intended destination
|
|
metadata:
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
category: security
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Path_Traversal
|
|
technology:
|
|
- express
|
|
- node.js
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal
|
|
shortlink: https://sg.run/weRn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9273
|
|
rv_id: 1263141
|
|
rule_id: L1Uyb8
|
|
version_id: ExTExX0
|
|
url: https://semgrep.dev/playground/r/ExTExX0/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $SINK
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PATH = require('path');
|
|
...
|
|
- pattern-inside: |
|
|
import $PATH from 'path';
|
|
...
|
|
- pattern-either:
|
|
- pattern: $PATH.join(...,$SINK,...)
|
|
- pattern: $PATH.resolve(...,$SINK,...)
|
|
- patterns:
|
|
- focus-metavariable: $SINK
|
|
- pattern-inside: |
|
|
import 'path';
|
|
...
|
|
- pattern-either:
|
|
- pattern: path.join(...,$SINK,...)
|
|
- pattern: path.resolve(...,$SINK,...)
|
|
pattern-sanitizers:
|
|
- pattern: $Y.replace(...)
|
|
- pattern: $Y.indexOf(...)
|
|
- pattern: |
|
|
function ... (...) {
|
|
...
|
|
<... $Y.indexOf(...) ...>
|
|
...
|
|
}
|
|
- patterns:
|
|
- pattern: $FUNC(...)
|
|
- metavariable-regex:
|
|
metavariable: $FUNC
|
|
regex: sanitize
|
|
- id: javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event
|
|
message: Xml Parser is used inside Request Event. Make sure that unverified user
|
|
data can not reach the XML Parser, as it can result in XML External or Internal
|
|
Entity (XXE) Processing vulnerabilities
|
|
metadata:
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
category: security
|
|
technology:
|
|
- express
|
|
references:
|
|
- https://www.npmjs.com/package/xml2json
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event
|
|
shortlink: https://sg.run/x1AA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9274
|
|
rv_id: 1263146
|
|
rule_id: 8GUjkk
|
|
version_id: QkTGqgo
|
|
url: https://semgrep.dev/playground/r/QkTGqgo/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('xml2json');
|
|
...
|
|
- pattern-inside: |
|
|
import 'xml2json';
|
|
...
|
|
- pattern: $REQ.on('...', function(...) { ... $EXPAT.toJson($INPUT,...); ... })
|
|
- focus-metavariable: $INPUT
|
|
- id: javascript.express.security.audit.res-render-injection.res-render-injection
|
|
message: User controllable data `$REQ` enters `$RES.render(...)` this can lead to
|
|
the loading of other HTML/templating pages that they may not be authorized to
|
|
render. An attacker may attempt to use directory traversal techniques e.g. `../folder/index`
|
|
to access other HTML pages on the file system. Where possible, do not allow users
|
|
to define what should be loaded in $RES.render or use an allow list for the existing
|
|
application.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-706: Use of Incorrectly-Resolved Name or Reference'
|
|
category: security
|
|
technology:
|
|
- express
|
|
references:
|
|
- http://expressjs.com/en/4x/api.html#res.render
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.res-render-injection.res-render-injection
|
|
shortlink: https://sg.run/eLjd
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9276
|
|
rv_id: 1263149
|
|
rule_id: QrUzrq
|
|
version_id: PkTR3OY
|
|
url: https://semgrep.dev/playground/r/PkTR3OY/javascript.express.security.audit.res-render-injection.res-render-injection
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $RES.render($SINK, ...)
|
|
- focus-metavariable: $SINK
|
|
- id: javascript.express.security.audit.xss.direct-response-write.direct-response-write
|
|
message: Detected directly writing to a Response object from user-defined input.
|
|
This bypasses any HTML escaping and may expose your application to a Cross-Site-scripting
|
|
(XSS) vulnerability. Instead, use 'resp.render()' to render safely escaped HTML.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.xss.direct-response-write.direct-response-write
|
|
shortlink: https://sg.run/vzGl
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9277
|
|
rv_id: 1263150
|
|
rule_id: 3qUPA1
|
|
version_id: JdTzxeg
|
|
url: https://semgrep.dev/playground/r/JdTzxeg/javascript.express.security.audit.xss.direct-response-write.direct-response-write
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)
|
|
- pattern-not-inside: |
|
|
function ... ($REQ, $RES) {
|
|
...
|
|
$RES.$SET('Content-Type', '$TYPE')
|
|
}
|
|
- pattern-not-inside: |
|
|
$APP.$METHOD(..., function $FUNC($REQ, $RES) {
|
|
...
|
|
$RES.$SET('Content-Type', '$TYPE')
|
|
})
|
|
- pattern-not-inside: |
|
|
function ... ($REQ, $RES, $NEXT) {
|
|
...
|
|
$RES.$SET('Content-Type', '$TYPE')
|
|
}
|
|
- pattern-not-inside: |
|
|
function ... ($REQ, $RES) {
|
|
...
|
|
$RES.set('$TYPE')
|
|
}
|
|
- pattern-not-inside: |
|
|
$APP.$METHOD(..., function $FUNC($REQ, $RES) {
|
|
...
|
|
$RES.set('$TYPE')
|
|
})
|
|
- pattern-not-inside: |
|
|
function ... ($REQ, $RES, $NEXT) {
|
|
...
|
|
$RES.set('$TYPE')
|
|
}
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- pattern-not-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{
|
|
...
|
|
$RES.$SET('Content-Type', '$TYPE')
|
|
}
|
|
- pattern-not-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {
|
|
...
|
|
$RES.$SET('Content-Type', '$TYPE')
|
|
}
|
|
- pattern-not-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{
|
|
...
|
|
$RES.set('$TYPE')
|
|
}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: function ... (..., $RES,...) {...}
|
|
- pattern-either:
|
|
- pattern: $RES.write($ARG)
|
|
- pattern: $RES.send($ARG)
|
|
- pattern-not: $RES. ... .set('...'). ... .send($ARG)
|
|
- pattern-not: $RES. ... .type('...'). ... .send($ARG)
|
|
- pattern-not-inside: $RES.$METHOD({ ... })
|
|
- focus-metavariable: $ARG
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("underscore.string")
|
|
...
|
|
- pattern-either:
|
|
- pattern: $S.escapeHTML(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import { ..., $S,... } from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("dompurify")
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("isomorphic-dompurify")
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S(...)
|
|
...
|
|
- pattern: $VALUE.sanitize(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S.sanitize
|
|
...
|
|
- pattern: $S(...)
|
|
- pattern: $S.sanitize(...)
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("xss")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'sanitize-html';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "sanitize-html";
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("sanitize-html")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$S = new Remarkable()
|
|
...
|
|
- pattern: $S.render(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'express-xss-sanitizer';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "express-xss-sanitizer";
|
|
...
|
|
- pattern-inside: |
|
|
const { ..., $S, ... } = require('express-xss-sanitizer');
|
|
...
|
|
- pattern-inside: |
|
|
var { ..., $S, ... } = require('express-xss-sanitizer');
|
|
...
|
|
- pattern-inside: |
|
|
let { ...,$S,... } = require('express-xss-sanitizer');
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("express-xss-sanitizer")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern: $RES. ... .type('$F'). ... .send(...)
|
|
- metavariable-regex:
|
|
metavariable: $F
|
|
regex: (?!.*text/html)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$X = [...];
|
|
...
|
|
- pattern: |
|
|
if(<... !$X.includes($SOURCE)...>) {
|
|
...
|
|
return ...
|
|
}
|
|
...
|
|
- pattern: $SOURCE
|
|
- id: javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
metadata:
|
|
interfile: true
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
asvs:
|
|
section: 'V3: Session Management Verification Requirements'
|
|
control_id: 3.5.2 Static API keys or secret
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- jose
|
|
- jwt
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret
|
|
shortlink: https://sg.run/Ro1g
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9293
|
|
rv_id: 1263182
|
|
rule_id: JDUyRl
|
|
version_id: d6TyxbX
|
|
url: https://semgrep.dev/playground/r/d6TyxbX/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
$JOSE = require("jose");
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
var {JWT} = $JOSE;
|
|
...
|
|
- pattern-inside: |
|
|
var {JWK, JWT} = $JOSE;
|
|
...
|
|
- pattern-inside: |
|
|
const {JWT} = $JOSE;
|
|
...
|
|
- pattern-inside: |
|
|
const {JWK, JWT} = $JOSE;
|
|
...
|
|
- pattern-inside: |
|
|
let {JWT} = $JOSE;
|
|
...
|
|
- pattern-inside: |
|
|
let {JWK, JWT} = $JOSE;
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
JWT.verify($P, "...", ...);
|
|
- pattern: |
|
|
JWT.sign($P, "...", ...);
|
|
- pattern: "JWT.verify($P, JWK.asKey(\"...\"), ...); \n"
|
|
- pattern: |
|
|
$JWT.sign($P, JWK.asKey("..."), ...);
|
|
options:
|
|
symbolic_propagation: true
|
|
interfile: true
|
|
- id: javascript.jose.security.jwt-none-alg.jwt-none-alg
|
|
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
|
|
assumes the integrity of the token has already been verified. This would allow
|
|
a malicious actor to forge a JWT token that will automatically be verified. Do
|
|
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
asvs:
|
|
section: 'V3: Session Management Verification Requirements'
|
|
control_id: 3.5.3 Insecue Stateless Session Tokens
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- jose
|
|
- jwt
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.jose.security.jwt-none-alg.jwt-none-alg
|
|
shortlink: https://sg.run/AvRL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9294
|
|
rv_id: 1263183
|
|
rule_id: 5rUOGN
|
|
version_id: ZRTKAyb
|
|
url: https://semgrep.dev/playground/r/ZRTKAyb/javascript.jose.security.jwt-none-alg.jwt-none-alg
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
pattern-either:
|
|
- pattern: |
|
|
var $JOSE = require("jose");
|
|
...
|
|
var { JWK, JWT } = $JOSE;
|
|
...
|
|
var $T = JWT.verify($P, JWK.None,...);
|
|
- pattern: |
|
|
var $JOSE = require("jose");
|
|
...
|
|
var { JWK, JWT } = $JOSE;
|
|
...
|
|
$T = JWT.verify($P, JWK.None,...);
|
|
- pattern: |
|
|
var $JOSE = require("jose");
|
|
...
|
|
var { JWK, JWT } = $JOSE;
|
|
...
|
|
JWT.verify($P, JWK.None,...);
|
|
- id: javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
asvs:
|
|
section: 'V3: Session Management Verification Requirements'
|
|
control_id: 3.5.2 Static API keys or secret
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
- javascript
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret
|
|
shortlink: https://sg.run/4xN9
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9300
|
|
rv_id: 1263189
|
|
rule_id: WAUon7
|
|
version_id: gETB75D
|
|
url: https://semgrep.dev/playground/r/gETB75D/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: "$X = '...' \n"
|
|
- pattern: "$X = '$Y' \n"
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$JWT.sign($DATA,"...",...);
|
|
- pattern-inside: |
|
|
$JWT.verify($DATA,"...",...);
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$JWT = require("jsonwebtoken")
|
|
...
|
|
- pattern-inside: |
|
|
import $JWT from "jsonwebtoken"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $JWT from "jsonwebtoken"
|
|
...
|
|
- pattern-inside: |
|
|
import {...,$JWT,...} from "jsonwebtoken"
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$JWT.sign($DATA,$VALUE,...);
|
|
- pattern-inside: |
|
|
$JWT.verify($DATA,$VALUE,...);
|
|
- focus-metavariable: $VALUE
|
|
- id: javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg
|
|
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
|
|
assumes the integrity of the token has already been verified. This would allow
|
|
a malicious actor to forge a JWT token that will automatically be verified. Do
|
|
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
asvs:
|
|
section: 'V3: Session Management Verification Requirements'
|
|
control_id: 3.5.3 Insecue Stateless Session Tokens
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg
|
|
shortlink: https://sg.run/PJXv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9301
|
|
rv_id: 1263190
|
|
rule_id: 0oU53g
|
|
version_id: QkTGqQo
|
|
url: https://semgrep.dev/playground/r/QkTGqQo/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-inside: |
|
|
$JWT = require("jsonwebtoken");
|
|
...
|
|
- pattern: $JWT.verify($P, $X, {algorithms:[...,'none',...]},...)
|
|
- id: javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression
|
|
message: Detected use of dynamic execution of JavaScript which may come from user-input,
|
|
which can lead to Cross-Site-Scripting (XSS). Where possible avoid including user-input
|
|
in functions which dynamically execute user-input.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-eval-with-expression.js
|
|
references:
|
|
- https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval#never_use_eval!
|
|
category: security
|
|
technology:
|
|
- javascript
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression
|
|
shortlink: https://sg.run/6nwK
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9315
|
|
rv_id: 1263214
|
|
rule_id: yyUngo
|
|
version_id: WrTqKkJ
|
|
url: https://semgrep.dev/playground/r/WrTqKkJ/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PROP = new URLSearchParams($WINDOW. ... .location.search).get('...')
|
|
...
|
|
- pattern-inside: |
|
|
$PROP = new URLSearchParams(location.search).get('...')
|
|
...
|
|
- pattern-inside: |
|
|
$PROP = new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...')
|
|
...
|
|
- pattern-inside: |
|
|
$PROP = new URLSearchParams(location.hash.substring(1)).get('...')
|
|
...
|
|
- focus-metavariable: $PROP
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PROPS = new URLSearchParams($WINDOW. ... .location.search)
|
|
...
|
|
- pattern-inside: |
|
|
$PROPS = new URLSearchParams(location.search)
|
|
...
|
|
- pattern-inside: |
|
|
$PROPS = new
|
|
URLSearchParams($WINDOW. ... .location.hash.substring(1))
|
|
...
|
|
- pattern-inside: |
|
|
$PROPS = new URLSearchParams(location.hash.substring(1))
|
|
...
|
|
- pattern: $PROPS.get('...')
|
|
- focus-metavariable: $PROPS
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: location.href
|
|
- pattern: location.hash
|
|
- pattern: location.search
|
|
- pattern: $WINDOW. ... .location.href
|
|
- pattern: $WINDOW. ... .location.hash
|
|
- pattern: $WINDOW. ... .location.search
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: eval(<... $SINK ...>)
|
|
- pattern: window.eval(<... $SINK ...>)
|
|
- pattern: new Function(<... $SINK ...>)
|
|
- pattern: new Function(<... $SINK ...>)(...)
|
|
- pattern: setTimeout(<... $SINK ...>,...)
|
|
- pattern: setInterval(<... $SINK ...>,...)
|
|
- focus-metavariable: $SINK
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: location.href = $FUNC(...)
|
|
- pattern: location.hash = $FUNC(...)
|
|
- pattern: location.search = $FUNC(...)
|
|
- pattern: $WINDOW. ... .location.href = $FUNC(...)
|
|
- pattern: $WINDOW. ... .location.hash = $FUNC(...)
|
|
- pattern: $WINDOW. ... .location.search = $FUNC(...)
|
|
- id: javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
asvs:
|
|
section: 'V3: Session Management Verification Requirements'
|
|
control_id: 3.5.2 Static API keys or secret
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
- nodejs
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret
|
|
shortlink: https://sg.run/vz70
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9333
|
|
rv_id: 1263225
|
|
rule_id: QrUzq6
|
|
version_id: X0TzyoE
|
|
url: https://semgrep.dev/playground/r/X0TzyoE/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- by-side-effect: true
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
{..., clientSecret: "...", ...}
|
|
- pattern: |
|
|
{..., secretOrKey: "...", ...}
|
|
- pattern: |
|
|
{..., consumerSecret: "...", ...}
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$OBJ = {}
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
$OBJ.clientSecret = "..."
|
|
- pattern: |
|
|
$OBJ.secretOrKey = "..."
|
|
- pattern: |
|
|
$OBJ.consumerSecret = "..."
|
|
- pattern: $OBJ
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$SECRET = '...'
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
{..., clientSecret: $SECRET, ...}
|
|
- pattern: |
|
|
{..., secretOrKey: $SECRET, ...}
|
|
- pattern: |
|
|
{..., consumerSecret: $SECRET, ...}
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$SECRET = '...'
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$VALUE = {..., clientSecret: $SECRET, ...}
|
|
...
|
|
- pattern-inside: |
|
|
$VALUE = {..., secretOrKey: $SECRET, ...}
|
|
...
|
|
- pattern-inside: |
|
|
$VALUE = {..., consumerSecret: $SECRET, ...}
|
|
...
|
|
- pattern: $VALUE
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$F = require("$I").Strategy
|
|
...
|
|
- pattern-inside: |
|
|
$F = require("$I")
|
|
...
|
|
- pattern-inside: |
|
|
import { $STRAT as $F } from '$I'
|
|
...
|
|
- pattern-inside: |
|
|
import $F from '$I'
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $I
|
|
regex: (passport-.*)
|
|
- pattern-inside: |
|
|
new $F($VALUE,...)
|
|
- focus-metavariable: $VALUE
|
|
- id: json.aws.security.public-s3-policy-statement.public-s3-policy-statement
|
|
pattern: |
|
|
{
|
|
"Effect": "Allow",
|
|
"Principal": "*",
|
|
"Resource": [
|
|
..., "=~/arn:aws:s3.*/", ...
|
|
],
|
|
...
|
|
}
|
|
message: Detected public S3 bucket policy. This policy allows anyone to access certain
|
|
properties of or items in the bucket. Do not do this unless you will never have
|
|
sensitive data inside the bucket.
|
|
metadata:
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls'
|
|
references:
|
|
- https://docs.aws.amazon.com/AmazonS3/latest/dev/WebsiteAccessPermissionsReqd.html
|
|
category: security
|
|
technology:
|
|
- aws
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/json.aws.security.public-s3-policy-statement.public-s3-policy-statement
|
|
shortlink: https://sg.run/Yv1d
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9358
|
|
rv_id: 1263255
|
|
rule_id: 9AU1br
|
|
version_id: A8Tgdxq
|
|
url: https://semgrep.dev/playground/r/A8Tgdxq/json.aws.security.public-s3-policy-statement.public-s3-policy-statement
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- json
|
|
- id: php.lang.security.assert-use.assert-use
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
- pattern: $_COOKIE
|
|
- pattern: $_REQUEST
|
|
- pattern: $_SERVER
|
|
- patterns:
|
|
- pattern: |
|
|
Route::$METHOD($ROUTENAME, function(..., $ARG, ...) { ... })
|
|
- focus-metavariable: $ARG
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: assert($SINK, ...);
|
|
- pattern-not: assert("...", ...);
|
|
- pattern: $SINK
|
|
message: Calling assert with user input is equivalent to eval'ing.
|
|
metadata:
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
references:
|
|
- https://www.php.net/manual/en/function.assert
|
|
- https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/AssertsSniff.php
|
|
category: security
|
|
technology:
|
|
- php
|
|
confidence: HIGH
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/php.lang.security.assert-use.assert-use
|
|
shortlink: https://sg.run/3xXW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9387
|
|
rv_id: 1263272
|
|
rule_id: DbUpjk
|
|
version_id: 9lT4bLx
|
|
url: https://semgrep.dev/playground/r/9lT4bLx/php.lang.security.assert-use.assert-use
|
|
origin: community
|
|
languages:
|
|
- php
|
|
severity: ERROR
|
|
- id: php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$ARG = $IS_VERIFIED;
|
|
...
|
|
curl_setopt(..., CURLOPT_SSL_VERIFYPEER, $ARG);
|
|
- pattern: curl_setopt(..., CURLOPT_SSL_VERIFYPEER, $IS_VERIFIED)
|
|
- metavariable-regex:
|
|
metavariable: $IS_VERIFIED
|
|
regex: 0|false|null
|
|
message: SSL verification is disabled but should not be (currently CURLOPT_SSL_VERIFYPEER=
|
|
$IS_VERIFIED)
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
references:
|
|
- https://www.saotn.org/dont-turn-off-curlopt_ssl_verifypeer-fix-php-configuration/
|
|
category: security
|
|
technology:
|
|
- php
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off
|
|
shortlink: https://sg.run/PJqv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9389
|
|
rv_id: 1263277
|
|
rule_id: 0oU5Xg
|
|
version_id: kbTzG9b
|
|
url: https://semgrep.dev/playground/r/kbTzG9b/php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off
|
|
origin: community
|
|
languages:
|
|
- php
|
|
severity: ERROR
|
|
- id: php.lang.security.phpinfo-use.phpinfo-use
|
|
pattern: phpinfo(...);
|
|
message: The 'phpinfo' function may reveal sensitive information about your environment.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
|
|
references:
|
|
- https://www.php.net/manual/en/function.phpinfo
|
|
- https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/PhpinfosSniff.php
|
|
category: security
|
|
technology:
|
|
- php
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/php.lang.security.phpinfo-use.phpinfo-use
|
|
shortlink: https://sg.run/W82E
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9397
|
|
rv_id: 1263298
|
|
rule_id: ReUglY
|
|
version_id: RGT0LN0
|
|
url: https://semgrep.dev/playground/r/RGT0LN0/php.lang.security.phpinfo-use.phpinfo-use
|
|
origin: community
|
|
languages:
|
|
- php
|
|
severity: ERROR
|
|
- id: python.boto3.security.hardcoded-token.hardcoded-token
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
- https://bento.dev/checks/boto3/hardcoded-access-token/
|
|
- https://aws.amazon.com/blogs/security/what-to-do-if-you-inadvertently-expose-an-aws-access-key/
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
category: security
|
|
technology:
|
|
- boto3
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/python.boto3.security.hardcoded-token.hardcoded-token
|
|
shortlink: https://sg.run/LwQ6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9439
|
|
rv_id: 1263347
|
|
rule_id: 5rUOwK
|
|
version_id: gETB78n
|
|
url: https://semgrep.dev/playground/r/gETB78n/python.boto3.security.hardcoded-token.hardcoded-token
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: |
|
|
"..."
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $W(...,$TOKEN="$VALUE",...)
|
|
- pattern: $BOTO. ... .$W(...,$TOKEN="$VALUE",...)
|
|
- metavariable-regex:
|
|
metavariable: $TOKEN
|
|
regex: (aws_session_token|aws_access_key_id|aws_secret_access_key)
|
|
- metavariable-pattern:
|
|
language: generic
|
|
metavariable: $VALUE
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-regex: ^AKI
|
|
- pattern-regex: ^[A-Za-z0-9/+=]+$
|
|
- metavariable-analysis:
|
|
metavariable: $VALUE
|
|
analyzer: entropy
|
|
- id: python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea
|
|
message: IDEA (International Data Encryption Algorithm) is a block cipher created
|
|
in 1991. It is an optional component of the OpenPGP standard. This cipher is
|
|
susceptible to attacks when using weak keys. It is recommended that you do not
|
|
use this cipher for new applications. Use a strong symmetric cipher such as EAS
|
|
instead. With the `cryptography` package it is recommended to use `Fernet` which
|
|
is a secure implementation of AES in CBC mode with a 128-bit key. Alternatively,
|
|
keep using the `Cipher` class from the hazmat primitives but use the AES algorithm
|
|
instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://tools.ietf.org/html/rfc5469
|
|
- https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#cryptography.hazmat.primitives.ciphers.algorithms.IDEA
|
|
category: security
|
|
technology:
|
|
- cryptography
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::cryptography
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea
|
|
shortlink: https://sg.run/3xyK
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9443
|
|
rv_id: 1263350
|
|
rule_id: BYUNPg
|
|
version_id: 44TEjNJ
|
|
url: https://semgrep.dev/playground/r/44TEjNJ/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
patterns:
|
|
- pattern: cryptography.hazmat.primitives.ciphers.algorithms.$IDEA($KEY)
|
|
- metavariable-regex:
|
|
metavariable: $IDEA
|
|
regex: ^(IDEA)$
|
|
- focus-metavariable: $IDEA
|
|
fix: AES
|
|
- id: python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb
|
|
message: ECB (Electronic Code Book) is the simplest mode of operation for block
|
|
ciphers. Each block of data is encrypted in the same way. This means identical
|
|
plaintext blocks will always result in identical ciphertext blocks, which can
|
|
leave significant patterns in the output. Use a different, cryptographically strong
|
|
mode instead, such as GCM.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L101
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B305
|
|
references:
|
|
- https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#insecure-modes
|
|
- https://crypto.stackexchange.com/questions/20941/why-shouldnt-i-use-ecb-encryption
|
|
category: security
|
|
technology:
|
|
- cryptography
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
functional-categories:
|
|
- crypto::search::mode::cryptography
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb
|
|
shortlink: https://sg.run/4xr5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9444
|
|
rv_id: 1263351
|
|
rule_id: DbUp5g
|
|
version_id: PkTR3w7
|
|
url: https://semgrep.dev/playground/r/PkTR3w7/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern: cryptography.hazmat.primitives.ciphers.modes.ECB($IV)
|
|
fix: cryptography.hazmat.primitives.ciphers.modes.GCM($IV)
|
|
- id: python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
|
|
patterns:
|
|
- pattern: cryptography.hazmat.primitives.hashes.$SHA(...)
|
|
- metavariable-pattern:
|
|
metavariable: $SHA
|
|
pattern: |
|
|
SHA1
|
|
- focus-metavariable: $SHA
|
|
fix: |
|
|
SHA256
|
|
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
|
|
collision resistant and is therefore not suitable as a cryptographic signature.
|
|
Use SHA256 or SHA3 instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B303
|
|
references:
|
|
- https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#sha-1
|
|
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
|
|
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
|
|
- http://2012.sharcs.org/slides/stevens.pdf
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- cryptography
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::cryptography
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
|
|
shortlink: https://sg.run/J9Qy
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9446
|
|
rv_id: 1263353
|
|
rule_id: 0oU5dN
|
|
version_id: 5PTo1l0
|
|
url: https://semgrep.dev/playground/r/5PTo1l0/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
- id: python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key(...,
|
|
key_size=$SIZE, ...)
|
|
- pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key($SIZE,
|
|
...)
|
|
- metavariable-comparison:
|
|
metavariable: $SIZE
|
|
comparison: $SIZE < 2048
|
|
- focus-metavariable: $SIZE
|
|
fix: |
|
|
2048
|
|
message: Detected an insufficient key size for DSA. NIST recommends a key size of
|
|
2048 or higher.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
|
|
references:
|
|
- https://www.cosic.esat.kuleuven.be/ecrypt/ecrypt2/documents/D.SPA.20.pdf
|
|
- https://cryptography.io/en/latest/hazmat/primitives/asymmetric/dsa/
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf
|
|
category: security
|
|
technology:
|
|
- cryptography
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
functional-categories:
|
|
- crypto::search::key-length::cryptography
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size
|
|
shortlink: https://sg.run/5Qb0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9447
|
|
rv_id: 1263354
|
|
rule_id: KxUb0x
|
|
version_id: GxTkeOK
|
|
url: https://semgrep.dev/playground/r/GxTkeOK/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size
|
|
patterns:
|
|
- pattern-inside: cryptography.hazmat.primitives.asymmetric.ec.generate_private_key(...)
|
|
- pattern: cryptography.hazmat.primitives.asymmetric.ec.$SIZE
|
|
- metavariable-pattern:
|
|
metavariable: $SIZE
|
|
pattern-either:
|
|
- pattern: SECP192R1
|
|
- pattern: SECT163K1
|
|
- pattern: SECT163R2
|
|
- focus-metavariable: $SIZE
|
|
fix: |
|
|
SECP256R1
|
|
message: Detected an insufficient curve size for EC. NIST recommends a key size
|
|
of 224 or higher. For example, use 'ec.SECP256R1'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf
|
|
- https://cryptography.io/en/latest/hazmat/primitives/asymmetric/ec/#elliptic-curves
|
|
category: security
|
|
technology:
|
|
- cryptography
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
functional-categories:
|
|
- crypto::search::key-length::cryptography
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size
|
|
shortlink: https://sg.run/GeQq
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9448
|
|
rv_id: 1263355
|
|
rule_id: qNUjZ3
|
|
version_id: RGT0LW6
|
|
url: https://semgrep.dev/playground/r/RGT0LW6/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key(...,
|
|
key_size=$SIZE, ...)
|
|
- pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key($EXP,
|
|
$SIZE, ...)
|
|
- metavariable-comparison:
|
|
metavariable: $SIZE
|
|
comparison: $SIZE < 2048
|
|
- focus-metavariable: $SIZE
|
|
fix: |
|
|
2048
|
|
message: Detected an insufficient key size for RSA. NIST recommends a key size of
|
|
2048 or higher.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
|
|
references:
|
|
- https://cryptography.io/en/latest/hazmat/primitives/asymmetric/rsa/
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf
|
|
category: security
|
|
technology:
|
|
- cryptography
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
functional-categories:
|
|
- crypto::search::key-length::cryptography
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
shortlink: https://sg.run/RoQq
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9449
|
|
rv_id: 1263356
|
|
rule_id: lBU9jn
|
|
version_id: A8TgdPK
|
|
url: https://semgrep.dev/playground/r/A8TgdPK/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.distributed.security.require-encryption
|
|
patterns:
|
|
- pattern: |
|
|
distributed.security.Security(..., require_encryption=$VAL, ...)
|
|
- metavariable-pattern:
|
|
metavariable: $VAL
|
|
pattern: |
|
|
False
|
|
- focus-metavariable: $VAL
|
|
fix: |
|
|
True
|
|
message: Initializing a security context for Dask (`distributed`) without "require_encryption"
|
|
keyword argument may silently fail to provide security.
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://distributed.dask.org/en/latest/tls.html?highlight=require_encryption#parameters
|
|
category: security
|
|
technology:
|
|
- distributed
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/python.distributed.security.require-encryption
|
|
shortlink: https://sg.run/AvQ2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9450
|
|
rv_id: 1263358
|
|
rule_id: YGURy0
|
|
version_id: DkTRbol
|
|
url: https://semgrep.dev/playground/r/DkTRbol/python.distributed.security.require-encryption
|
|
origin: community
|
|
languages:
|
|
- python
|
|
- id: python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization
|
|
metadata:
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
references:
|
|
- https://docs.python.org/3/library/pickle.html
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization
|
|
shortlink: https://sg.run/9oyr
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9467
|
|
rv_id: 1409400
|
|
rule_id: OrU3e6
|
|
version_id: GxTlb9e
|
|
url: https://semgrep.dev/playground/r/GxTlb9e/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization
|
|
origin: community
|
|
message: Avoid using insecure deserialization library, backed by `pickle`, `_pickle`,
|
|
`cpickle`, `dill`, `shelve`, or `yaml`, which are known to lead to remote code
|
|
execution vulnerabilities.
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $INSIDE(..., $PARAM, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: request.$REQFUNC(...)
|
|
- pattern: request.$REQFUNC.get(...)
|
|
- pattern: request.$REQFUNC[...]
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
pickle.$PICKLEFUNC(...)
|
|
- pattern: |
|
|
_pickle.$PICKLEFUNC(...)
|
|
- pattern: |
|
|
cPickle.$PICKLEFUNC(...)
|
|
- pattern: |
|
|
shelve.$PICKLEFUNC(...)
|
|
- metavariable-regex:
|
|
metavariable: $PICKLEFUNC
|
|
regex: dumps|dump|load|loads
|
|
- patterns:
|
|
- pattern: dill.$DILLFUNC(...)
|
|
- metavariable-regex:
|
|
metavariable: $DILLFUNC
|
|
regex: dump|dump_session|dumps|load|load_session|loads
|
|
- patterns:
|
|
- pattern: yaml.$YAMLFUNC(...)
|
|
- pattern-not: yaml.$YAMLFUNC(..., Dumper=SafeDumper, ...)
|
|
- pattern-not: yaml.$YAMLFUNC(..., Dumper=yaml.SafeDumper, ...)
|
|
- pattern-not: yaml.$YAMLFUNC(..., Loader=SafeLoader, ...)
|
|
- pattern-not: yaml.$YAMLFUNC(..., Loader=yaml.SafeLoader, ...)
|
|
- metavariable-regex:
|
|
metavariable: $YAMLFUNC
|
|
regex: dump|dump_all|load|load_all
|
|
- id: python.django.security.injection.open-redirect.open-redirect
|
|
message: Data from request ($DATA) is passed to redirect(). This is an open redirect
|
|
and could be exploited. Ensure you are redirecting to safe URLs by using django.utils.http.is_safe_url().
|
|
See https://cwe.mitre.org/data/definitions/601.html for more information.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://www.djm.org.uk/posts/djangos-little-protections-word-redirect-dangers/
|
|
- https://github.com/django/django/blob/d1b7bd030b1db111e1a3505b1fc029ab964382cc/django/utils/http.py#L231
|
|
category: security
|
|
technology:
|
|
- django
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Open Redirect
|
|
source: https://semgrep.dev/r/python.django.security.injection.open-redirect.open-redirect
|
|
shortlink: https://sg.run/Ave2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9494
|
|
rv_id: 1263393
|
|
rule_id: PeUZgr
|
|
version_id: 3ZT4XD7
|
|
url: https://semgrep.dev/playground/r/3ZT4XD7/python.django.security.injection.open-redirect.open-redirect
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-not-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
django.utils.http.is_safe_url(...)
|
|
...
|
|
- pattern-not-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
if <... django.utils.http.is_safe_url(...) ...>:
|
|
...
|
|
- pattern-not-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
django.utils.http.url_has_allowed_host_and_scheme(...)
|
|
...
|
|
- pattern-not-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
if <... django.utils.http.url_has_allowed_host_and_scheme(...) ...>:
|
|
...
|
|
- pattern-either:
|
|
- pattern: django.shortcuts.redirect(..., request.$W.get(...), ...)
|
|
- pattern: django.shortcuts.redirect(..., $S.format(..., request.$W.get(...),
|
|
...), ...)
|
|
- pattern: django.shortcuts.redirect(..., $S % request.$W.get(...), ...)
|
|
- pattern: django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.shortcuts.redirect(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.shortcuts.redirect(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.shortcuts.redirect(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.shortcuts.redirect(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., request.$W.get(...), ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W.get(...),
|
|
...), ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., $S % request.$W.get(...), ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., f"...{request.$W.get(...)}...",
|
|
...)
|
|
- pattern: return django.shortcuts.redirect(..., request.$W.get(...), ...)
|
|
- pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W.get(...),
|
|
...), ...)
|
|
- pattern: return django.shortcuts.redirect(..., $S % request.$W.get(...), ...)
|
|
- pattern: return django.shortcuts.redirect(..., f"...{request.$W.get(...)}...",
|
|
...)
|
|
- pattern: django.shortcuts.redirect(..., request.$W(...), ...)
|
|
- pattern: django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...),
|
|
...)
|
|
- pattern: django.shortcuts.redirect(..., $S % request.$W(...), ...)
|
|
- pattern: django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.shortcuts.redirect(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.shortcuts.redirect(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.shortcuts.redirect(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.shortcuts.redirect(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., request.$W(...), ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W(...),
|
|
...), ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., $S % request.$W(...), ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: return django.shortcuts.redirect(..., request.$W(...), ...)
|
|
- pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W(...),
|
|
...), ...)
|
|
- pattern: return django.shortcuts.redirect(..., $S % request.$W(...), ...)
|
|
- pattern: return django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: django.shortcuts.redirect(..., request.$W[...], ...)
|
|
- pattern: django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...),
|
|
...)
|
|
- pattern: django.shortcuts.redirect(..., $S % request.$W[...], ...)
|
|
- pattern: django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.shortcuts.redirect(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.shortcuts.redirect(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.shortcuts.redirect(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.shortcuts.redirect(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., request.$W[...], ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W[...],
|
|
...), ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., $S % request.$W[...], ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: return django.shortcuts.redirect(..., request.$W[...], ...)
|
|
- pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W[...],
|
|
...), ...)
|
|
- pattern: return django.shortcuts.redirect(..., $S % request.$W[...], ...)
|
|
- pattern: return django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: django.shortcuts.redirect(..., request.$W, ...)
|
|
- pattern: django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: django.shortcuts.redirect(..., $S % request.$W, ...)
|
|
- pattern: django.shortcuts.redirect(..., f"...{request.$W}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.shortcuts.redirect(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.shortcuts.redirect(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.shortcuts.redirect(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.shortcuts.redirect(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.shortcuts.redirect(..., $INTERM, ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., request.$W, ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W, ...),
|
|
...)
|
|
- pattern: $A = django.shortcuts.redirect(..., $S % request.$W, ...)
|
|
- pattern: $A = django.shortcuts.redirect(..., f"...{request.$W}...", ...)
|
|
- pattern: return django.shortcuts.redirect(..., request.$W, ...)
|
|
- pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W, ...),
|
|
...)
|
|
- pattern: return django.shortcuts.redirect(..., $S % request.$W, ...)
|
|
- pattern: return django.shortcuts.redirect(..., f"...{request.$W}...", ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., request.$W.get(...), ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...),
|
|
...), ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...",
|
|
...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., request.$W.get(...), ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...),
|
|
...), ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W.get(...),
|
|
...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...",
|
|
...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., request.$W.get(...), ...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...),
|
|
...), ...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., $S % request.$W.get(...),
|
|
...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...",
|
|
...)
|
|
- pattern: django.http.HttpResponseRedirect(..., request.$W(...), ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...),
|
|
...), ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., $S % request.$W(...), ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., request.$W(...), ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...),
|
|
...), ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W(...), ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...",
|
|
...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., request.$W(...), ...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...),
|
|
...), ...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., $S % request.$W(...),
|
|
...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...",
|
|
...)
|
|
- pattern: django.http.HttpResponseRedirect(..., request.$W[...], ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...],
|
|
...), ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., $S % request.$W[...], ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponseRedirect(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., request.$W[...], ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...],
|
|
...), ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W[...], ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...",
|
|
...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., request.$W[...], ...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...],
|
|
...), ...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., $S % request.$W[...],
|
|
...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...",
|
|
...)
|
|
- pattern: django.http.HttpResponseRedirect(..., request.$W, ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...),
|
|
...)
|
|
- pattern: django.http.HttpResponseRedirect(..., $S % request.$W, ...)
|
|
- pattern: django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponseRedirect(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponseRedirect(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponseRedirect(..., $INTERM, ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., request.$W, ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W,
|
|
...), ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W, ...)
|
|
- pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., request.$W, ...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W,
|
|
...), ...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., $S % request.$W, ...)
|
|
- pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W}...",
|
|
...)
|
|
- metavariable-regex:
|
|
metavariable: $W
|
|
regex: (?!get_full_path)
|
|
- id: python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse
|
|
message: Found user-controlled request data passed into HttpResponse. This could
|
|
be vulnerable to XSS, leading to attackers gaining access to user cookies and
|
|
protected information. Ensure that the request data is properly escaped or sanitzed.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse
|
|
shortlink: https://sg.run/BkvA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9495
|
|
rv_id: 1263398
|
|
rule_id: JDUydR
|
|
version_id: GxTke5K
|
|
url: https://semgrep.dev/playground/r/GxTke5K/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: django.http.HttpResponse(..., $S.format(..., request.$W.get(...), ...),
|
|
...)
|
|
- pattern: django.http.HttpResponse(..., $S % request.$W.get(...), ...)
|
|
- pattern: django.http.HttpResponse(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: django.http.HttpResponse(..., request.$W.get(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponse(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponse(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponse(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponse(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: $A = django.http.HttpResponse(..., request.$W.get(...), ...)
|
|
- pattern: return django.http.HttpResponse(..., request.$W.get(...), ...)
|
|
- pattern: django.http.HttpResponse(..., $S.format(..., request.$W(...), ...),
|
|
...)
|
|
- pattern: django.http.HttpResponse(..., $S % request.$W(...), ...)
|
|
- pattern: django.http.HttpResponse(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: django.http.HttpResponse(..., request.$W(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponse(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponse(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponse(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponse(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: $A = django.http.HttpResponse(..., request.$W(...), ...)
|
|
- pattern: return django.http.HttpResponse(..., request.$W(...), ...)
|
|
- pattern: django.http.HttpResponse(..., $S.format(..., request.$W[...], ...),
|
|
...)
|
|
- pattern: django.http.HttpResponse(..., $S % request.$W[...], ...)
|
|
- pattern: django.http.HttpResponse(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: django.http.HttpResponse(..., request.$W[...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponse(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponse(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponse(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponse(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: $A = django.http.HttpResponse(..., request.$W[...], ...)
|
|
- pattern: return django.http.HttpResponse(..., request.$W[...], ...)
|
|
- pattern: django.http.HttpResponse(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: django.http.HttpResponse(..., $S % request.$W, ...)
|
|
- pattern: django.http.HttpResponse(..., f"...{request.$W}...", ...)
|
|
- pattern: django.http.HttpResponse(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponse(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponse(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponse(..., f"...{$DATA}...", ...)
|
|
- pattern: $A = django.http.HttpResponse(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$A = django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: return django.http.HttpResponse(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponse(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponse(..., $INTERM, ...)
|
|
- id: python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest
|
|
message: Found user-controlled request data passed into a HttpResponseBadRequest.
|
|
This could be vulnerable to XSS, leading to attackers gaining access to user cookies
|
|
and protected information. Ensure that the request data is properly escaped or
|
|
sanitzed.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest
|
|
shortlink: https://sg.run/DoZP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9496
|
|
rv_id: 1263399
|
|
rule_id: 5rUOX1
|
|
version_id: RGT0LY6
|
|
url: https://semgrep.dev/playground/r/RGT0LY6/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W.get(...),
|
|
...), ...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., $S % request.$W.get(...), ...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W.get(...)}...",
|
|
...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., request.$W.get(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: $A = django.http.HttpResponseBadRequest(..., request.$W.get(...), ...)
|
|
- pattern: return django.http.HttpResponseBadRequest(..., request.$W.get(...),
|
|
...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W(...),
|
|
...), ...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., $S % request.$W(...), ...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W(...)}...",
|
|
...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., request.$W(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: $A = django.http.HttpResponseBadRequest(..., request.$W(...), ...)
|
|
- pattern: return django.http.HttpResponseBadRequest(..., request.$W(...), ...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W[...],
|
|
...), ...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., $S % request.$W[...], ...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W[...]}...",
|
|
...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., request.$W[...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: $A = django.http.HttpResponseBadRequest(..., request.$W[...], ...)
|
|
- pattern: return django.http.HttpResponseBadRequest(..., request.$W[...], ...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W,
|
|
...), ...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., $S % request.$W, ...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W}...", ...)
|
|
- pattern: django.http.HttpResponseBadRequest(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.http.HttpResponseBadRequest(..., $INTERM, ...)
|
|
- pattern: $A = django.http.HttpResponseBadRequest(..., request.$W, ...)
|
|
- pattern: return django.http.HttpResponseBadRequest(..., request.$W, ...)
|
|
- id: python.django.security.injection.request-data-fileresponse.request-data-fileresponse
|
|
message: Found user-controlled request data being passed into a file open, which
|
|
is them passed as an argument into the FileResponse. This is dangerous because
|
|
an attacker could specify an arbitrary file to read, which could result in leaking
|
|
important data. Be sure to validate or sanitize the user-inputted filename in
|
|
the request data before using it in FileResponse.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/python.django.security.injection.request-data-fileresponse.request-data-fileresponse
|
|
shortlink: https://sg.run/W862
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9497
|
|
rv_id: 1263400
|
|
rule_id: GdU7QR
|
|
version_id: A8Tgd1K
|
|
url: https://semgrep.dev/playground/r/A8Tgd1K/python.django.security.injection.request-data-fileresponse.request-data-fileresponse
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: django.http.FileResponse(..., request.$W.get(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.http.FileResponse(..., open($DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = open($DATA, ...)
|
|
...
|
|
django.http.FileResponse(..., $INTERM, ...)
|
|
- pattern: $A = django.http.FileResponse(..., request.$W.get(...), ...)
|
|
- pattern: return django.http.FileResponse(..., request.$W.get(...), ...)
|
|
- pattern: django.http.FileResponse(..., request.$W(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.http.FileResponse(..., open($DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = open($DATA, ...)
|
|
...
|
|
django.http.FileResponse(..., $INTERM, ...)
|
|
- pattern: $A = django.http.FileResponse(..., request.$W(...), ...)
|
|
- pattern: return django.http.FileResponse(..., request.$W(...), ...)
|
|
- pattern: django.http.FileResponse(..., request.$W[...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.http.FileResponse(..., open($DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = open($DATA, ...)
|
|
...
|
|
django.http.FileResponse(..., $INTERM, ...)
|
|
- pattern: $A = django.http.FileResponse(..., request.$W[...], ...)
|
|
- pattern: return django.http.FileResponse(..., request.$W[...], ...)
|
|
- pattern: django.http.FileResponse(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.http.FileResponse(..., open($DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = open($DATA, ...)
|
|
...
|
|
django.http.FileResponse(..., $INTERM, ...)
|
|
- pattern: $A = django.http.FileResponse(..., request.$W, ...)
|
|
- pattern: return django.http.FileResponse(..., request.$W, ...)
|
|
- id: python.django.security.injection.request-data-write.request-data-write
|
|
message: Found user-controlled request data passed into '.write(...)'. This could
|
|
be dangerous if a malicious actor is able to control data into sensitive files.
|
|
For example, a malicious actor could force rolling of critical log files, or cause
|
|
a denial-of-service by using up available disk space. Instead, ensure that request
|
|
data is properly escaped or sanitized.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-93: Improper Neutralization of CRLF Sequences (''CRLF Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- django
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/python.django.security.injection.request-data-write.request-data-write
|
|
shortlink: https://sg.run/0Q6j
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9498
|
|
rv_id: 1263401
|
|
rule_id: ReUg5z
|
|
version_id: BjTkZO5
|
|
url: https://semgrep.dev/playground/r/BjTkZO5/python.django.security.injection.request-data-write.request-data-write
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern: $F.write(..., request.$W.get(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$F.write(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$F.write(..., $B.$C(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $B.$C(..., $DATA, ...)
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$F.write(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$F.write(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: $A = $F.write(..., request.$W.get(...), ...)
|
|
- pattern: return $F.write(..., request.$W.get(...), ...)
|
|
- pattern: $F.write(..., request.$W(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$F.write(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$F.write(..., $B.$C(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $B.$C(..., $DATA, ...)
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$F.write(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$F.write(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: $A = $F.write(..., request.$W(...), ...)
|
|
- pattern: return $F.write(..., request.$W(...), ...)
|
|
- pattern: $F.write(..., request.$W[...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$F.write(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$F.write(..., $B.$C(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $B.$C(..., $DATA, ...)
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$F.write(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$F.write(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: $A = $F.write(..., request.$W[...], ...)
|
|
- pattern: return $F.write(..., request.$W[...], ...)
|
|
- pattern: $F.write(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$F.write(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$F.write(..., $B.$C(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $B.$C(..., $DATA, ...)
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$F.write(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$F.write(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$F.write(..., $INTERM, ...)
|
|
- pattern: $A = $F.write(..., request.$W, ...)
|
|
- pattern: return $F.write(..., request.$W, ...)
|
|
- id: python.django.security.injection.code.user-eval-format-string.user-eval-format-string
|
|
message: Found user data in a call to 'eval'. This is extremely dangerous because
|
|
it can enable an attacker to execute remote code. See https://owasp.org/www-community/attacks/Code_Injection
|
|
for more information.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html
|
|
category: security
|
|
technology:
|
|
- django
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.django.security.injection.code.user-eval-format-string.user-eval-format-string
|
|
shortlink: https://sg.run/4x2z
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9500
|
|
rv_id: 1263383
|
|
rule_id: BYUNw9
|
|
version_id: vdT06xG
|
|
url: https://semgrep.dev/playground/r/vdT06xG/python.django.security.injection.code.user-eval-format-string.user-eval-format-string
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $F(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: eval(..., $STR % request.$W.get(...), ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
eval(..., $STR % $V, ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
$S = $STR % $V
|
|
...
|
|
eval(..., $S, ...)
|
|
- pattern: eval(..., "..." % request.$W(...), ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
eval(..., $STR % $V, ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
$S = $STR % $V
|
|
...
|
|
eval(..., $S, ...)
|
|
- pattern: eval(..., $STR % request.$W[...], ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
eval(..., $STR % $V, ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
$S = $STR % $V
|
|
...
|
|
eval(..., $S, ...)
|
|
- pattern: eval(..., $STR.format(..., request.$W.get(...), ...), ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
eval(..., $STR.format(..., $V, ...), ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
$S = $STR.format(..., $V, ...)
|
|
...
|
|
eval(..., $S, ...)
|
|
- pattern: eval(..., $STR.format(..., request.$W(...), ...), ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
eval(..., $STR.format(..., $V, ...), ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
$S = $STR.format(..., $V, ...)
|
|
...
|
|
eval(..., $S, ...)
|
|
- pattern: eval(..., $STR.format(..., request.$W[...], ...), ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
eval(..., $STR.format(..., $V, ...), ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
$S = $STR.format(..., $V, ...)
|
|
...
|
|
eval(..., $S, ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
eval(..., f"...{$V}...", ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
$S = f"...{$V}..."
|
|
...
|
|
eval(..., $S, ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
eval(..., f"...{$V}...", ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
$S = f"...{$V}..."
|
|
...
|
|
eval(..., $S, ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
eval(..., f"...{$V}...", ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
$S = f"...{$V}..."
|
|
...
|
|
eval(..., $S, ...)
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.django.security.injection.code.user-eval.user-eval
|
|
message: Found user data in a call to 'eval'. This is extremely dangerous because
|
|
it can enable an attacker to execute arbitrary remote code on the system. Instead,
|
|
refactor your code to not use 'eval' and instead use a safe library for the specific
|
|
functionality you need.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html
|
|
- https://owasp.org/www-community/attacks/Code_Injection
|
|
category: security
|
|
technology:
|
|
- django
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.django.security.injection.code.user-eval.user-eval
|
|
shortlink: https://sg.run/PJDW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9501
|
|
rv_id: 1263384
|
|
rule_id: DbUpDQ
|
|
version_id: d6Tyx2A
|
|
url: https://semgrep.dev/playground/r/d6Tyx2A/python.django.security.injection.code.user-eval.user-eval
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $F(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: eval(..., request.$W.get(...), ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
eval(..., $V, ...)
|
|
- pattern: eval(..., request.$W(...), ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
eval(..., $V, ...)
|
|
- pattern: eval(..., request.$W[...], ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
eval(..., $V, ...)
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.django.security.injection.code.user-exec-format-string.user-exec-format-string
|
|
message: Found user data in a call to 'exec'. This is extremely dangerous because
|
|
it can enable an attacker to execute arbitrary remote code on the system. Instead,
|
|
refactor your code to not use 'eval' and instead use a safe library for the specific
|
|
functionality you need.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- django
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Code_Injection
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.django.security.injection.code.user-exec-format-string.user-exec-format-string
|
|
shortlink: https://sg.run/J9JW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9502
|
|
rv_id: 1263385
|
|
rule_id: WAUovx
|
|
version_id: ZRTKA1p
|
|
url: https://semgrep.dev/playground/r/ZRTKA1p/python.django.security.injection.code.user-exec-format-string.user-exec-format-string
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $F(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: exec(..., $STR % request.$W.get(...), ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
exec(..., $STR % $V, ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
$S = $STR % $V
|
|
...
|
|
exec(..., $S, ...)
|
|
- pattern: exec(..., "..." % request.$W(...), ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
exec(..., $STR % $V, ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
$S = $STR % $V
|
|
...
|
|
exec(..., $S, ...)
|
|
- pattern: exec(..., $STR % request.$W[...], ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
exec(..., $STR % $V, ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
$S = $STR % $V
|
|
...
|
|
exec(..., $S, ...)
|
|
- pattern: exec(..., $STR.format(..., request.$W.get(...), ...), ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
exec(..., $STR.format(..., $V, ...), ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
$S = $STR.format(..., $V, ...)
|
|
...
|
|
exec(..., $S, ...)
|
|
- pattern: exec(..., $STR.format(..., request.$W(...), ...), ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
exec(..., $STR.format(..., $V, ...), ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
$S = $STR.format(..., $V, ...)
|
|
...
|
|
exec(..., $S, ...)
|
|
- pattern: exec(..., $STR.format(..., request.$W[...], ...), ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
exec(..., $STR.format(..., $V, ...), ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
$S = $STR.format(..., $V, ...)
|
|
...
|
|
exec(..., $S, ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
exec(..., f"...{$V}...", ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
$S = f"...{$V}..."
|
|
...
|
|
exec(..., $S, ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
exec(..., f"...{$V}...", ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
$S = f"...{$V}..."
|
|
...
|
|
exec(..., $S, ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
exec(..., f"...{$V}...", ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
$S = f"...{$V}..."
|
|
...
|
|
exec(..., $S, ...)
|
|
- pattern: exec(..., base64.decodestring($S.format(..., request.$W.get(...), ...),
|
|
...), ...)
|
|
- pattern: exec(..., base64.decodestring($S % request.$W.get(...), ...), ...)
|
|
- pattern: exec(..., base64.decodestring(f"...{request.$W.get(...)}...", ...),
|
|
...)
|
|
- pattern: exec(..., base64.decodestring(request.$W.get(...), ...), ...)
|
|
- pattern: exec(..., base64.decodestring(bytes($S.format(..., request.$W.get(...),
|
|
...), ...), ...), ...)
|
|
- pattern: exec(..., base64.decodestring(bytes($S % request.$W.get(...), ...),
|
|
...), ...)
|
|
- pattern: exec(..., base64.decodestring(bytes(f"...{request.$W.get(...)}...",
|
|
...), ...), ...)
|
|
- pattern: exec(..., base64.decodestring(bytes(request.$W.get(...), ...), ...),
|
|
...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
exec(..., base64.decodestring($DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = base64.decodestring($DATA, ...)
|
|
...
|
|
exec(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
exec(..., base64.decodestring(bytes($DATA, ...), ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = base64.decodestring(bytes($DATA, ...), ...)
|
|
...
|
|
exec(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
exec(..., base64.decodestring($DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = base64.decodestring($DATA, ...)
|
|
...
|
|
exec(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
exec(..., base64.decodestring(bytes($DATA, ...), ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = base64.decodestring(bytes($DATA, ...), ...)
|
|
...
|
|
exec(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
exec(..., base64.decodestring($DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = base64.decodestring($DATA, ...)
|
|
...
|
|
exec(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
exec(..., base64.decodestring(bytes($DATA, ...), ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = base64.decodestring(bytes($DATA, ...), ...)
|
|
...
|
|
exec(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
exec(..., base64.decodestring($DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = base64.decodestring($DATA, ...)
|
|
...
|
|
exec(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
exec(..., base64.decodestring(bytes($DATA, ...), ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = base64.decodestring(bytes($DATA, ...), ...)
|
|
...
|
|
exec(..., $INTERM, ...)
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.django.security.injection.code.user-exec.user-exec
|
|
message: Found user data in a call to 'exec'. This is extremely dangerous because
|
|
it can enable an attacker to execute arbitrary remote code on the system. Instead,
|
|
refactor your code to not use 'eval' and instead use a safe library for the specific
|
|
functionality you need.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- django
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Code_Injection
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.django.security.injection.code.user-exec.user-exec
|
|
shortlink: https://sg.run/5Q3X
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9503
|
|
rv_id: 1263386
|
|
rule_id: 0oU5AW
|
|
version_id: nWT2LA2
|
|
url: https://semgrep.dev/playground/r/nWT2LA2/python.django.security.injection.code.user-exec.user-exec
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $F(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: exec(..., request.$W.get(...), ...)
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
exec(..., $V, ...)
|
|
- pattern: exec(..., request.$W(...), ...)
|
|
- pattern: |
|
|
$V = request.$W(...)
|
|
...
|
|
exec(..., $V, ...)
|
|
- pattern: exec(..., request.$W[...], ...)
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
exec(..., $V, ...)
|
|
- pattern: |
|
|
loop = asyncio.get_running_loop()
|
|
...
|
|
await loop.run_in_executor(None, exec, request.$W[...])
|
|
- pattern: |
|
|
$V = request.$W[...]
|
|
...
|
|
loop = asyncio.get_running_loop()
|
|
...
|
|
await loop.run_in_executor(None, exec, $V)
|
|
- pattern: |
|
|
loop = asyncio.get_running_loop()
|
|
...
|
|
await loop.run_in_executor(None, exec, request.$W.get(...))
|
|
- pattern: |
|
|
$V = request.$W.get(...)
|
|
...
|
|
loop = asyncio.get_running_loop()
|
|
...
|
|
await loop.run_in_executor(None, exec, $V)
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.django.security.injection.command.command-injection-os-system.command-injection-os-system
|
|
message: Request data detected in os.system. This could be vulnerable to a command
|
|
injection and should be avoided. If this must be done, use the 'subprocess' module
|
|
instead and pass the arguments as a list. See https://owasp.org/www-community/attacks/Command_Injection
|
|
for more information.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Command_Injection
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.django.security.injection.command.command-injection-os-system.command-injection-os-system
|
|
shortlink: https://sg.run/Gen2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9504
|
|
rv_id: 1263387
|
|
rule_id: KxUbp2
|
|
version_id: ExTExPo
|
|
url: https://semgrep.dev/playground/r/ExTExPo/python.django.security.injection.command.command-injection-os-system.command-injection-os-system
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: os.system(..., request.$W.get(...), ...)
|
|
- pattern: os.system(..., $S.format(..., request.$W.get(...), ...), ...)
|
|
- pattern: os.system(..., $S % request.$W.get(...), ...)
|
|
- pattern: os.system(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
os.system(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
os.system(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
os.system(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
os.system(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
os.system(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: $A = os.system(..., request.$W.get(...), ...)
|
|
- pattern: $A = os.system(..., $S.format(..., request.$W.get(...), ...), ...)
|
|
- pattern: $A = os.system(..., $S % request.$W.get(...), ...)
|
|
- pattern: $A = os.system(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: return os.system(..., request.$W.get(...), ...)
|
|
- pattern: return os.system(..., $S.format(..., request.$W.get(...), ...), ...)
|
|
- pattern: return os.system(..., $S % request.$W.get(...), ...)
|
|
- pattern: return os.system(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: os.system(..., request.$W(...), ...)
|
|
- pattern: os.system(..., $S.format(..., request.$W(...), ...), ...)
|
|
- pattern: os.system(..., $S % request.$W(...), ...)
|
|
- pattern: os.system(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
os.system(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
os.system(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
os.system(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
os.system(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
os.system(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: $A = os.system(..., request.$W(...), ...)
|
|
- pattern: $A = os.system(..., $S.format(..., request.$W(...), ...), ...)
|
|
- pattern: $A = os.system(..., $S % request.$W(...), ...)
|
|
- pattern: $A = os.system(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: return os.system(..., request.$W(...), ...)
|
|
- pattern: return os.system(..., $S.format(..., request.$W(...), ...), ...)
|
|
- pattern: return os.system(..., $S % request.$W(...), ...)
|
|
- pattern: return os.system(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: os.system(..., request.$W[...], ...)
|
|
- pattern: os.system(..., $S.format(..., request.$W[...], ...), ...)
|
|
- pattern: os.system(..., $S % request.$W[...], ...)
|
|
- pattern: os.system(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
os.system(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
os.system(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
os.system(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
os.system(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
os.system(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: $A = os.system(..., request.$W[...], ...)
|
|
- pattern: $A = os.system(..., $S.format(..., request.$W[...], ...), ...)
|
|
- pattern: $A = os.system(..., $S % request.$W[...], ...)
|
|
- pattern: $A = os.system(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: return os.system(..., request.$W[...], ...)
|
|
- pattern: return os.system(..., $S.format(..., request.$W[...], ...), ...)
|
|
- pattern: return os.system(..., $S % request.$W[...], ...)
|
|
- pattern: return os.system(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: os.system(..., request.$W, ...)
|
|
- pattern: os.system(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: os.system(..., $S % request.$W, ...)
|
|
- pattern: os.system(..., f"...{request.$W}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
os.system(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
os.system(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
os.system(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
os.system(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
os.system(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
os.system(..., $INTERM, ...)
|
|
- pattern: $A = os.system(..., request.$W, ...)
|
|
- pattern: $A = os.system(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: $A = os.system(..., $S % request.$W, ...)
|
|
- pattern: $A = os.system(..., f"...{request.$W}...", ...)
|
|
- pattern: return os.system(..., request.$W, ...)
|
|
- pattern: return os.system(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: return os.system(..., $S % request.$W, ...)
|
|
- pattern: return os.system(..., f"...{request.$W}...", ...)
|
|
- id: python.django.security.injection.email.xss-html-email-body.xss-html-email-body
|
|
message: Found request data in an EmailMessage that is set to use HTML. This is
|
|
dangerous because HTML emails are susceptible to XSS. An attacker could inject
|
|
data into this HTML email, causing XSS.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream
|
|
Component (''Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://www.damonkohler.com/2008/12/email-injection.html
|
|
category: security
|
|
technology:
|
|
- django
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/python.django.security.injection.email.xss-html-email-body.xss-html-email-body
|
|
shortlink: https://sg.run/RoBe
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9505
|
|
rv_id: 1263390
|
|
rule_id: qNUj02
|
|
version_id: 8KT5rOn
|
|
url: https://semgrep.dev/playground/r/8KT5rOn/python.django.security.injection.email.xss-html-email-body.xss-html-email-body
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
$EMAIL.content_subtype = "html"
|
|
...
|
|
- pattern-either:
|
|
- pattern: django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $B.$C(..., $DATA, ...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...)
|
|
- pattern: return django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...)
|
|
- pattern: django.core.mail.EmailMessage($SUBJ, request.$W(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $B.$C(..., $DATA, ...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W(...), ...)
|
|
- pattern: return django.core.mail.EmailMessage($SUBJ, request.$W(...), ...)
|
|
- pattern: django.core.mail.EmailMessage($SUBJ, request.$W[...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $B.$C(..., $DATA, ...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W[...], ...)
|
|
- pattern: return django.core.mail.EmailMessage($SUBJ, request.$W[...], ...)
|
|
- pattern: django.core.mail.EmailMessage($SUBJ, request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $B.$C(..., $DATA, ...)
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
|
|
- pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W, ...)
|
|
- pattern: return django.core.mail.EmailMessage($SUBJ, request.$W, ...)
|
|
- id: python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message
|
|
message: Found request data in 'send_mail(...)' that uses 'html_message'. This is
|
|
dangerous because HTML emails are susceptible to XSS. An attacker could inject
|
|
data into this HTML email, causing XSS.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream
|
|
Component (''Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://www.damonkohler.com/2008/12/email-injection.html
|
|
category: security
|
|
technology:
|
|
- django
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message
|
|
shortlink: https://sg.run/Avx8
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9506
|
|
rv_id: 1263391
|
|
rule_id: lBU9Ll
|
|
version_id: gETB7Gn
|
|
url: https://semgrep.dev/playground/r/gETB7Gn/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: django.core.mail.send_mail(..., html_message=request.$W.get(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: $A = django.core.mail.send_mail(..., html_message=request.$W.get(...),
|
|
...)
|
|
- pattern: return django.core.mail.send_mail(..., html_message=request.$W.get(...),
|
|
...)
|
|
- pattern: django.core.mail.send_mail(..., html_message=request.$W(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: $A = django.core.mail.send_mail(..., html_message=request.$W(...),
|
|
...)
|
|
- pattern: return django.core.mail.send_mail(..., html_message=request.$W(...),
|
|
...)
|
|
- pattern: django.core.mail.send_mail(..., html_message=request.$W[...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: $A = django.core.mail.send_mail(..., html_message=request.$W[...],
|
|
...)
|
|
- pattern: return django.core.mail.send_mail(..., html_message=request.$W[...],
|
|
...)
|
|
- pattern: django.core.mail.send_mail(..., html_message=request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.core.mail.send_mail(..., html_message=$INTERM, ...)
|
|
- pattern: $A = django.core.mail.send_mail(..., html_message=request.$W, ...)
|
|
- pattern: return django.core.mail.send_mail(..., html_message=request.$W, ...)
|
|
- id: python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open
|
|
message: Found request data in a call to 'open'. Ensure the request data is validated
|
|
or sanitized, otherwise it could result in path traversal attacks and therefore
|
|
sensitive data being leaked. To mitigate, consider using os.path.abspath or os.path.realpath
|
|
or the pathlib library.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Path_Traversal
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open
|
|
shortlink: https://sg.run/W8qg
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9509
|
|
rv_id: 1263396
|
|
rule_id: oqUe7z
|
|
version_id: JdTzxAw
|
|
url: https://semgrep.dev/playground/r/JdTzxAw/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: open(..., request.$W.get(...), ...)
|
|
- pattern: open(..., $S.format(..., request.$W.get(...), ...), ...)
|
|
- pattern: open(..., $S % request.$W.get(...), ...)
|
|
- pattern: open(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
open(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
open(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
open(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
open(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
open(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: $A = open(..., request.$W.get(...), ...)
|
|
- pattern: $A = open(..., $S.format(..., request.$W.get(...), ...), ...)
|
|
- pattern: $A = open(..., $S % request.$W.get(...), ...)
|
|
- pattern: $A = open(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: return open(..., request.$W.get(...), ...)
|
|
- pattern: return open(..., $S.format(..., request.$W.get(...), ...), ...)
|
|
- pattern: return open(..., $S % request.$W.get(...), ...)
|
|
- pattern: return open(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
with open(..., $DATA, ...) as $FD:
|
|
...
|
|
- pattern: open(..., request.$W(...), ...)
|
|
- pattern: open(..., $S.format(..., request.$W(...), ...), ...)
|
|
- pattern: open(..., $S % request.$W(...), ...)
|
|
- pattern: open(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
open(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
open(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
open(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
open(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
open(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: $A = open(..., request.$W(...), ...)
|
|
- pattern: $A = open(..., $S.format(..., request.$W(...), ...), ...)
|
|
- pattern: $A = open(..., $S % request.$W(...), ...)
|
|
- pattern: $A = open(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: return open(..., request.$W(...), ...)
|
|
- pattern: return open(..., $S.format(..., request.$W(...), ...), ...)
|
|
- pattern: return open(..., $S % request.$W(...), ...)
|
|
- pattern: return open(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
with open(..., $DATA, ...) as $FD:
|
|
...
|
|
- pattern: open(..., request.$W[...], ...)
|
|
- pattern: open(..., $S.format(..., request.$W[...], ...), ...)
|
|
- pattern: open(..., $S % request.$W[...], ...)
|
|
- pattern: open(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
open(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
open(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
open(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
open(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
open(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: $A = open(..., request.$W[...], ...)
|
|
- pattern: $A = open(..., $S.format(..., request.$W[...], ...), ...)
|
|
- pattern: $A = open(..., $S % request.$W[...], ...)
|
|
- pattern: $A = open(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: return open(..., request.$W[...], ...)
|
|
- pattern: return open(..., $S.format(..., request.$W[...], ...), ...)
|
|
- pattern: return open(..., $S % request.$W[...], ...)
|
|
- pattern: return open(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
with open(..., $DATA, ...) as $FD:
|
|
...
|
|
- pattern: open(..., request.$W, ...)
|
|
- pattern: open(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: open(..., $S % request.$W, ...)
|
|
- pattern: open(..., f"...{request.$W}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
open(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
open(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
open(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
open(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
open(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
open(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
with open(..., $INTERM, ...) as $FD:
|
|
...
|
|
- pattern: $A = open(..., request.$W, ...)
|
|
- pattern: $A = open(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: $A = open(..., $S % request.$W, ...)
|
|
- pattern: $A = open(..., f"...{request.$W}...", ...)
|
|
- pattern: return open(..., request.$W, ...)
|
|
- pattern: return open(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: return open(..., $S % request.$W, ...)
|
|
- pattern: return open(..., f"...{request.$W}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
with open(..., $DATA, ...) as $FD:
|
|
...
|
|
- id: python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where
|
|
message: User-controlled data from a request is passed to 'extra()'. This could
|
|
lead to a SQL injection and therefore protected information could be leaked. Instead,
|
|
use parameterized queries or escape the user-controlled data by using `params`
|
|
and not using quote placeholders in the SQL string.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.djangoproject.com/en/3.0/ref/models/expressions/#.objects.extra
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where
|
|
shortlink: https://sg.run/0Ql5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9510
|
|
rv_id: 1263402
|
|
rule_id: zdUkx1
|
|
version_id: DkTRb4l
|
|
url: https://semgrep.dev/playground/r/DkTRb4l/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W.get(...),
|
|
...), ...], ...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W.get(...), ...],
|
|
...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W.get(...)}...",
|
|
...], ...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...],
|
|
...)
|
|
- pattern: return $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...],
|
|
...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W(...),
|
|
...), ...], ...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W(...), ...], ...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W(...)}...", ...],
|
|
...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...)
|
|
- pattern: return $MODEL.objects.extra(..., where=[..., request.$W(...), ...],
|
|
...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W[...],
|
|
...), ...], ...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W[...], ...], ...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W[...]}...", ...],
|
|
...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...)
|
|
- pattern: return $MODEL.objects.extra(..., where=[..., request.$W[...], ...],
|
|
...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W, ...),
|
|
...], ...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W, ...], ...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W}...", ...],
|
|
...)
|
|
- pattern: $MODEL.objects.extra(..., where=[..., request.$W, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W, ...], ...)
|
|
- pattern: return $MODEL.objects.extra(..., where=[..., request.$W, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
|
|
- id: python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql
|
|
message: User-controlled data from request is passed to 'RawSQL()'. This could lead
|
|
to a SQL injection and therefore protected information could be leaked. Instead,
|
|
use parameterized queries or escape the user-controlled data by using `params`
|
|
and not using quote placeholders in the SQL string.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.djangoproject.com/en/3.0/ref/models/expressions/#django.db.models.expressions.RawSQL
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql
|
|
shortlink: https://sg.run/Kl4X
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9511
|
|
rv_id: 1263403
|
|
rule_id: pKUOBp
|
|
version_id: WrTqK2L
|
|
url: https://semgrep.dev/playground/r/WrTqK2L/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W.get(...),
|
|
...), ...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., $S % request.$W.get(...),
|
|
...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W.get(...)}...",
|
|
...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., request.$W.get(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: $A = django.db.models.expressions.RawSQL(..., request.$W.get(...),
|
|
...)
|
|
- pattern: return django.db.models.expressions.RawSQL(..., request.$W.get(...),
|
|
...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W(...),
|
|
...), ...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., $S % request.$W(...), ...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W(...)}...",
|
|
...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., request.$W(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: $A = django.db.models.expressions.RawSQL(..., request.$W(...), ...)
|
|
- pattern: return django.db.models.expressions.RawSQL(..., request.$W(...), ...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W[...],
|
|
...), ...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., $S % request.$W[...], ...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W[...]}...",
|
|
...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., request.$W[...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: $A = django.db.models.expressions.RawSQL(..., request.$W[...], ...)
|
|
- pattern: return django.db.models.expressions.RawSQL(..., request.$W[...], ...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W,
|
|
...), ...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., $S % request.$W, ...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W}...", ...)
|
|
- pattern: django.db.models.expressions.RawSQL(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
django.db.models.expressions.RawSQL(..., $INTERM, ...)
|
|
- pattern: $A = django.db.models.expressions.RawSQL(..., request.$W, ...)
|
|
- pattern: return django.db.models.expressions.RawSQL(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
django.db.models.expressions.RawSQL($INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
django.db.models.expressions.RawSQL($INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
django.db.models.expressions.RawSQL($INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
django.db.models.expressions.RawSQL($INTERM, ...)
|
|
- id: python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute
|
|
message: User-controlled data from a request is passed to 'execute()'. This could
|
|
lead to a SQL injection and therefore protected information could be leaked. Instead,
|
|
use django's QuerySets, which are built with query parameterization and therefore
|
|
not vulnerable to sql injection. For example, you could use `Entry.objects.filter(date=2006)`.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute
|
|
shortlink: https://sg.run/qx7y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9512
|
|
rv_id: 1263404
|
|
rule_id: 2ZUbDL
|
|
version_id: 0bTKzRj
|
|
url: https://semgrep.dev/playground/r/0bTKzRj/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: $CURSOR.execute(..., $S.format(..., request.$W.get(...), ...), ...)
|
|
- pattern: $CURSOR.execute(..., $S % request.$W.get(...), ...)
|
|
- pattern: $CURSOR.execute(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: $CURSOR.execute(..., request.$W.get(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$CURSOR.execute(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$CURSOR.execute(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$CURSOR.execute(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$CURSOR.execute(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: $A = $CURSOR.execute(..., request.$W.get(...), ...)
|
|
- pattern: return $CURSOR.execute(..., request.$W.get(...), ...)
|
|
- pattern: $CURSOR.execute(..., $S.format(..., request.$W(...), ...), ...)
|
|
- pattern: $CURSOR.execute(..., $S % request.$W(...), ...)
|
|
- pattern: $CURSOR.execute(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: $CURSOR.execute(..., request.$W(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$CURSOR.execute(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$CURSOR.execute(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$CURSOR.execute(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$CURSOR.execute(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: $A = $CURSOR.execute(..., request.$W(...), ...)
|
|
- pattern: return $CURSOR.execute(..., request.$W(...), ...)
|
|
- pattern: $CURSOR.execute(..., $S.format(..., request.$W[...], ...), ...)
|
|
- pattern: $CURSOR.execute(..., $S % request.$W[...], ...)
|
|
- pattern: $CURSOR.execute(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: $CURSOR.execute(..., request.$W[...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$CURSOR.execute(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$CURSOR.execute(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$CURSOR.execute(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$CURSOR.execute(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: $A = $CURSOR.execute(..., request.$W[...], ...)
|
|
- pattern: return $CURSOR.execute(..., request.$W[...], ...)
|
|
- pattern: $CURSOR.execute(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: $CURSOR.execute(..., $S % request.$W, ...)
|
|
- pattern: $CURSOR.execute(..., f"...{request.$W}...", ...)
|
|
- pattern: $CURSOR.execute(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$CURSOR.execute(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$CURSOR.execute(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$CURSOR.execute(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$CURSOR.execute(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$CURSOR.execute(..., $INTERM, ...)
|
|
- pattern: $A = $CURSOR.execute(..., request.$W, ...)
|
|
- pattern: return $CURSOR.execute(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$CURSOR.execute($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$CURSOR.execute($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$CURSOR.execute($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$CURSOR.execute($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$CURSOR.execute($INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$CURSOR.execute($INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$CURSOR.execute($INTERM, ...)
|
|
- pattern: |-
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$CURSOR.execute($INTERM, ...)
|
|
- id: python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw
|
|
message: Data that is possible user-controlled from a python request is passed to
|
|
`raw()`. This could lead to SQL injection and attackers gaining access to protected
|
|
information. Instead, use django's QuerySets, which are built with query parameterization
|
|
and therefore not vulnerable to sql injection. For example, you could use `Entry.objects.filter(date=2006)`.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw
|
|
shortlink: https://sg.run/l2v9
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9513
|
|
rv_id: 1263405
|
|
rule_id: X5U8v5
|
|
version_id: K3TKkBW
|
|
url: https://semgrep.dev/playground/r/K3TKkBW/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: $MODEL.objects.raw(..., $S.format(..., request.$W.get(...), ...), ...)
|
|
- pattern: $MODEL.objects.raw(..., $S % request.$W.get(...), ...)
|
|
- pattern: $MODEL.objects.raw(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: $MODEL.objects.raw(..., request.$W.get(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.raw(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.raw(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.raw(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.raw(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: $A = $MODEL.objects.raw(..., request.$W.get(...), ...)
|
|
- pattern: return $MODEL.objects.raw(..., request.$W.get(...), ...)
|
|
- pattern: $MODEL.objects.raw(..., $S.format(..., request.$W(...), ...), ...)
|
|
- pattern: $MODEL.objects.raw(..., $S % request.$W(...), ...)
|
|
- pattern: $MODEL.objects.raw(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: $MODEL.objects.raw(..., request.$W(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.raw(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.raw(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.raw(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.raw(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: $A = $MODEL.objects.raw(..., request.$W(...), ...)
|
|
- pattern: return $MODEL.objects.raw(..., request.$W(...), ...)
|
|
- pattern: $MODEL.objects.raw(..., $S.format(..., request.$W[...], ...), ...)
|
|
- pattern: $MODEL.objects.raw(..., $S % request.$W[...], ...)
|
|
- pattern: $MODEL.objects.raw(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: $MODEL.objects.raw(..., request.$W[...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.raw(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.raw(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.raw(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.raw(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: $A = $MODEL.objects.raw(..., request.$W[...], ...)
|
|
- pattern: return $MODEL.objects.raw(..., request.$W[...], ...)
|
|
- pattern: $MODEL.objects.raw(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: $MODEL.objects.raw(..., $S % request.$W, ...)
|
|
- pattern: $MODEL.objects.raw(..., f"...{request.$W}...", ...)
|
|
- pattern: $MODEL.objects.raw(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.raw(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.raw(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.raw(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.raw(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
$MODEL.objects.raw(..., $INTERM, ...)
|
|
- pattern: $A = $MODEL.objects.raw(..., request.$W, ...)
|
|
- pattern: return $MODEL.objects.raw(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$MODEL.objects.raw($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$MODEL.objects.raw($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$MODEL.objects.raw($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$MODEL.objects.raw($STR % (..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.raw($INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.raw($INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.raw($INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % (..., $DATA, ...)
|
|
...
|
|
$MODEL.objects.raw($INTERM, ...)
|
|
- id: python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests
|
|
message: Data from request object is passed to a new server-side request. This could
|
|
lead to a server-side request forgery (SSRF). To mitigate, ensure that schemes
|
|
and hosts are validated against an allowlist, do not forward the response to the
|
|
user, and ensure proper authentication and transport-layer security in the proxied
|
|
request. See https://owasp.org/www-community/attacks/Server_Side_Request_Forgery
|
|
to learn more about SSRF vulnerabilities.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Server_Side_Request_Forgery
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests
|
|
shortlink: https://sg.run/YvY4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9514
|
|
rv_id: 1263406
|
|
rule_id: j2UvEw
|
|
version_id: qkTR7zn
|
|
url: https://semgrep.dev/playground/r/qkTR7zn/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: requests.$METHOD(..., $S.format(..., request.$W.get(...), ...), ...)
|
|
- pattern: requests.$METHOD(..., $S % request.$W.get(...), ...)
|
|
- pattern: requests.$METHOD(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: requests.$METHOD(..., request.$W.get(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
requests.$METHOD(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
requests.$METHOD(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
requests.$METHOD(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
requests.$METHOD(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
requests.$METHOD(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: $A = requests.$METHOD(..., request.$W.get(...), ...)
|
|
- pattern: return requests.$METHOD(..., request.$W.get(...), ...)
|
|
- pattern: requests.$METHOD(..., $S.format(..., request.$W(...), ...), ...)
|
|
- pattern: requests.$METHOD(..., $S % request.$W(...), ...)
|
|
- pattern: requests.$METHOD(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: requests.$METHOD(..., request.$W(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
requests.$METHOD(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
requests.$METHOD(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
requests.$METHOD(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
requests.$METHOD(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
requests.$METHOD(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: $A = requests.$METHOD(..., request.$W(...), ...)
|
|
- pattern: return requests.$METHOD(..., request.$W(...), ...)
|
|
- pattern: requests.$METHOD(..., $S.format(..., request.$W[...], ...), ...)
|
|
- pattern: requests.$METHOD(..., $S % request.$W[...], ...)
|
|
- pattern: requests.$METHOD(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: requests.$METHOD(..., request.$W[...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
requests.$METHOD(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
requests.$METHOD(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
requests.$METHOD(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
requests.$METHOD(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
requests.$METHOD(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: $A = requests.$METHOD(..., request.$W[...], ...)
|
|
- pattern: return requests.$METHOD(..., request.$W[...], ...)
|
|
- pattern: requests.$METHOD(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: requests.$METHOD(..., $S % request.$W, ...)
|
|
- pattern: requests.$METHOD(..., f"...{request.$W}...", ...)
|
|
- pattern: requests.$METHOD(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
requests.$METHOD(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
requests.$METHOD(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
requests.$METHOD(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
requests.$METHOD(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
requests.$METHOD(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
requests.$METHOD(..., $INTERM, ...)
|
|
- pattern: $A = requests.$METHOD(..., request.$W, ...)
|
|
- pattern: return requests.$METHOD(..., request.$W, ...)
|
|
- id: python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib
|
|
message: Data from request object is passed to a new server-side request. This could
|
|
lead to a server-side request forgery (SSRF), which could result in attackers
|
|
gaining access to private organization data. To mitigate, ensure that schemes
|
|
and hosts are validated against an allowlist, do not forward the response to the
|
|
user, and ensure proper authentication and transport-layer security in the proxied
|
|
request.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Server_Side_Request_Forgery
|
|
category: security
|
|
technology:
|
|
- django
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib
|
|
shortlink: https://sg.run/6n2B
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9515
|
|
rv_id: 1263407
|
|
rule_id: 10UKDo
|
|
version_id: l4TJRwD
|
|
url: https://semgrep.dev/playground/r/l4TJRwD/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: urllib.request.urlopen(..., $S.format(..., request.$W.get(...), ...),
|
|
...)
|
|
- pattern: urllib.request.urlopen(..., $S % request.$W.get(...), ...)
|
|
- pattern: urllib.request.urlopen(..., f"...{request.$W.get(...)}...", ...)
|
|
- pattern: urllib.request.urlopen(..., request.$W.get(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
urllib.request.urlopen(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
urllib.request.urlopen(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
urllib.request.urlopen(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
urllib.request.urlopen(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W.get(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: $A = urllib.request.urlopen(..., request.$W.get(...), ...)
|
|
- pattern: return urllib.request.urlopen(..., request.$W.get(...), ...)
|
|
- pattern: urllib.request.urlopen(..., $S.format(..., request.$W(...), ...), ...)
|
|
- pattern: urllib.request.urlopen(..., $S % request.$W(...), ...)
|
|
- pattern: urllib.request.urlopen(..., f"...{request.$W(...)}...", ...)
|
|
- pattern: urllib.request.urlopen(..., request.$W(...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
urllib.request.urlopen(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
urllib.request.urlopen(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
urllib.request.urlopen(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
urllib.request.urlopen(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W(...)
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: $A = urllib.request.urlopen(..., request.$W(...), ...)
|
|
- pattern: return urllib.request.urlopen(..., request.$W(...), ...)
|
|
- pattern: urllib.request.urlopen(..., $S.format(..., request.$W[...], ...), ...)
|
|
- pattern: urllib.request.urlopen(..., $S % request.$W[...], ...)
|
|
- pattern: urllib.request.urlopen(..., f"...{request.$W[...]}...", ...)
|
|
- pattern: urllib.request.urlopen(..., request.$W[...], ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
urllib.request.urlopen(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
urllib.request.urlopen(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
urllib.request.urlopen(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
urllib.request.urlopen(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W[...]
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: $A = urllib.request.urlopen(..., request.$W[...], ...)
|
|
- pattern: return urllib.request.urlopen(..., request.$W[...], ...)
|
|
- pattern: urllib.request.urlopen(..., $S.format(..., request.$W, ...), ...)
|
|
- pattern: urllib.request.urlopen(..., $S % request.$W, ...)
|
|
- pattern: urllib.request.urlopen(..., f"...{request.$W}...", ...)
|
|
- pattern: urllib.request.urlopen(..., request.$W, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
urllib.request.urlopen(..., $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR.format(..., $DATA, ...)
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
urllib.request.urlopen(..., $STR % $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR % $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
urllib.request.urlopen(..., f"...{$DATA}...", ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = f"...{$DATA}..."
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
urllib.request.urlopen(..., $STR + $DATA, ...)
|
|
- pattern: |
|
|
$DATA = request.$W
|
|
...
|
|
$INTERM = $STR + $DATA
|
|
...
|
|
urllib.request.urlopen(..., $INTERM, ...)
|
|
- pattern: $A = urllib.request.urlopen(..., request.$W, ...)
|
|
- pattern: return urllib.request.urlopen(..., request.$W, ...)
|
|
- id: python.django.security.passwords.password-empty-string.password-empty-string
|
|
message: '''$VAR'' is the empty string and is being used to set the password on
|
|
''$MODEL''. If you meant to set an unusable password, set the password to None
|
|
or call ''set_unusable_password()''.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-521: Weak Password Requirements'
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
references:
|
|
- https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password
|
|
category: security
|
|
technology:
|
|
- django
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/python.django.security.passwords.password-empty-string.password-empty-string
|
|
shortlink: https://sg.run/oxnR
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9516
|
|
rv_id: 1263411
|
|
rule_id: 9AU1jW
|
|
version_id: GxTke5Q
|
|
url: https://semgrep.dev/playground/r/GxTke5Q/python.django.security.passwords.password-empty-string.password-empty-string
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$MODEL.set_password($EMPTY)
|
|
...
|
|
$MODEL.save()
|
|
- pattern: |
|
|
$VAR = $EMPTY
|
|
...
|
|
$MODEL.set_password($VAR)
|
|
...
|
|
$MODEL.save()
|
|
- metavariable-regex:
|
|
metavariable: $EMPTY
|
|
regex: (\'\'|\"\")
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.django.security.passwords.use-none-for-password-default.use-none-for-password-default
|
|
message: '''$VAR'' is using the empty string as its default and is being used to
|
|
set the password on ''$MODEL''. If you meant to set an unusable password, set
|
|
the default value to ''None'' or call ''set_unusable_password()''.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-521: Weak Password Requirements'
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
references:
|
|
- https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password
|
|
category: security
|
|
technology:
|
|
- django
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default
|
|
shortlink: https://sg.run/zvBW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9517
|
|
rv_id: 1263412
|
|
rule_id: yyUn6Z
|
|
version_id: RGT0LYX
|
|
url: https://semgrep.dev/playground/r/RGT0LYX/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$VAR = request.$W.get($X, $EMPTY)
|
|
...
|
|
$MODEL.set_password($VAR)
|
|
...
|
|
$MODEL.save(...)
|
|
- pattern: |
|
|
def $F(..., $VAR=$EMPTY, ...):
|
|
...
|
|
$MODEL.set_password($VAR)
|
|
- metavariable-pattern:
|
|
metavariable: $EMPTY
|
|
pattern: '""'
|
|
- focus-metavariable: $EMPTY
|
|
fix: |
|
|
None
|
|
- id: python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host
|
|
message: Running flask app with host 0.0.0.0 could expose the server publicly.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-668: Exposure of Resource to Wrong Sphere'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- flask
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host
|
|
shortlink: https://sg.run/eLby
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9532
|
|
rv_id: 1263414
|
|
rule_id: L1Uy1n
|
|
version_id: BjTkZOY
|
|
url: https://semgrep.dev/playground/r/BjTkZOY/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern: app.run(..., host="0.0.0.0", ...)
|
|
- pattern: app.run(..., "0.0.0.0", ...)
|
|
- id: python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
if __name__ == '__main__':
|
|
...
|
|
- pattern-not-inside: |
|
|
def $X(...):
|
|
...
|
|
- pattern: app.run(...)
|
|
message: top-level app.run(...) is ignored by flask. Consider putting app.run(...)
|
|
behind a guard, like inside a function
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-668: Exposure of Resource to Wrong Sphere'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- flask
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly
|
|
shortlink: https://sg.run/vz5b
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9533
|
|
rv_id: 1263415
|
|
rule_id: 8GUjdX
|
|
version_id: DkTRb4z
|
|
url: https://semgrep.dev/playground/r/DkTRb4z/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.flask.security.audit.debug-enabled.debug-enabled
|
|
patterns:
|
|
- pattern-inside: |
|
|
import flask
|
|
...
|
|
- pattern: $APP.run(..., debug=True, ...)
|
|
message: Detected Flask app with debug=True. Do not deploy to production with this
|
|
flag enabled as it will leak sensitive information. Instead, consider using Flask
|
|
configuration variables or setting 'debug' using system environment variables.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-489: Active Debug Code'
|
|
owasp: A06:2017 - Security Misconfiguration
|
|
references:
|
|
- https://labs.detectify.com/2015/10/02/how-patreon-got-hacked-publicly-exposed-werkzeug-debugger/
|
|
category: security
|
|
technology:
|
|
- flask
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Active Debug Code
|
|
source: https://semgrep.dev/r/python.flask.security.audit.debug-enabled.debug-enabled
|
|
shortlink: https://sg.run/dKrd
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9534
|
|
rv_id: 946206
|
|
rule_id: gxU1bd
|
|
version_id: 8KTKjwR
|
|
url: https://semgrep.dev/playground/r/8KTKjwR/python.flask.security.audit.debug-enabled.debug-enabled
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
- id: python.flask.security.audit.directly-returned-format-string.directly-returned-format-string
|
|
message: Detected Flask route directly returning a formatted string. This is subject
|
|
to cross-site scripting if user input can reach the string. Consider using the
|
|
template engine instead and rendering pages with 'render_template()'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- flask
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string
|
|
shortlink: https://sg.run/Zv6o
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9535
|
|
rv_id: 1263416
|
|
rule_id: QrUz49
|
|
version_id: WrTqKAz
|
|
url: https://semgrep.dev/playground/r/WrTqKAz/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route(...)
|
|
def $FUNC(..., $PARAM, ...):
|
|
...
|
|
- pattern: $PARAM
|
|
- pattern: |
|
|
request.$FUNC.get(...)
|
|
- pattern: |
|
|
request.$FUNC(...)
|
|
- pattern: request.$FUNC[...]
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-not-inside: return "..."
|
|
- pattern-either:
|
|
- pattern: return "...".format(...)
|
|
- pattern: return "..." % ...
|
|
- pattern: return "..." + ...
|
|
- pattern: return ... + "..."
|
|
- pattern: return f"...{...}..."
|
|
- patterns:
|
|
- pattern: return $X
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$X = "...".format(...)
|
|
...
|
|
- pattern-inside: |
|
|
$X = "..." % ...
|
|
...
|
|
- pattern-inside: |
|
|
$X = "..." + ...
|
|
...
|
|
- pattern-inside: |
|
|
$X = ... + "..."
|
|
...
|
|
- pattern-inside: |
|
|
$X = f"...{...}..."
|
|
...
|
|
- pattern-not-inside: |
|
|
$X = "..."
|
|
...
|
|
- id: python.flask.security.injection.os-system-injection.os-system-injection
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
message: User data detected in os.system. This could be vulnerable to a command
|
|
injection and should be avoided. If this must be done, use the 'subprocess' module
|
|
instead and pass the arguments as a list.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Command_Injection
|
|
category: security
|
|
technology:
|
|
- flask
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.flask.security.injection.os-system-injection.os-system-injection
|
|
shortlink: https://sg.run/4xzz
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9544
|
|
rv_id: 1263429
|
|
rule_id: BYUN99
|
|
version_id: 1QTypw7
|
|
url: https://semgrep.dev/playground/r/1QTypw7/python.flask.security.injection.os-system-injection.os-system-injection
|
|
origin: community
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: os.system(...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
os.system(..., <... $ROUTEVAR ...>, ...)
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
$INTERM = <... $ROUTEVAR ...>
|
|
...
|
|
os.system(..., <... $INTERM ...>, ...)
|
|
- pattern: os.system(..., <... flask.request.$W.get(...) ...>, ...)
|
|
- pattern: os.system(..., <... flask.request.$W[...] ...>, ...)
|
|
- pattern: os.system(..., <... flask.request.$W(...) ...>, ...)
|
|
- pattern: os.system(..., <... flask.request.$W ...>, ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W.get(...) ...>
|
|
...
|
|
os.system(<... $INTERM ...>)
|
|
- pattern: os.system(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W[...] ...>
|
|
...
|
|
os.system(<... $INTERM ...>)
|
|
- pattern: os.system(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W(...) ...>
|
|
...
|
|
os.system(<... $INTERM ...>)
|
|
- pattern: os.system(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W ...>
|
|
...
|
|
os.system(<... $INTERM ...>)
|
|
- pattern: os.system(...)
|
|
- id: python.flask.security.injection.path-traversal-open.path-traversal-open
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
message: Found request data in a call to 'open'. Ensure the request data is validated
|
|
or sanitized, otherwise it could result in path traversal attacks.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Path_Traversal
|
|
category: security
|
|
technology:
|
|
- flask
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/python.flask.security.injection.path-traversal-open.path-traversal-open
|
|
shortlink: https://sg.run/PJRW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9545
|
|
rv_id: 1263430
|
|
rule_id: DbUpOQ
|
|
version_id: 9lT4b94
|
|
url: https://semgrep.dev/playground/r/9lT4b94/python.flask.security.injection.path-traversal-open.path-traversal-open
|
|
origin: community
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: open(...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
open(..., <... $ROUTEVAR ...>, ...)
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
with open(..., <... $ROUTEVAR ...>, ...) as $FD:
|
|
...
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
$INTERM = <... $ROUTEVAR ...>
|
|
...
|
|
open(..., <... $INTERM ...>, ...)
|
|
- pattern: open(..., <... flask.request.$W.get(...) ...>, ...)
|
|
- pattern: open(..., <... flask.request.$W[...] ...>, ...)
|
|
- pattern: open(..., <... flask.request.$W(...) ...>, ...)
|
|
- pattern: open(..., <... flask.request.$W ...>, ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W.get(...) ...>
|
|
...
|
|
open(<... $INTERM ...>, ...)
|
|
- pattern: open(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W[...] ...>
|
|
...
|
|
open(<... $INTERM ...>, ...)
|
|
- pattern: open(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W(...) ...>
|
|
...
|
|
open(<... $INTERM ...>, ...)
|
|
- pattern: open(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W ...>
|
|
...
|
|
open(<... $INTERM ...>, ...)
|
|
- pattern: open(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W.get(...) ...>
|
|
...
|
|
with open(<... $INTERM ...>, ...) as $F:
|
|
...
|
|
- pattern: open(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W[...] ...>
|
|
...
|
|
with open(<... $INTERM ...>, ...) as $F:
|
|
...
|
|
- pattern: open(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W(...) ...>
|
|
...
|
|
with open(<... $INTERM ...>, ...) as $F:
|
|
...
|
|
- pattern: open(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W ...>
|
|
...
|
|
with open(<... $INTERM ...>, ...) as $F:
|
|
...
|
|
- pattern: open(...)
|
|
- id: python.flask.security.injection.ssrf-requests.ssrf-requests
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
message: Data from request object is passed to a new server-side request. This could
|
|
lead to a server-side request forgery (SSRF). To mitigate, ensure that schemes
|
|
and hosts are validated against an allowlist, do not forward the response to the
|
|
user, and ensure proper authentication and transport-layer security in the proxied
|
|
request.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Server_Side_Request_Forgery
|
|
category: security
|
|
technology:
|
|
- flask
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/python.flask.security.injection.ssrf-requests.ssrf-requests
|
|
shortlink: https://sg.run/J9LW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9546
|
|
rv_id: 1263432
|
|
rule_id: WAUoRx
|
|
version_id: rxTAKJn
|
|
url: https://semgrep.dev/playground/r/rxTAKJn/python.flask.security.injection.ssrf-requests.ssrf-requests
|
|
origin: community
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: requests.$FUNC(...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@$APP.$ROUTE_METHOD($ROUTE, ...)
|
|
def $ROUTE_FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
requests.$FUNC(..., <... $ROUTEVAR ...>, ...)
|
|
- pattern-inside: |
|
|
@$APP.$ROUTE_METHOD($ROUTE, ...)
|
|
def $ROUTE_FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
$INTERM = <... $ROUTEVAR ...>
|
|
...
|
|
requests.$FUNC(..., <... $INTERM ...>, ...)
|
|
- metavariable-regex:
|
|
metavariable: $ROUTE_METHOD
|
|
regex: ^(route|get|post|put|delete|patch)$
|
|
- pattern: requests.$FUNC(..., <... flask.request.$W.get(...) ...>, ...)
|
|
- pattern: requests.$FUNC(..., <... flask.request.$W[...] ...>, ...)
|
|
- pattern: requests.$FUNC(..., <... flask.request.$W(...) ...>, ...)
|
|
- pattern: requests.$FUNC(..., <... flask.request.$W ...>, ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W.get(...) ...>
|
|
...
|
|
requests.$FUNC(<... $INTERM ...>, ...)
|
|
- pattern: requests.$FUNC(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W[...] ...>
|
|
...
|
|
requests.$FUNC(<... $INTERM ...>, ...)
|
|
- pattern: requests.$FUNC(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W(...) ...>
|
|
...
|
|
requests.$FUNC(<... $INTERM ...>, ...)
|
|
- pattern: requests.$FUNC(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W ...>
|
|
...
|
|
requests.$FUNC(<... $INTERM ...>, ...)
|
|
- pattern: requests.$FUNC(...)
|
|
- id: python.flask.security.injection.user-eval.eval-injection
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
message: Detected user data flowing into eval. This is code injection and should
|
|
be avoided.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html
|
|
category: security
|
|
technology:
|
|
- flask
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.flask.security.injection.user-eval.eval-injection
|
|
shortlink: https://sg.run/5QpX
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9547
|
|
rv_id: 1263436
|
|
rule_id: 0oU54W
|
|
version_id: w8TRoB0
|
|
url: https://semgrep.dev/playground/r/w8TRoB0/python.flask.security.injection.user-eval.eval-injection
|
|
origin: community
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: eval(...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
eval(..., <... $ROUTEVAR ...>, ...)
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
$INTERM = <... $ROUTEVAR ...>
|
|
...
|
|
eval(..., <... $INTERM ...>, ...)
|
|
- pattern: eval(..., <... flask.request.$W.get(...) ...>, ...)
|
|
- pattern: eval(..., <... flask.request.$W[...] ...>, ...)
|
|
- pattern: eval(..., <... flask.request.$W(...) ...>, ...)
|
|
- pattern: eval(..., <... flask.request.$W ...>, ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W.get(...) ...>
|
|
...
|
|
eval(..., <... $INTERM ...>, ...)
|
|
- pattern: eval(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W[...] ...>
|
|
...
|
|
eval(..., <... $INTERM ...>, ...)
|
|
- pattern: eval(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W(...) ...>
|
|
...
|
|
eval(..., <... $INTERM ...>, ...)
|
|
- pattern: eval(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W ...>
|
|
...
|
|
eval(..., <... $INTERM ...>, ...)
|
|
- pattern: eval(...)
|
|
- id: python.flask.security.injection.user-exec.exec-injection
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
message: Detected user data flowing into exec. This is code injection and should
|
|
be avoided.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://nedbatchelder.com/blog/201206/exec_really_is_dangerous.html
|
|
category: security
|
|
technology:
|
|
- flask
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.flask.security.injection.user-exec.exec-injection
|
|
shortlink: https://sg.run/Ge42
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9548
|
|
rv_id: 1263437
|
|
rule_id: KxUbl2
|
|
version_id: xyTjzD9
|
|
url: https://semgrep.dev/playground/r/xyTjzD9/python.flask.security.injection.user-exec.exec-injection
|
|
origin: community
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: exec(...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
exec(..., <... $ROUTEVAR ...>, ...)
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
$INTERM = <... $ROUTEVAR ...>
|
|
...
|
|
exec(..., <... $INTERM ...>, ...)
|
|
- pattern: exec(..., <... flask.request.$W.get(...) ...>, ...)
|
|
- pattern: exec(..., <... flask.request.$W[...] ...>, ...)
|
|
- pattern: exec(..., <... flask.request.$W(...) ...>, ...)
|
|
- pattern: exec(..., <... flask.request.$W ...>, ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W.get(...) ...>
|
|
...
|
|
exec(..., <... $INTERM ...>, ...)
|
|
- pattern: exec(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W[...] ...>
|
|
...
|
|
exec(..., <... $INTERM ...>, ...)
|
|
- pattern: exec(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W(...) ...>
|
|
...
|
|
exec(..., <... $INTERM ...>, ...)
|
|
- pattern: exec(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$INTERM = <... flask.request.$W ...>
|
|
...
|
|
exec(..., <... $INTERM ...>, ...)
|
|
- pattern: exec(...)
|
|
- id: python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret
|
|
message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently
|
|
Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html
|
|
Consider using an appropriate security mechanism to protect the credentials (e.g.
|
|
keeping secrets in environment variables)'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
references:
|
|
- https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret
|
|
shortlink: https://sg.run/l2E9
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9557
|
|
rv_id: 1263452
|
|
rule_id: X5U8P5
|
|
version_id: PkTR3X3
|
|
url: https://semgrep.dev/playground/r/PkTR3X3/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret
|
|
origin: community
|
|
patterns:
|
|
- pattern: |
|
|
jwt.encode($_, "...", ...)
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.jwt.security.jwt-none-alg.jwt-python-none-alg
|
|
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
|
|
assumes the integrity of the token has already been verified. This would allow
|
|
a malicious actor to forge a JWT token that will automatically be verified. Do
|
|
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.jwt.security.jwt-none-alg.jwt-python-none-alg
|
|
shortlink: https://sg.run/Yvp4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9558
|
|
rv_id: 1263453
|
|
rule_id: j2UvKw
|
|
version_id: JdTzxYj
|
|
url: https://semgrep.dev/playground/r/JdTzxYj/python.jwt.security.jwt-none-alg.jwt-python-none-alg
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
pattern-either:
|
|
- pattern: |
|
|
jwt.encode(...,algorithm="none",...)
|
|
- pattern: jwt.decode(...,algorithms=[...,"none",...],...)
|
|
- id: python.jwt.security.unverified-jwt-decode.unverified-jwt-decode
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
jwt.decode(..., options={..., "verify_signature": $BOOL, ...}, ...)
|
|
- metavariable-pattern:
|
|
metavariable: $BOOL
|
|
pattern: |
|
|
False
|
|
- focus-metavariable: $BOOL
|
|
- patterns:
|
|
- pattern: |
|
|
$OPTS = {..., "verify_signature": $BOOL, ...}
|
|
...
|
|
jwt.decode(..., options=$OPTS, ...)
|
|
- metavariable-pattern:
|
|
metavariable: $BOOL
|
|
pattern: |
|
|
False
|
|
- focus-metavariable: $BOOL
|
|
message: Detected JWT token decoded with 'verify=False'. This bypasses any integrity
|
|
checks for the token which means the token could be tampered with by malicious
|
|
actors. Ensure that the JWT token is verified.
|
|
metadata:
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe:
|
|
- 'CWE-287: Improper Authentication'
|
|
references:
|
|
- https://github.com/we45/Vulnerable-Flask-App/blob/752ee16087c0bfb79073f68802d907569a1f0df7/app/app.py#L96
|
|
category: security
|
|
technology:
|
|
- jwt
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode
|
|
shortlink: https://sg.run/6nyB
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9559
|
|
rv_id: 1263454
|
|
rule_id: 10UKjo
|
|
version_id: 5PTo12w
|
|
url: https://semgrep.dev/playground/r/5PTo12w/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode
|
|
origin: community
|
|
fix: |
|
|
True
|
|
severity: ERROR
|
|
languages:
|
|
- python
|
|
- id: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
|
|
pattern: hashlib.sha1(...)
|
|
fix-regex:
|
|
regex: sha1
|
|
replacement: sha256
|
|
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
|
|
collision resistant and is therefore not suitable as a cryptographic signature.
|
|
Use SHA256 or SHA3 instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B303
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.2 Insecure Custom Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
references:
|
|
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
|
|
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
|
|
- http://2012.sharcs.org/slides/stevens.pdf
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- python
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
|
|
shortlink: https://sg.run/ydYx
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9624
|
|
rv_id: 1263537
|
|
rule_id: x8UnBk
|
|
version_id: w8TRoE7
|
|
url: https://semgrep.dev/playground/r/w8TRoE7/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
- id: python.lang.security.insecure-hash-function.insecure-hash-function
|
|
message: Detected use of an insecure MD4 or MD5 hash function. These functions have
|
|
known vulnerabilities and are considered deprecated. Consider using 'SHA256' or
|
|
a similar function instead.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/hashlib_new_insecure_functions.py
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.2 Insecure Custom Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
references:
|
|
- https://tools.ietf.org/html/rfc6151
|
|
- https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- python
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.lang.security.insecure-hash-function.insecure-hash-function
|
|
shortlink: https://sg.run/rdBn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9625
|
|
rv_id: 1263538
|
|
rule_id: OrU30g
|
|
version_id: xyTjzEe
|
|
url: https://semgrep.dev/playground/r/xyTjzEe/python.lang.security.insecure-hash-function.insecure-hash-function
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern: hashlib.new("=~/[M|m][D|d][4|5]/", ...)
|
|
- pattern: hashlib.new(..., name="=~/[M|m][D|d][4|5]/", ...)
|
|
- id: python.lang.security.unverified-ssl-context.unverified-ssl-context
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: ssl._create_unverified_context(...)
|
|
- pattern: ssl._create_default_https_context = ssl._create_unverified_context
|
|
fix-regex:
|
|
regex: _create_unverified_context
|
|
replacement: create_default_context
|
|
message: Unverified SSL context detected. This will permit insecure connections
|
|
without verifying SSL certificates. Use 'ssl.create_default_context' instead.
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe:
|
|
- 'CWE-295: Improper Certificate Validation'
|
|
references:
|
|
- https://docs.python.org/3/library/ssl.html#ssl-security
|
|
- https://docs.python.org/3/library/http.client.html#http.client.HTTPSConnection
|
|
category: security
|
|
technology:
|
|
- python
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/python.lang.security.unverified-ssl-context.unverified-ssl-context
|
|
shortlink: https://sg.run/N4lp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9627
|
|
rv_id: 1263540
|
|
rule_id: v8UnkQ
|
|
version_id: e1Tyjlj
|
|
url: https://semgrep.dev/playground/r/e1Tyjlj/python.lang.security.unverified-ssl-context.unverified-ssl-context
|
|
origin: community
|
|
severity: ERROR
|
|
languages:
|
|
- python
|
|
- id: python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated
|
|
pattern: ssl.wrap_socket(...)
|
|
message: '''ssl.wrap_socket()'' is deprecated. This function creates an insecure
|
|
socket without server name indication or hostname matching. Instead, create an
|
|
SSL context using ''ssl.SSLContext()'' and use that to wrap a socket.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://docs.python.org/3/library/ssl.html#ssl.wrap_socket
|
|
- https://docs.python.org/3/library/ssl.html#ssl.SSLContext.wrap_socket
|
|
category: security
|
|
technology:
|
|
- python
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated
|
|
shortlink: https://sg.run/PJOY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9645
|
|
rv_id: 1263516
|
|
rule_id: BYUN2e
|
|
version_id: DkTRbgn
|
|
url: https://semgrep.dev/playground/r/DkTRbgn/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true
|
|
patterns:
|
|
- pattern: subprocess.$FUNC(..., shell=$TRUE, ...)
|
|
- metavariable-pattern:
|
|
metavariable: $TRUE
|
|
pattern: "True \n"
|
|
- pattern-not: subprocess.$FUNC("...", shell=True, ...)
|
|
- focus-metavariable: $TRUE
|
|
message: Found 'subprocess' function '$FUNC' with 'shell=True'. This is dangerous
|
|
because this call will spawn the command using a shell process. Doing so propagates
|
|
current shell settings and variables, which makes it much easier for a malicious
|
|
actor to execute commands. Use 'shell=False' instead.
|
|
fix: |
|
|
False
|
|
metadata:
|
|
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b602_subprocess_popen_with_shell_equals_true.html
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
references:
|
|
- https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess
|
|
- https://docs.python.org/3/library/subprocess.html
|
|
category: security
|
|
technology:
|
|
- python
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- secure default
|
|
likelihood: HIGH
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true
|
|
shortlink: https://sg.run/J92w
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9646
|
|
rv_id: 1263518
|
|
rule_id: DbUpz2
|
|
version_id: 0bTKzDK
|
|
url: https://semgrep.dev/playground/r/0bTKzDK/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.audit.weak-ssl-version.weak-ssl-version
|
|
message: An insecure SSL version was detected. TLS versions 1.0, 1.1, and all SSL
|
|
versions are considered weak encryption and are deprecated. Use 'ssl.PROTOCOL_TLSv1_2'
|
|
or higher.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/insecure_ssl_tls.py#L30
|
|
asvs:
|
|
section: V9 Communications Verification Requirements
|
|
control_id: 9.1.3 Weak TLS
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v91-client-communications-security-requirements
|
|
version: '4'
|
|
references:
|
|
- https://tools.ietf.org/html/rfc7568
|
|
- https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html
|
|
- https://docs.python.org/3/library/ssl.html#ssl.PROTOCOL_TLSv1_2
|
|
category: security
|
|
technology:
|
|
- python
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.lang.security.audit.weak-ssl-version.weak-ssl-version
|
|
shortlink: https://sg.run/RoZO
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9649
|
|
rv_id: 1263520
|
|
rule_id: KxUbNG
|
|
version_id: qkTR7Ev
|
|
url: https://semgrep.dev/playground/r/qkTR7Ev/python.lang.security.audit.weak-ssl-version.weak-ssl-version
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern: ssl.PROTOCOL_SSLv2
|
|
- pattern: ssl.PROTOCOL_SSLv3
|
|
- pattern: ssl.PROTOCOL_TLSv1
|
|
- pattern: ssl.PROTOCOL_TLSv1_1
|
|
- pattern: pyOpenSSL.SSL.SSLv2_METHOD
|
|
- pattern: pyOpenSSL.SSL.SSLv23_METHOD
|
|
- pattern: pyOpenSSL.SSL.SSLv3_METHOD
|
|
- pattern: pyOpenSSL.SSL.TLSv1_METHOD
|
|
- pattern: pyOpenSSL.SSL.TLSv1_1_METHOD
|
|
- id: python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context
|
|
options:
|
|
symbolic_propagation: true
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: |
|
|
"$URL"
|
|
- metavariable-pattern:
|
|
metavariable: $URL
|
|
language: regex
|
|
patterns:
|
|
- pattern-regex: http://
|
|
- pattern-not-regex: .*://localhost
|
|
- pattern-not-regex: .*://127\.0\.0\.1
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
with requests.Session(...) as $SESSION:
|
|
...
|
|
- pattern-either:
|
|
- pattern: $SESSION.$W($SINK, ...)
|
|
- pattern: $SESSION.request($METHOD, $SINK, ...)
|
|
- focus-metavariable: $SINK
|
|
fix-regex:
|
|
regex: '[Hh][Tt][Tt][Pp]://'
|
|
replacement: https://
|
|
count: 1
|
|
message: Detected a request using 'http://'. This request will be unencrypted. Use
|
|
'https://' instead.
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
asvs:
|
|
section: V9 Communications Verification Requirements
|
|
control_id: 9.2.1 Weak TLS
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- requests
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context
|
|
shortlink: https://sg.run/Bk5W
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9651
|
|
rv_id: 1263484
|
|
rule_id: lBU9BZ
|
|
version_id: vdT06wb
|
|
url: https://semgrep.dev/playground/r/vdT06wb/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: INFO
|
|
- id: python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http
|
|
options:
|
|
symbolic_propagation: true
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: |
|
|
"$URL"
|
|
- metavariable-pattern:
|
|
metavariable: $URL
|
|
language: regex
|
|
patterns:
|
|
- pattern-regex: http://
|
|
- pattern-not-regex: .*://localhost
|
|
- pattern-not-regex: .*://127\.0\.0\.1
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: requests.Session(...).$W($SINK, ...)
|
|
- pattern: requests.Session(...).request($METHOD, $SINK, ...)
|
|
- focus-metavariable: $SINK
|
|
fix-regex:
|
|
regex: '[Hh][Tt][Tt][Pp]://'
|
|
replacement: https://
|
|
count: 1
|
|
message: Detected a request using 'http://'. This request will be unencrypted. Use
|
|
'https://' instead.
|
|
languages:
|
|
- python
|
|
severity: INFO
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
asvs:
|
|
section: V9 Communications Verification Requirements
|
|
control_id: 9.1.1 Weak TLS
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- requests
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http
|
|
shortlink: https://sg.run/DoBY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9652
|
|
rv_id: 1263485
|
|
rule_id: YGURXw
|
|
version_id: d6Tyx02
|
|
url: https://semgrep.dev/playground/r/d6Tyx02/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http
|
|
origin: community
|
|
- id: python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http
|
|
fix-regex:
|
|
regex: '[Hh][Tt][Tt][Pp]://'
|
|
replacement: https://
|
|
count: 1
|
|
message: Detected a request using 'http://'. This request will be unencrypted, and
|
|
attackers could listen into traffic on the network and be able to obtain sensitive
|
|
information. Use 'https://' instead.
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
asvs:
|
|
section: V9 Communications Verification Requirements
|
|
control_id: 9.1.1 Weak TLS
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- requests
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http
|
|
shortlink: https://sg.run/W8J4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9653
|
|
rv_id: 1263486
|
|
rule_id: 6JUjpG
|
|
version_id: ZRTKA9v
|
|
url: https://semgrep.dev/playground/r/ZRTKA9v/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: INFO
|
|
options:
|
|
symbolic_propagation: true
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: |
|
|
"$URL"
|
|
- metavariable-pattern:
|
|
metavariable: $URL
|
|
language: regex
|
|
patterns:
|
|
- pattern-regex: http://
|
|
- pattern-not-regex: .*://localhost
|
|
- pattern-not-regex: .*://127\.0\.0\.1
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: requests.$W($SINK, ...)
|
|
- pattern: requests.request($METHOD, $SINK, ...)
|
|
- pattern: requests.Request($METHOD, $SINK, ...)
|
|
- focus-metavariable: $SINK
|
|
- id: python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure
|
|
patterns:
|
|
- pattern: |
|
|
$LOGGER_OBJ.$LOGGER_CALL($FORMAT_STRING,...)
|
|
- metavariable-regex:
|
|
metavariable: $LOGGER_OBJ
|
|
regex: (?i)(_logger|logger|self.logger|log)
|
|
- metavariable-regex:
|
|
metavariable: $LOGGER_CALL
|
|
regex: (debug|info|warn|warning|error|exception|critical)
|
|
- metavariable-regex:
|
|
metavariable: $FORMAT_STRING
|
|
regex: (?i).*(api.key|secret|credential|token|password).*\%s.*
|
|
message: Detected a python logger call with a potential hardcoded secret $FORMAT_STRING
|
|
being logged. This may lead to secret credentials being exposed. Make sure that
|
|
the logger is not logging sensitive information.
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-532: Insertion of Sensitive Information into Log File'
|
|
category: security
|
|
technology:
|
|
- python
|
|
owasp:
|
|
- A09:2021 - Security Logging and Monitoring Failures
|
|
- A09:2025 - Security Logging & Alerting Failures
|
|
references:
|
|
- https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure
|
|
shortlink: https://sg.run/ydNx
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9668
|
|
rv_id: 1263501
|
|
rule_id: x8UnJk
|
|
version_id: A8TgdOR
|
|
url: https://semgrep.dev/playground/r/A8TgdOR/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure
|
|
origin: community
|
|
- id: python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces
|
|
message: Running `socket.bind` to 0.0.0.0, or empty string could unexpectedly expose
|
|
the server publicly as it binds to all available interfaces. Consider instead
|
|
getting correct address from an environment variable or configuration file.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- python
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces
|
|
shortlink: https://sg.run/rdln
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9669
|
|
rv_id: 1263505
|
|
rule_id: OrU3og
|
|
version_id: 0bTKzDL
|
|
url: https://semgrep.dev/playground/r/0bTKzDL/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: INFO
|
|
pattern-either:
|
|
- pattern: |
|
|
$S = socket.socket(...)
|
|
...
|
|
$S.bind(("0.0.0.0", ...))
|
|
- pattern: |
|
|
$S = socket.socket(...)
|
|
...
|
|
$S.bind(("::", ...))
|
|
- pattern: |
|
|
$S = socket.socket(...)
|
|
...
|
|
$S.bind(("", ...))
|
|
- id: python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: urllib3.PoolManager(..., cert_reqs=$REQS, ...)
|
|
- pattern: urllib3.ProxyManager(..., cert_reqs=$REQS, ...)
|
|
- pattern: urllib3.HTTPSConnectionPool(..., cert_reqs=$REQS, ...)
|
|
- pattern: urllib3.connectionpool.HTTPSConnectionPool(..., cert_reqs=$REQS, ...)
|
|
- pattern: urllib3.connection_from_url(..., cert_reqs=$REQS, ...)
|
|
- pattern: urllib3.proxy_from_url(..., cert_reqs=$REQS, ...)
|
|
- pattern: $CONTEXT.wrap_socket(..., cert_reqs=$REQS, ...)
|
|
- pattern: ssl.wrap_socket(..., cert_reqs=$REQS, ...)
|
|
- metavariable-regex:
|
|
metavariable: $REQS
|
|
regex: (NONE|CERT_NONE|CERT_OPTIONAL|ssl\.CERT_NONE|ssl\.CERT_OPTIONAL|\'NONE\'|\"NONE\"|\'OPTIONAL\'|\"OPTIONAL\")
|
|
message: certificate verification explicitly disabled, insecure connections possible
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-295: Improper Certificate Validation'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
category: security
|
|
technology:
|
|
- python
|
|
references:
|
|
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation
|
|
shortlink: https://sg.run/b7yp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9670
|
|
rv_id: 1263506
|
|
rule_id: eqU87k
|
|
version_id: K3TKkZn
|
|
url: https://semgrep.dev/playground/r/K3TKkZn/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.audit.network.http-not-https-connection.http-not-https-connection
|
|
message: Detected HTTPConnectionPool. This will transmit data in cleartext. It is
|
|
recommended to use HTTPSConnectionPool instead for to encrypt communications.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://urllib3.readthedocs.io/en/1.2.1/pools.html#urllib3.connectionpool.HTTPSConnectionPool
|
|
category: security
|
|
technology:
|
|
- python
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection
|
|
shortlink: https://sg.run/N4Np
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9671
|
|
rv_id: 1263507
|
|
rule_id: v8UnWQ
|
|
version_id: qkTR7E1
|
|
url: https://semgrep.dev/playground/r/qkTR7E1/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
pattern-either:
|
|
- pattern: urllib3.HTTPConnectionPool(...)
|
|
- pattern: urllib3.connectionpool.HTTPConnectionPool(...)
|
|
- id: python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load
|
|
metadata:
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
references:
|
|
- https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation
|
|
- https://nvd.nist.gov/vuln/detail/CVE-2017-18342
|
|
category: security
|
|
technology:
|
|
- pyyaml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load
|
|
shortlink: https://sg.run/we9Y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9673
|
|
rv_id: 1263530
|
|
rule_id: ZqU5jZ
|
|
version_id: 1QTyprw
|
|
url: https://semgrep.dev/playground/r/1QTyprw/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load
|
|
origin: community
|
|
languages:
|
|
- python
|
|
message: Detected a possible YAML deserialization vulnerability. `yaml.unsafe_load`,
|
|
`yaml.Loader`, `yaml.CLoader`, and `yaml.UnsafeLoader` are all known to be unsafe
|
|
methods of deserializing YAML. An attacker with control over the YAML input could
|
|
create special YAML input that allows the attacker to run arbitrary Python code.
|
|
This would allow the attacker to steal files, download and install malware, or
|
|
otherwise take over the machine. Use `yaml.safe_load` or `yaml.SafeLoader` instead.
|
|
fix-regex:
|
|
regex: unsafe_load
|
|
replacement: safe_load
|
|
count: 1
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-inside: |
|
|
import yaml
|
|
...
|
|
- pattern-not-inside: |
|
|
$YAML = ruamel.yaml.YAML(...)
|
|
...
|
|
- pattern-either:
|
|
- pattern: yaml.unsafe_load(...)
|
|
- pattern: yaml.load(..., Loader=yaml.Loader, ...)
|
|
- pattern: yaml.load(..., Loader=yaml.UnsafeLoader, ...)
|
|
- pattern: yaml.load(..., Loader=yaml.CLoader, ...)
|
|
- pattern: yaml.load_all(..., Loader=yaml.Loader, ...)
|
|
- pattern: yaml.load_all(..., Loader=yaml.UnsafeLoader, ...)
|
|
- pattern: yaml.load_all(..., Loader=yaml.CLoader, ...)
|
|
- id: python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel
|
|
metadata:
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
references:
|
|
- https://yaml.readthedocs.io/en/latest/basicuse.html?highlight=typ
|
|
category: security
|
|
technology:
|
|
- ruamel.yaml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel
|
|
shortlink: https://sg.run/x1rz
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9674
|
|
rv_id: 1263531
|
|
rule_id: nJUzqK
|
|
version_id: 9lT4bvG
|
|
url: https://semgrep.dev/playground/r/9lT4bvG/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel
|
|
origin: community
|
|
languages:
|
|
- python
|
|
message: Avoid using unsafe `ruamel.yaml.YAML()`. `ruamel.yaml.YAML` can create
|
|
arbitrary Python objects. A malicious actor could exploit this to run arbitrary
|
|
code. Use `YAML(typ='rt')` or `YAML(typ='safe')` instead.
|
|
severity: ERROR
|
|
pattern-either:
|
|
- pattern: ruamel.yaml.YAML(..., typ='unsafe', ...)
|
|
- pattern: ruamel.yaml.YAML(..., typ='base', ...)
|
|
- id: python.lang.security.deserialization.pickle.avoid-shelve
|
|
metadata:
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
references:
|
|
- https://docs.python.org/3/library/pickle.html
|
|
category: security
|
|
technology:
|
|
- python
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/python.lang.security.deserialization.pickle.avoid-shelve
|
|
shortlink: https://sg.run/dKkZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9678
|
|
rv_id: 1263535
|
|
rule_id: 8GUje2
|
|
version_id: NdTzyb4
|
|
url: https://semgrep.dev/playground/r/NdTzyb4/python.lang.security.deserialization.pickle.avoid-shelve
|
|
origin: community
|
|
languages:
|
|
- python
|
|
message: Avoid using `shelve`, which uses `pickle`, which is known to lead to code
|
|
execution vulnerabilities. When unpickling, the serialized data could be manipulated
|
|
to run arbitrary code. Instead, consider serializing the relevant data as JSON
|
|
or a similar text-based serialization format.
|
|
severity: WARNING
|
|
pattern: shelve.$FUNC(...)
|
|
- id: python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor
|
|
message: Detected XOR cipher algorithm which is considered insecure. This algorithm
|
|
is not cryptographically secure and can be reversed easily. Use AES instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor
|
|
shortlink: https://sg.run/L0yr
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9683
|
|
rv_id: 1263549
|
|
rule_id: PeUk5W
|
|
version_id: gETB7j3
|
|
url: https://semgrep.dev/playground/r/gETB7j3/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Cryptodome.Cipher.XOR.new(...)
|
|
- pattern: Crypto.Cipher.XOR.new(...)
|
|
- id: python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1
|
|
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
|
|
collision resistant and is therefore not suitable as a cryptographic signature.
|
|
Use SHA256 or SHA3 instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
|
|
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
|
|
- http://2012.sharcs.org/slides/stevens.pdf
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1
|
|
shortlink: https://sg.run/3ALr
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9687
|
|
rv_id: 1263553
|
|
rule_id: ReUPO3
|
|
version_id: PkTR3vk
|
|
url: https://semgrep.dev/playground/r/PkTR3vk/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Crypto.Hash.SHA.new(...)
|
|
- pattern: Cryptodome.Hash.SHA.new (...)
|
|
- id: python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size
|
|
message: Detected an insufficient key size for DSA. NIST recommends a key size of
|
|
2048 or higher.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
|
|
references:
|
|
- https://www.pycryptodome.org/src/public_key/dsa
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::key-length::pycryptodome
|
|
- crypto::search::key-length::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size
|
|
shortlink: https://sg.run/4y8l
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9688
|
|
rv_id: 1263554
|
|
rule_id: AbUWje
|
|
version_id: JdTzxbQ
|
|
url: https://semgrep.dev/playground/r/JdTzxbQ/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: Crypto.PublicKey.DSA.generate(..., bits=$SIZE, ...)
|
|
- pattern: Crypto.PublicKey.DSA.generate($SIZE, ...)
|
|
- pattern: Cryptodome.PublicKey.DSA.generate(..., bits=$SIZE, ...)
|
|
- pattern: Cryptodome.PublicKey.DSA.generate($SIZE, ...)
|
|
- metavariable-comparison:
|
|
metavariable: $SIZE
|
|
comparison: $SIZE < 2048
|
|
- id: python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
message: Detected an insufficient key size for RSA. NIST recommends a key size of
|
|
3072 or higher.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
|
|
references:
|
|
- https://www.pycryptodome.org/src/public_key/rsa#rsa
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::key-length::pycryptodome
|
|
- crypto::search::key-length::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
shortlink: https://sg.run/PprY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9689
|
|
rv_id: 1263555
|
|
rule_id: BYUBWe
|
|
version_id: 5PTo1jL
|
|
url: https://semgrep.dev/playground/r/5PTo1jL/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: Crypto.PublicKey.RSA.generate(..., bits=$SIZE, ...)
|
|
- pattern: Crypto.PublicKey.RSA.generate($SIZE, ...)
|
|
- pattern: Cryptodome.PublicKey.RSA.generate(..., bits=$SIZE, ...)
|
|
- pattern: Cryptodome.PublicKey.RSA.generate($SIZE, ...)
|
|
- metavariable-comparison:
|
|
metavariable: $SIZE
|
|
comparison: $SIZE < 3072
|
|
- id: python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
def $FUNC(...,$VAR,...):
|
|
...
|
|
$SESSION.query(...).$SQLFUNC("...".$FORMATFUNC(...,$VAR,...))
|
|
- pattern: |
|
|
def $FUNC(...,$VAR,...):
|
|
...
|
|
$SESSION.query.join(...).$SQLFUNC("...".$FORMATFUNC(...,$VAR,...))
|
|
- pattern: |
|
|
def $FUNC(...,$VAR,...):
|
|
...
|
|
$SESSION.query.$SQLFUNC("...".$FORMATFUNC(...,$VAR,...))
|
|
- pattern: |
|
|
def $FUNC(...,$VAR,...):
|
|
...
|
|
query.$SQLFUNC("...".$FORMATFUNC(...,$VAR,...))
|
|
- metavariable-regex:
|
|
metavariable: $SQLFUNC
|
|
regex: (group_by|order_by|distinct|having|filter)
|
|
- metavariable-regex:
|
|
metavariable: $FORMATFUNC
|
|
regex: (?!bindparams)
|
|
message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause
|
|
sql injections if the developer inputs raw SQL into the before-mentioned clauses.
|
|
This pattern captures relevant cases in which the developer inputs raw SQL into
|
|
the distinct, having, group_by, order_by or filter clauses and injects user-input
|
|
into the raw SQL with any function besides "bindparams". Use bindParams to securely
|
|
bind user-input to SQL statements.
|
|
fix-regex:
|
|
regex: format
|
|
replacement: bindparams
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
category: security
|
|
technology:
|
|
- sqlalchemy
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection
|
|
shortlink: https://sg.run/J3Xo
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9702
|
|
rv_id: 1263579
|
|
rule_id: BYUBWo
|
|
version_id: NdTzyL4
|
|
url: https://semgrep.dev/playground/r/NdTzyL4/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection
|
|
origin: community
|
|
- id: ruby.lang.security.bad-deserialization.bad-deserialization
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: cookies
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- pattern: |
|
|
CSV.load(...)
|
|
- pattern: |
|
|
Marshal.load(...)
|
|
- pattern: |
|
|
Marshal.restore(...)
|
|
- pattern: |
|
|
Oj.object_load(...)
|
|
- pattern: |
|
|
Oj.load($X)
|
|
message: Checks for unsafe deserialization. Objects in Ruby can be serialized into
|
|
strings, then later loaded from strings. However, uses of load and object_load
|
|
can cause remote code execution. Loading user input with MARSHAL or CSV can potentially
|
|
be dangerous. Use JSON in a secure fashion instead.
|
|
metadata:
|
|
references:
|
|
- https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ
|
|
- https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
technology:
|
|
- ruby
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/ruby.lang.security.bad-deserialization.bad-deserialization
|
|
shortlink: https://sg.run/DJj2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9708
|
|
rv_id: 1263595
|
|
rule_id: lBUdQg
|
|
version_id: 3ZT4Xqp
|
|
url: https://semgrep.dev/playground/r/3ZT4Xqp/ruby.lang.security.bad-deserialization.bad-deserialization
|
|
origin: community
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
- id: ruby.lang.security.force-ssl-false.force-ssl-false
|
|
message: Checks for configuration setting of force_ssl to false. Force_ssl forces
|
|
usage of HTTPS, which could lead to network interception of unencrypted application
|
|
traffic. To fix, set config.force_ssl = true.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-311: Missing Encryption of Sensitive Data'
|
|
references:
|
|
- https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_force_ssl.rb
|
|
category: security
|
|
technology:
|
|
- ruby
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/ruby.lang.security.force-ssl-false.force-ssl-false
|
|
shortlink: https://sg.run/YgkW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9714
|
|
rv_id: 1263605
|
|
rule_id: 2ZU4lx
|
|
version_id: WrTqKB3
|
|
url: https://semgrep.dev/playground/r/WrTqKB3/ruby.lang.security.force-ssl-false.force-ssl-false
|
|
origin: community
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
pattern: config.force_ssl = false
|
|
fix-regex:
|
|
regex: =\s*false
|
|
replacement: = true
|
|
- id: ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller
|
|
patterns:
|
|
- pattern-inside: |
|
|
class $CONTROLLER < ApplicationController
|
|
...
|
|
http_basic_authenticate_with ..., :password => "$SECRET", ...
|
|
end
|
|
- focus-metavariable: $SECRET
|
|
message: Detected hardcoded password used in basic authentication in a controller
|
|
class. Including this password in version control could expose this credential.
|
|
Consider refactoring to use environment variables or configuration files.
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/basic_auth/index.markdown
|
|
category: security
|
|
technology:
|
|
- ruby
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller
|
|
shortlink: https://sg.run/6r0w
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9715
|
|
rv_id: 1263606
|
|
rule_id: X5UZWK
|
|
version_id: 0bTKzNK
|
|
url: https://semgrep.dev/playground/r/0bTKzNK/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller
|
|
origin: community
|
|
languages:
|
|
- ruby
|
|
- id: ruby.lang.security.no-eval.ruby-eval
|
|
message: Use of eval with user-controllable input detected. This can lead to attackers
|
|
running arbitrary code. Ensure external data does not reach here, otherwise this
|
|
is a security vulnerability. Consider other ways to do this without eval.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_evaluation.rb
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/ruby.lang.security.no-eval.ruby-eval
|
|
shortlink: https://sg.run/bDwZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9726
|
|
rv_id: 1263615
|
|
rule_id: OrUGNk
|
|
version_id: A8TgdDv
|
|
url: https://semgrep.dev/playground/r/A8TgdDv/ruby.lang.security.no-eval.ruby-eval
|
|
origin: community
|
|
languages:
|
|
- ruby
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: cookies
|
|
- patterns:
|
|
- pattern: |
|
|
RubyVM::InstructionSequence.compile(...)
|
|
- pattern-not: |
|
|
RubyVM::InstructionSequence.compile("...")
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $X.eval
|
|
- pattern: $X.class_eval
|
|
- pattern: $X.instance_eval
|
|
- pattern: $X.module_eval
|
|
- pattern: $X.eval(...)
|
|
- pattern: $X.class_eval(...)
|
|
- pattern: $X.instance_eval(...)
|
|
- pattern: $X.module_eval(...)
|
|
- pattern: eval(...)
|
|
- pattern: class_eval(...)
|
|
- pattern: module_eval(...)
|
|
- pattern: instance_eval(...)
|
|
- pattern-not: $M("...",...)
|
|
- id: ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify
|
|
pattern: OpenSSL::SSL::VERIFY_NONE
|
|
message: Detected SSL that will accept an unverified connection. This makes the
|
|
connections susceptible to man-in-the-middle attacks. Use 'OpenSSL::SSL::VERIFY_PEER'
|
|
instead.
|
|
fix-regex:
|
|
regex: VERIFY_NONE
|
|
replacement: VERIFY_PEER
|
|
severity: WARNING
|
|
languages:
|
|
- ruby
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-295: Improper Certificate Validation'
|
|
category: security
|
|
technology:
|
|
- ruby
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
references:
|
|
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify
|
|
shortlink: https://sg.run/kLxX
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9728
|
|
rv_id: 1263617
|
|
rule_id: v8U5Yn
|
|
version_id: DkTRbl4
|
|
url: https://semgrep.dev/playground/r/DkTRbl4/ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify
|
|
origin: community
|
|
- id: ruby.lang.security.weak-hashes-md5.weak-hashes-md5
|
|
message: Should not use md5 to generate hashes. md5 is proven to be vulnerable through
|
|
the use of brute-force attacks. Could also result in collisions, leading to potential
|
|
collision attacks. Use SHA256 or other hashing functions instead.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
references:
|
|
- https://www.ibm.com/support/pages/security-bulletin-vulnerability-md5-signature-and-hash-algorithm-affects-sterling-integrator-and-sterling-file-gateway-cve-2015-7575
|
|
category: security
|
|
technology:
|
|
- ruby
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/ruby.lang.security.weak-hashes-md5.weak-hashes-md5
|
|
shortlink: https://sg.run/O1re
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9731
|
|
rv_id: 1263619
|
|
rule_id: nJUYxZ
|
|
version_id: 0bTKzN8
|
|
url: https://semgrep.dev/playground/r/0bTKzN8/ruby.lang.security.weak-hashes-md5.weak-hashes-md5
|
|
origin: community
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern: Digest::MD5.base64digest $X
|
|
- pattern: Digest::MD5.hexdigest $X
|
|
- pattern: Digest::MD5.digest $X
|
|
- pattern: Digest::MD5.new
|
|
- pattern: OpenSSL::Digest::MD5.base64digest $X
|
|
- pattern: OpenSSL::Digest::MD5.hexdigest $X
|
|
- pattern: OpenSSL::Digest::MD5.digest $X
|
|
- pattern: OpenSSL::Digest::MD5.new
|
|
- id: ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1
|
|
message: Should not use SHA1 to generate hashes. There is a proven SHA1 hash collision
|
|
by Google, which could lead to vulnerabilities. Use SHA256, SHA3 or other hashing
|
|
functions instead.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
references:
|
|
- https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html
|
|
- https://shattered.io/
|
|
category: security
|
|
technology:
|
|
- ruby
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1
|
|
shortlink: https://sg.run/e4qX
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9732
|
|
rv_id: 1263620
|
|
rule_id: EwU4jq
|
|
version_id: K3TKkEZ
|
|
url: https://semgrep.dev/playground/r/K3TKkEZ/ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1
|
|
origin: community
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern: Digest::SHA1.$FUNC
|
|
- pattern: OpenSSL::Digest::SHA1.$FUNC
|
|
- pattern: OpenSSL::HMAC.$FUNC("sha1",...)
|
|
- id: terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket
|
|
pattern: acl = "public-read-write"
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
message: S3 bucket with public read-write access detected.
|
|
metadata:
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#acl
|
|
- https://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html#canned-acl
|
|
cwe:
|
|
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket
|
|
shortlink: https://sg.run/0nok
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9754
|
|
rv_id: 1263900
|
|
rule_id: 6JUqvn
|
|
version_id: PkTR3y5
|
|
url: https://semgrep.dev/playground/r/PkTR3y5/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket
|
|
origin: community
|
|
- id: typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust
|
|
message: Detected the use of `$TRUST`. This can introduce a Cross-Site-Scripting
|
|
(XSS) vulnerability if this comes from user-provided input. If you have to use
|
|
`$TRUST`, ensure it does not come from user-input or use the appropriate prevention
|
|
mechanism e.g. input validation or sanitization depending on the context.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
references:
|
|
- https://angular.io/api/platform-browser/DomSanitizer
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
confidence: MEDIUM
|
|
category: security
|
|
technology:
|
|
- angular
|
|
- browser
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust
|
|
shortlink: https://sg.run/KWxP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9755
|
|
rv_id: 1263902
|
|
rule_id: oqUzgA
|
|
version_id: 5PTo1zk
|
|
url: https://semgrep.dev/playground/r/5PTo1zk/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust
|
|
origin: community
|
|
languages:
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
function ...({..., $X: string, ...}) { ... }
|
|
- pattern-inside: |
|
|
function ...(..., $X: string, ...) { ... }
|
|
- focus-metavariable: $X
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $X.$TRUST($Y)
|
|
- focus-metavariable: $Y
|
|
- pattern-not: |
|
|
$X.$TRUST(`...`)
|
|
- pattern-not: |
|
|
$X.$TRUST("...")
|
|
- metavariable-regex:
|
|
metavariable: $TRUST
|
|
regex: (bypassSecurityTrustHtml|bypassSecurityTrustStyle|bypassSecurityTrustScript|bypassSecurityTrustUrl|bypassSecurityTrustResourceUrl)
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("underscore.string")
|
|
...
|
|
- pattern-either:
|
|
- pattern: $S.escapeHTML(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import { ..., $S,... } from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("dompurify")
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("isomorphic-dompurify")
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S(...)
|
|
...
|
|
- pattern: $VALUE.sanitize(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S.sanitize
|
|
...
|
|
- pattern: $S(...)
|
|
- pattern: $S.sanitize(...)
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("xss")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'sanitize-html';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "sanitize-html";
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("sanitize-html")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern: sanitizer.sanitize(...)
|
|
- pattern-not: sanitizer.sanitize(SecurityContext.NONE, ...);
|
|
- id: typescript.react.security.react-insecure-request.react-insecure-request
|
|
message: Unencrypted request over HTTP detected.
|
|
metadata:
|
|
vulnerability: Insecure Transport
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
references:
|
|
- https://www.npmjs.com/package/axios
|
|
category: security
|
|
technology:
|
|
- react
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/typescript.react.security.react-insecure-request.react-insecure-request
|
|
shortlink: https://sg.run/1n0b
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9766
|
|
rv_id: 1263918
|
|
rule_id: NbUA3O
|
|
version_id: A8Tgd2p
|
|
url: https://semgrep.dev/playground/r/A8Tgd2p/typescript.react.security.react-insecure-request.react-insecure-request
|
|
origin: community
|
|
languages:
|
|
- typescript
|
|
- javascript
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $AXIOS from 'axios';
|
|
...
|
|
$AXIOS.$METHOD(...)
|
|
- pattern-inside: |
|
|
$AXIOS = require('axios');
|
|
...
|
|
$AXIOS.$METHOD(...)
|
|
- pattern: $AXIOS.$VERB("$URL",...)
|
|
- metavariable-regex:
|
|
metavariable: $VERB
|
|
regex: ^(get|post|delete|head|patch|put|options)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $AXIOS from 'axios';
|
|
...
|
|
$AXIOS(...)
|
|
- pattern-inside: |
|
|
$AXIOS = require('axios');
|
|
...
|
|
$AXIOS(...)
|
|
- pattern-either:
|
|
- pattern: '$AXIOS({url: "$URL"}, ...)'
|
|
- pattern: |
|
|
$OPTS = {url: "$URL"}
|
|
...
|
|
$AXIOS($OPTS, ...)
|
|
- pattern: fetch("$URL", ...)
|
|
- metavariable-regex:
|
|
metavariable: $URL
|
|
regex: ^([Hh][Tt][Tt][Pp]:\/\/(?!localhost).*)
|
|
- id: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml
|
|
message: Detection of dangerouslySetInnerHTML from non-constant definition. This
|
|
can inadvertently expose users to cross-site scripting (XSS) attacks if this comes
|
|
from user-provided input. If you have to use dangerouslySetInnerHTML, consider
|
|
using a sanitization library such as DOMPurify to sanitize your HTML.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html
|
|
category: security
|
|
confidence: MEDIUM
|
|
technology:
|
|
- react
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml
|
|
shortlink: https://sg.run/rAx6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9769
|
|
rv_id: 1263912
|
|
rule_id: x8UWvK
|
|
version_id: l4TJR0v
|
|
url: https://semgrep.dev/playground/r/l4TJR0v/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml
|
|
origin: community
|
|
languages:
|
|
- typescript
|
|
- javascript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
function ...({..., $X, ...}) { ... }
|
|
- pattern-inside: |
|
|
function ...(..., $X, ...) { ... }
|
|
- focus-metavariable: $X
|
|
- pattern-not-inside: |
|
|
$F. ... .$SANITIZEUNC(...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $X
|
|
- pattern-either:
|
|
- pattern: |
|
|
{...,dangerouslySetInnerHTML: {__html: $X},...}
|
|
- pattern: |
|
|
<$Y ... dangerouslySetInnerHTML={{__html: $X}} />
|
|
- pattern-not: |
|
|
<$Y ... dangerouslySetInnerHTML={{__html: "..."}} />
|
|
- pattern-not: |
|
|
{...,dangerouslySetInnerHTML:{__html: "..."},...}
|
|
- metavariable-pattern:
|
|
patterns:
|
|
- pattern-not: |
|
|
{...}
|
|
metavariable: $X
|
|
- pattern-not: |
|
|
<... {__html: "..."} ...>
|
|
- pattern-not: |
|
|
<... {__html: `...`} ...>
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("underscore.string")
|
|
...
|
|
- pattern-either:
|
|
- pattern: $S.escapeHTML(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import { ..., $S,... } from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("dompurify")
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("isomorphic-dompurify")
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S(...)
|
|
...
|
|
- pattern: $VALUE.sanitize(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S.sanitize
|
|
...
|
|
- pattern: $S(...)
|
|
- pattern: $S.sanitize(...)
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("xss")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'sanitize-html';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "sanitize-html";
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("sanitize-html")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$S = new Remarkable()
|
|
...
|
|
- pattern: $S.render(...)
|
|
- id: typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method
|
|
message: Detection of $HTML from non-constant definition. This can inadvertently
|
|
expose users to cross-site scripting (XSS) attacks if this comes from user-provided
|
|
input. If you have to use $HTML, consider using a sanitization library such as
|
|
DOMPurify to sanitize your HTML.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://developer.mozilla.org/en-US/docs/Web/API/Document/writeln
|
|
- https://developer.mozilla.org/en-US/docs/Web/API/Document/write
|
|
- https://developer.mozilla.org/en-US/docs/Web/API/Element/insertAdjacentHTML
|
|
category: security
|
|
confidence: MEDIUM
|
|
technology:
|
|
- react
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method
|
|
shortlink: https://sg.run/E5x8
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9781
|
|
rv_id: 1263916
|
|
rule_id: QrU68w
|
|
version_id: GxTkeRl
|
|
url: https://semgrep.dev/playground/r/GxTkeRl/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method
|
|
origin: community
|
|
languages:
|
|
- typescript
|
|
- javascript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
function ...({..., $X, ...}) { ... }
|
|
- pattern-inside: |
|
|
function ...(..., $X, ...) { ... }
|
|
- focus-metavariable: $X
|
|
- pattern-either:
|
|
- pattern: $X.$Y
|
|
- pattern: $X[...]
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: "this.window.document. ... .$HTML('...',$SINK) \n"
|
|
- pattern: "window.document. ... .$HTML('...',$SINK) \n"
|
|
- pattern: "document.$HTML($SINK) \n"
|
|
- metavariable-regex:
|
|
metavariable: $HTML
|
|
regex: (writeln|write)
|
|
- focus-metavariable: $SINK
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: "$PROP. ... .$HTML('...',$SINK) \n"
|
|
- metavariable-regex:
|
|
metavariable: $HTML
|
|
regex: (insertAdjacentHTML)
|
|
- focus-metavariable: $SINK
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("underscore.string")
|
|
...
|
|
- pattern-either:
|
|
- pattern: $S.escapeHTML(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import { ..., $S,... } from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("dompurify")
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("isomorphic-dompurify")
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S(...)
|
|
...
|
|
- pattern: $VALUE.sanitize(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S.sanitize
|
|
...
|
|
- pattern: $S(...)
|
|
- pattern: $S.sanitize(...)
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("xss")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'sanitize-html';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "sanitize-html";
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("sanitize-html")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$S = new Remarkable()
|
|
...
|
|
- pattern: $S.render(...)
|
|
- id: typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property
|
|
message: Detection of $HTML from non-constant definition. This can inadvertently
|
|
expose users to cross-site scripting (XSS) attacks if this comes from user-provided
|
|
input. If you have to use $HTML, consider using a sanitization library such as
|
|
DOMPurify to sanitize your HTML.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html
|
|
category: security
|
|
confidence: MEDIUM
|
|
technology:
|
|
- react
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property
|
|
shortlink: https://sg.run/70Zv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9782
|
|
rv_id: 1263917
|
|
rule_id: 3qUBl4
|
|
version_id: RGT0Lln
|
|
url: https://semgrep.dev/playground/r/RGT0Lln/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property
|
|
origin: community
|
|
languages:
|
|
- typescript
|
|
- javascript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
function ...({..., $X, ...}) { ... }
|
|
- pattern-inside: |
|
|
function ...(..., $X, ...) { ... }
|
|
- focus-metavariable: $X
|
|
- pattern-either:
|
|
- pattern: $X.$Y
|
|
- pattern: $X[...]
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$BODY = $REACT.useRef(...)
|
|
...
|
|
- pattern-inside: |
|
|
$BODY = useRef(...)
|
|
...
|
|
- pattern-inside: |
|
|
$BODY = findDOMNode(...)
|
|
...
|
|
- pattern-inside: |
|
|
$BODY = createRef(...)
|
|
...
|
|
- pattern-inside: |
|
|
$BODY = $REACT.findDOMNode(...)
|
|
...
|
|
- pattern-inside: |
|
|
$BODY = $REACT.createRef(...)
|
|
...
|
|
- pattern-either:
|
|
- pattern: "$BODY. ... .$HTML = $SINK \n"
|
|
- pattern: "$BODY.$HTML = $SINK \n"
|
|
- metavariable-regex:
|
|
metavariable: $HTML
|
|
regex: (innerHTML|outerHTML)
|
|
- focus-metavariable: $SINK
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: ReactDOM.findDOMNode(...).$HTML = $SINK
|
|
- metavariable-regex:
|
|
metavariable: $HTML
|
|
regex: (innerHTML|outerHTML)
|
|
- focus-metavariable: $SINK
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "underscore.string"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("underscore.string")
|
|
...
|
|
- pattern-either:
|
|
- pattern: $S.escapeHTML(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import { ..., $S,... } from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("dompurify")
|
|
...
|
|
- pattern-inside: |
|
|
import $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "isomorphic-dompurify"
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("isomorphic-dompurify")
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S(...)
|
|
...
|
|
- pattern: $VALUE.sanitize(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $S.sanitize
|
|
...
|
|
- pattern: $S(...)
|
|
- pattern: $S.sanitize(...)
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from 'xss';
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("xss")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import $S from 'sanitize-html';
|
|
...
|
|
- pattern-inside: |
|
|
import * as $S from "sanitize-html";
|
|
...
|
|
- pattern-inside: |
|
|
$S = require("sanitize-html")
|
|
...
|
|
- pattern: $S(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$S = new Remarkable()
|
|
...
|
|
- pattern: $S.render(...)
|
|
- id: ruby.lang.security.dangerous-exec.dangerous-exec
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: |
|
|
def $F(...,$ARG,...)
|
|
...
|
|
end
|
|
- focus-metavariable: $ARG
|
|
- pattern: params
|
|
- pattern: cookies
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
$EXEC(...)
|
|
- pattern-not: |
|
|
$EXEC("...","...","...",...)
|
|
- pattern-not: |
|
|
$EXEC(["...","...","...",...],...)
|
|
- pattern-not: |
|
|
$EXEC({...},"...","...","...",...)
|
|
- pattern-not: |
|
|
$EXEC({...},["...","...","...",...],...)
|
|
- metavariable-regex:
|
|
metavariable: $EXEC
|
|
regex: ^(system|exec|spawn|Process.exec|Process.spawn|Open3.capture2|Open3.capture2e|Open3.capture3|Open3.popen2|Open3.popen2e|Open3.popen3|IO.popen|Gem::Util.popen|PTY.spawn)$
|
|
message: Detected non-static command inside $EXEC. Audit the input to '$EXEC'. If
|
|
unverified user data can reach this call site, this is a code injection vulnerability.
|
|
A malicious actor can inject a malicious script to execute arbitrary code.
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_execute.rb
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://guides.rubyonrails.org/security.html#command-line-injection
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/ruby.lang.security.dangerous-exec.dangerous-exec
|
|
shortlink: https://sg.run/R8GY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9805
|
|
rv_id: 1409405
|
|
rule_id: WAUZOw
|
|
version_id: WrT7erb
|
|
url: https://semgrep.dev/playground/r/WrT7erb/ruby.lang.security.dangerous-exec.dangerous-exec
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- ruby
|
|
- id: javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run
|
|
message: Detected non-literal calls to Deno.run(). This could lead to a command
|
|
injection vulnerability.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- deno
|
|
references:
|
|
- https://deno.land/manual/examples/subprocess#simple-example
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run
|
|
shortlink: https://sg.run/Nrrn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 9927
|
|
rv_id: 1409397
|
|
rule_id: x8UWWg
|
|
version_id: PkTe7AP
|
|
url: https://semgrep.dev/playground/r/PkTe7AP/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: function ... (..., $ARG,...) {...}
|
|
- focus-metavariable: $ARG
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
Deno.run({cmd: [$INPUT,...]},...)
|
|
- pattern: |
|
|
Deno.run({cmd: ["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$INPUT,...]},...)
|
|
- patterns:
|
|
- pattern: |
|
|
Deno.run({cmd: [$CMD,"-c",$INPUT,...]},...)
|
|
- pattern-inside: |
|
|
$CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/"
|
|
...
|
|
- focus-metavariable: $INPUT
|
|
- id: yaml.docker-compose.security.privileged-service.privileged-service
|
|
patterns:
|
|
- pattern-inside: |
|
|
version: ...
|
|
...
|
|
services:
|
|
...
|
|
$SERVICE:
|
|
...
|
|
privileged: $TRUE
|
|
- focus-metavariable: $TRUE
|
|
- metavariable-regex:
|
|
metavariable: $TRUE
|
|
regex: (true)
|
|
fix: |
|
|
false
|
|
message: Service '$SERVICE' is running in privileged mode. This grants the container
|
|
the equivalent of root capabilities on the host machine. This can lead to container
|
|
escapes, privilege escalation, and other security concerns. Remove the 'privileged'
|
|
key to disable this capability.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-250: Execution with Unnecessary Privileges'
|
|
owasp:
|
|
- A06:2017 - Security Misconfiguration
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://www.trendmicro.com/en_us/research/19/l/why-running-a-privileged-container-in-docker-is-a-bad-idea.html
|
|
- https://containerjournal.com/topics/container-security/why-running-a-privileged-container-is-not-a-good-idea/
|
|
category: security
|
|
technology:
|
|
- docker-compose
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.docker-compose.security.privileged-service.privileged-service
|
|
shortlink: https://sg.run/AlX0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 10006
|
|
rv_id: 1263922
|
|
rule_id: DbUW17
|
|
version_id: 0bTKzXZ
|
|
url: https://semgrep.dev/playground/r/0bTKzXZ/yaml.docker-compose.security.privileged-service.privileged-service
|
|
origin: community
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
- id: yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation
|
|
patterns:
|
|
- pattern-inside: |
|
|
containers:
|
|
...
|
|
- pattern-inside: |
|
|
- name: $CONTAINER
|
|
...
|
|
- pattern: |
|
|
image: ...
|
|
...
|
|
- pattern-inside: |
|
|
image: ...
|
|
...
|
|
$SC:
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $SC
|
|
regex: ^(securityContext)$
|
|
- pattern-not-inside: |
|
|
image: ...
|
|
...
|
|
securityContext:
|
|
...
|
|
allowPrivilegeEscalation: $VAL
|
|
- focus-metavariable: $SC
|
|
fix: |
|
|
securityContext:
|
|
allowPrivilegeEscalation: false #
|
|
message: In Kubernetes, each pod runs in its own isolated environment with its own
|
|
set of security policies. However, certain container images may contain `setuid`
|
|
or `setgid` binaries that could allow an attacker to perform privilege escalation
|
|
and gain access to sensitive resources. To mitigate this risk, it's recommended
|
|
to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation`
|
|
set to `false`. This will prevent the container from running any privileged processes
|
|
and limit the impact of any potential attacks. By adding the `allowPrivilegeEscalation`
|
|
parameter to your the `securityContext`, you can help to ensure that your containerized
|
|
applications are more secure and less vulnerable to privilege escalation attacks.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A06:2017 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation
|
|
- https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
|
|
- https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag
|
|
category: security
|
|
technology:
|
|
- kubernetes
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation
|
|
shortlink: https://sg.run/ljp6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 10057
|
|
rv_id: 1263933
|
|
rule_id: 6JUqEO
|
|
version_id: jQTn527
|
|
url: https://semgrep.dev/playground/r/jQTn527/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation
|
|
origin: community
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
- id: yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled
|
|
patterns:
|
|
- pattern-inside: |
|
|
containers:
|
|
...
|
|
- pattern: |
|
|
image: ...
|
|
...
|
|
securityContext:
|
|
...
|
|
seccompProfile: unconfined
|
|
message: 'Container is explicitly disabling seccomp confinement. This runs the service
|
|
in an unrestricted state. Remove ''seccompProfile: unconfined'' to prevent this.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-284: Improper Access Control'
|
|
references:
|
|
- https://kubernetes.io/docs/concepts/policy/pod-security-policy/#seccomp
|
|
- https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
|
|
category: security
|
|
technology:
|
|
- kubernetes
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled
|
|
shortlink: https://sg.run/6rgY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 10059
|
|
rv_id: 1263941
|
|
rule_id: zdUynw
|
|
version_id: w8TRoL3
|
|
url: https://semgrep.dev/playground/r/w8TRoL3/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled
|
|
origin: community
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
- id: yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster
|
|
pattern: |
|
|
cluster:
|
|
...
|
|
insecure-skip-tls-verify: true
|
|
message: 'Cluster is disabling TLS certificate verification when communicating with
|
|
the server. This makes your HTTPS connections insecure. Remove the ''insecure-skip-tls-verify:
|
|
true'' key to secure communication.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
references:
|
|
- https://kubernetes.io/docs/reference/config-api/client-authentication.v1beta1/#client-authentication-k8s-io-v1beta1-Cluster
|
|
category: security
|
|
technology:
|
|
- kubernetes
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster
|
|
shortlink: https://sg.run/okyn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 10116
|
|
rv_id: 1263943
|
|
rule_id: zdUyWx
|
|
version_id: O9Tpxbo
|
|
url: https://semgrep.dev/playground/r/O9Tpxbo/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster
|
|
origin: community
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
- id: yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service
|
|
pattern: |
|
|
spec:
|
|
...
|
|
insecureSkipTLSVerify: true
|
|
message: 'Service is disabling TLS certificate verification when communicating with
|
|
the server. This makes your HTTPS connections insecure. Remove the ''insecureSkipTLSVerify:
|
|
true'' key to secure communication.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
references:
|
|
- https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#apiservice-v1-apiregistration-k8s-io
|
|
category: security
|
|
technology:
|
|
- kubernetes
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service
|
|
shortlink: https://sg.run/zk10
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 10117
|
|
rv_id: 1263944
|
|
rule_id: pKUGXr
|
|
version_id: e1TyjnR
|
|
url: https://semgrep.dev/playground/r/e1TyjnR/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service
|
|
origin: community
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
- id: ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli
|
|
mode: taint
|
|
pattern-propagators:
|
|
- pattern: $X << $Y
|
|
from: $Y
|
|
to: $X
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- pattern: |
|
|
params
|
|
- pattern: |
|
|
cookies
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$CON = PG.connect(...)
|
|
...
|
|
- pattern-inside: |
|
|
$CON = PG::Connection.open(...)
|
|
...
|
|
- pattern-inside: |
|
|
$CON = PG::Connection.new(...)
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
$CON.$METHOD($X,...)
|
|
- pattern: |
|
|
$CON.$METHOD $X, ...
|
|
- focus-metavariable: $X
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(exec|exec_params)$
|
|
languages:
|
|
- ruby
|
|
message: 'Detected string concatenation with a non-literal variable in a pg Ruby
|
|
SQL statement. This could lead to SQL injection if the variable is user-controlled
|
|
and not properly sanitized. In order to prevent SQL injection, use parameterized
|
|
queries or prepared statements instead. You can use parameterized queries like
|
|
so: `conn.exec_params(''SELECT $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])` And
|
|
you can use prepared statements with `exec_prepared`.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://www.rubydoc.info/gems/pg/PG/Connection
|
|
category: security
|
|
technology:
|
|
- rails
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli
|
|
shortlink: https://sg.run/kL0o
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 10328
|
|
rv_id: 1263628
|
|
rule_id: NbUAz7
|
|
version_id: 2KTv2y2
|
|
url: https://semgrep.dev/playground/r/2KTv2y2/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli
|
|
origin: community
|
|
severity: WARNING
|
|
- id: java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled
|
|
pattern: management.endpoints.web.exposure.include=*
|
|
message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints
|
|
such as /actuator/env, /actuator/logfile, /actuator/heapdump and others. Unless
|
|
you have Spring Security enabled or another means to protect these endpoints,
|
|
this functionality is available without authentication, causing a significant
|
|
security risk.
|
|
severity: ERROR
|
|
languages:
|
|
- generic
|
|
paths:
|
|
include:
|
|
- '*properties'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints
|
|
- https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785
|
|
- https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators
|
|
category: security
|
|
technology:
|
|
- spring
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled
|
|
shortlink: https://sg.run/L0vY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 10439
|
|
rv_id: 1263077
|
|
rule_id: EwU4vg
|
|
version_id: xyTjzwp
|
|
url: https://semgrep.dev/playground/r/xyTjzwp/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled
|
|
origin: community
|
|
- id: generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
proxy_http_version 1.1 ...;
|
|
...
|
|
proxy_set_header Upgrade ...;
|
|
...
|
|
proxy_set_header Connection ...;
|
|
- pattern: |
|
|
proxy_set_header Upgrade ...;
|
|
...
|
|
proxy_set_header Connection ...;
|
|
...
|
|
proxy_http_version 1.1 ...;
|
|
- pattern: |
|
|
proxy_set_header Upgrade ...;
|
|
...
|
|
proxy_http_version 1.1 ...;
|
|
...
|
|
proxy_set_header Connection ...;
|
|
- pattern-inside: |
|
|
location ... {
|
|
...
|
|
}
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
message: 'Conditions for Nginx H2C smuggling identified. H2C smuggling allows upgrading
|
|
HTTP/1.1 connections to lesser-known HTTP/2 over cleartext (h2c) connections which
|
|
can allow a bypass of reverse proxy access controls, and lead to long-lived, unrestricted
|
|
HTTP traffic directly to back-end servers. To mitigate: WebSocket support required:
|
|
Allow only the value websocket for HTTP/1.1 upgrade headers (e.g., Upgrade: websocket).
|
|
WebSocket support not required: Do not forward Upgrade headers.'
|
|
paths:
|
|
include:
|
|
- '*.conf'
|
|
- '*.vhost'
|
|
- '**/sites-available/*'
|
|
- '**/sites-enabled/*'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response
|
|
Smuggling'')'
|
|
references:
|
|
- https://labs.bishopfox.com/tech-blog/h2c-smuggling-request-smuggling-via-http/2-cleartext-h2c
|
|
category: security
|
|
technology:
|
|
- nginx
|
|
confidence: MEDIUM
|
|
owasp:
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling
|
|
shortlink: https://sg.run/ploZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 10562
|
|
rv_id: 1262679
|
|
rule_id: 6JUq0Z
|
|
version_id: nWT2Lyp
|
|
url: https://semgrep.dev/playground/r/nWT2Lyp/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling
|
|
origin: community
|
|
- id: csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization
|
|
severity: WARNING
|
|
languages:
|
|
- C#
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
references:
|
|
- https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide
|
|
category: security
|
|
technology:
|
|
- .net
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization
|
|
shortlink: https://sg.run/ZeXW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 11135
|
|
rv_id: 1262635
|
|
rule_id: bwUOjK
|
|
version_id: nWT2LGp
|
|
url: https://semgrep.dev/playground/r/nWT2LGp/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization
|
|
origin: community
|
|
message: The BinaryFormatter type is dangerous and is not recommended for data processing.
|
|
Applications should stop using BinaryFormatter as soon as possible, even if they
|
|
believe the data they're processing to be trustworthy. BinaryFormatter is insecure
|
|
and can't be made secure
|
|
patterns:
|
|
- pattern-inside: |
|
|
using System.Runtime.Serialization.Formatters.Binary;
|
|
...
|
|
- pattern: |
|
|
new BinaryFormatter();
|
|
- id: csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization
|
|
severity: WARNING
|
|
languages:
|
|
- C#
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
references:
|
|
- https://mbraceproject.github.io/FsPickler/tutorial.html#Disabling-Subtype-Resolution
|
|
category: security
|
|
technology:
|
|
- .net
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization
|
|
shortlink: https://sg.run/E5e5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 11137
|
|
rv_id: 1262638
|
|
rule_id: kxURnR
|
|
version_id: LjTkgPk
|
|
url: https://semgrep.dev/playground/r/LjTkgPk/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization
|
|
origin: community
|
|
message: The FsPickler is dangerous and is not recommended for data processing.
|
|
Default configuration tend to insecure deserialization vulnerability.
|
|
patterns:
|
|
- pattern-inside: |
|
|
using MBrace.FsPickler.Json;
|
|
...
|
|
- pattern: |
|
|
FsPickler.CreateJsonSerializer();
|
|
- id: csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization
|
|
severity: WARNING
|
|
languages:
|
|
- C#
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
references:
|
|
- https://docs.microsoft.com/en-us/dotnet/api/system.web.ui.losformatter?view=netframework-4.8
|
|
category: security
|
|
technology:
|
|
- .net
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization
|
|
shortlink: https://sg.run/70pG
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 11138
|
|
rv_id: 1262641
|
|
rule_id: wdU87G
|
|
version_id: QkTGqnA
|
|
url: https://semgrep.dev/playground/r/QkTGqnA/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization
|
|
origin: community
|
|
message: The LosFormatter type is dangerous and is not recommended for data processing.
|
|
Applications should stop using LosFormatter as soon as possible, even if they
|
|
believe the data they're processing to be trustworthy. LosFormatter is insecure
|
|
and can't be made secure
|
|
patterns:
|
|
- pattern-inside: |
|
|
using System.Web.UI;
|
|
...
|
|
- pattern: |
|
|
new LosFormatter();
|
|
- id: csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization
|
|
severity: WARNING
|
|
languages:
|
|
- C#
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
references:
|
|
- https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.netdatacontractserializer?view=netframework-4.8#security
|
|
category: security
|
|
technology:
|
|
- .net
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization
|
|
shortlink: https://sg.run/L0AX
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 11139
|
|
rv_id: 1262642
|
|
rule_id: x8UW7x
|
|
version_id: 3ZT4X6b
|
|
url: https://semgrep.dev/playground/r/3ZT4X6b/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization
|
|
origin: community
|
|
message: The NetDataContractSerializer type is dangerous and is not recommended
|
|
for data processing. Applications should stop using NetDataContractSerializer
|
|
as soon as possible, even if they believe the data they're processing to be trustworthy.
|
|
NetDataContractSerializer is insecure and can't be made secure
|
|
patterns:
|
|
- pattern-inside: |
|
|
using System.Runtime.Serialization;
|
|
...
|
|
- pattern: |
|
|
new NetDataContractSerializer();
|
|
- id: csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization
|
|
severity: WARNING
|
|
languages:
|
|
- C#
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
references:
|
|
- https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.formatters.soap.soapformatter?view=netframework-4.8#remarks
|
|
category: security
|
|
technology:
|
|
- .net
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization
|
|
shortlink: https://sg.run/gJnR
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 11141
|
|
rv_id: 1262644
|
|
rule_id: eqUvND
|
|
version_id: PkTR30n
|
|
url: https://semgrep.dev/playground/r/PkTR30n/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization
|
|
origin: community
|
|
message: The SoapFormatter type is dangerous and is not recommended for data processing.
|
|
Applications should stop using SoapFormatter as soon as possible, even if they
|
|
believe the data they're processing to be trustworthy. SoapFormatter is insecure
|
|
and can't be made secure
|
|
patterns:
|
|
- pattern-inside: |
|
|
using System.Runtime.Serialization.Formatters.Soap;
|
|
...
|
|
- pattern: |
|
|
new SoapFormatter();
|
|
- id: terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional
|
|
languages:
|
|
- hcl
|
|
message: AWS EC2 Instance allowing use of the IMDSv1
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
references:
|
|
- https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/instance#metadata-options
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional
|
|
shortlink: https://sg.run/J3BQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 11302
|
|
rv_id: 1263884
|
|
rule_id: GdU0eA
|
|
version_id: w8TRooE
|
|
url: https://semgrep.dev/playground/r/w8TRooE/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional
|
|
origin: community
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: http_tokens = "optional"
|
|
- pattern-inside: |
|
|
metadata_options { ... }
|
|
- patterns:
|
|
- pattern: |
|
|
resource "aws_instance" "$NAME" {
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
resource "aws_instance" "$NAME" {
|
|
...
|
|
metadata_options {
|
|
...
|
|
http_tokens = "required"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
resource "aws_instance" "$NAME" {
|
|
...
|
|
metadata_options {
|
|
...
|
|
http_tokens = "optional"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
resource "aws_instance" "$NAME" {
|
|
...
|
|
metadata_options {
|
|
...
|
|
http_endpoint = "disabled"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
severity: ERROR
|
|
- id: java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::randomness::javax.crypto
|
|
cwe:
|
|
- 'CWE-323: Reusing a Nonce, Key Pair in Encryption'
|
|
category: security
|
|
source-rule-url: https://www.youtube.com/watch?v=r1awgAl90wM
|
|
technology:
|
|
- java
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse
|
|
shortlink: https://sg.run/Dww2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 11908
|
|
rv_id: 1263000
|
|
rule_id: GdUZZ3
|
|
version_id: 0bTKzGk
|
|
url: https://semgrep.dev/playground/r/0bTKzGk/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse
|
|
origin: community
|
|
languages:
|
|
- java
|
|
message: 'GCM IV/nonce is reused: encryption can be totally useless'
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: new GCMParameterSpec(..., "...".getBytes(...), ...);
|
|
- pattern: byte[] $NONCE = "...".getBytes(...); ... new GCMParameterSpec(...,
|
|
$NONCE, ...);
|
|
severity: ERROR
|
|
- id: csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos
|
|
severity: WARNING
|
|
languages:
|
|
- C#
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1333: Inefficient Regular Expression Complexity'
|
|
owasp: A01:2017 - Injection
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS
|
|
- https://docs.microsoft.com/en-us/dotnet/standard/base-types/regular-expressions#regular-expression-examples
|
|
category: security
|
|
technology:
|
|
- .net
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Denial-of-Service (DoS)
|
|
source: https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos
|
|
shortlink: https://sg.run/RPyY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 12005
|
|
rv_id: 945225
|
|
rule_id: 4bU2gd
|
|
version_id: rxT6rjl
|
|
url: https://semgrep.dev/playground/r/rxT6rjl/csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos
|
|
origin: community
|
|
message: When using `System.Text.RegularExpressions` to process untrusted input,
|
|
pass a timeout. A malicious user can provide input to `RegularExpressions` that
|
|
abuses the backtracking behaviour of this regular expression engine. This will
|
|
lead to excessive CPU usage, causing a Denial-of-Service attack
|
|
patterns:
|
|
- pattern-inside: |
|
|
using System.Text.RegularExpressions;
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
public $T $F($X)
|
|
{
|
|
Regex $Y = new Regex($P);
|
|
...
|
|
$Y.Match($X);
|
|
}
|
|
- pattern: |
|
|
public $T $F($X)
|
|
{
|
|
Regex $Y = new Regex($P, $O);
|
|
...
|
|
$Y.Match($X);
|
|
}
|
|
- pattern: |
|
|
public $T $F($X)
|
|
{
|
|
... Regex.Match($X, $P);
|
|
}
|
|
- pattern: |
|
|
public $T $F($X)
|
|
{
|
|
... Regex.Match($X, $P, $O);
|
|
}
|
|
- id: javascript.express.security.express-vm-injection.express-vm-injection
|
|
message: Make sure that unverified user data can not reach `$VM`.
|
|
metadata:
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/javascript.express.security.express-vm-injection.express-vm-injection
|
|
shortlink: https://sg.run/jkqJ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 12821
|
|
rv_id: 1263170
|
|
rule_id: DbUKPX
|
|
version_id: 1QTypXQ
|
|
url: https://semgrep.dev/playground/r/1QTypXQ/javascript.express.security.express-vm-injection.express-vm-injection
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VM = require('vm');
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
$VM.runInContext(...)
|
|
- pattern: |
|
|
$VM.runInNewContext(...)
|
|
- pattern: |
|
|
$VM.compileFunction(...)
|
|
- pattern: |
|
|
$VM.runInThisContext(...)
|
|
- pattern: new $VM.Script(...)
|
|
- id: javascript.express.security.express-vm2-injection.express-vm2-injection
|
|
message: Make sure that unverified user data can not reach `vm2`.
|
|
metadata:
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/javascript.express.security.express-vm2-injection.express-vm2-injection
|
|
shortlink: https://sg.run/1GWv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 12822
|
|
rv_id: 1263171
|
|
rule_id: WAUPXJ
|
|
version_id: 9lT4bnX
|
|
url: https://semgrep.dev/playground/r/9lT4bnX/javascript.express.security.express-vm2-injection.express-vm2-injection
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
require('vm2')
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$VM = new VM(...)
|
|
...
|
|
- pattern-inside: |
|
|
$VM = new NodeVM(...)
|
|
...
|
|
- pattern: |
|
|
$VM.run(...)
|
|
- pattern: |
|
|
new VM(...).run(...)
|
|
- pattern: |
|
|
new NodeVM(...).run(...)
|
|
- pattern: |
|
|
new VMScript(...)
|
|
- pattern: |
|
|
new VM(...)
|
|
- pattern: new NodeVM(...)
|
|
- id: javascript.lang.security.audit.code-string-concat.code-string-concat
|
|
message: Found data from an Express or Next web request flowing to `eval`. If this
|
|
data is user-controllable this can lead to execution of arbitrary system commands
|
|
in the context of your application process. Avoid `eval` whenever possible.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
confidence: HIGH
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
references:
|
|
- https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval
|
|
- https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback
|
|
- https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/
|
|
- https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html
|
|
category: security
|
|
technology:
|
|
- node.js
|
|
- Express
|
|
- Next.js
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat
|
|
shortlink: https://sg.run/96Yk
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13023
|
|
rv_id: 1263192
|
|
rule_id: DbUKEz
|
|
version_id: 44TEjYX
|
|
url: https://semgrep.dev/playground/r/44TEjYX/javascript.lang.security.audit.code-string-concat.code-string-concat
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT)
|
|
{...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import { ...,$IMPORT,... } from 'next/router'
|
|
...
|
|
- pattern-inside: |
|
|
import $IMPORT from 'next/router';
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ROUTER = $IMPORT()
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
const { ...,$PROPS,... } = $ROUTER.query
|
|
...
|
|
- pattern-inside: |
|
|
var { ...,$PROPS,... } = $ROUTER.query
|
|
...
|
|
- pattern-inside: |
|
|
let { ...,$PROPS,... } = $ROUTER.query
|
|
...
|
|
- focus-metavariable: $PROPS
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ROUTER = $IMPORT()
|
|
...
|
|
- pattern: "$ROUTER.query.$VALUE \n"
|
|
- patterns:
|
|
- pattern: $IMPORT().query.$VALUE
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
eval(...)
|
|
- id: yaml.github-actions.security.run-shell-injection.run-shell-injection
|
|
languages:
|
|
- yaml
|
|
message: 'Using variable interpolation `${{...}}` with `github` context data in
|
|
a `run:` step could allow an attacker to inject their own code into the runner.
|
|
This would allow them to steal secrets and code. `github` context data can have
|
|
arbitrary user input and should be treated as untrusted. Instead, use an intermediate
|
|
environment variable with `env:` to store the data and use the environment variable
|
|
in the `run:` script. Be sure to use double-quotes the environment variable, like
|
|
this: "$ENVVAR".'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections
|
|
- https://securitylab.github.com/research/github-actions-untrusted-input/
|
|
technology:
|
|
- github-actions
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.run-shell-injection.run-shell-injection
|
|
shortlink: https://sg.run/pkzk
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13162
|
|
rv_id: 1423395
|
|
rule_id: v8UjQj
|
|
version_id: GxTl1DQ
|
|
url: https://semgrep.dev/playground/r/GxTl1DQ/yaml.github-actions.security.run-shell-injection.run-shell-injection
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: 'steps: [...]'
|
|
- pattern-inside: |
|
|
- run: ...
|
|
...
|
|
- pattern: 'run: $SHELL'
|
|
- metavariable-pattern:
|
|
language: generic
|
|
metavariable: $SHELL
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: ${{ ... github.event.issue.title ... }}
|
|
- pattern: ${{ ... github.event.issue.body ... }}
|
|
- pattern: ${{ ... github.event.pull_request.title ... }}
|
|
- pattern: ${{ ... github.event.pull_request.body ... }}
|
|
- pattern: ${{ ... github.event.comment.body ... }}
|
|
- pattern: ${{ ... github.event.review.body ... }}
|
|
- pattern: ${{ ... github.event.review_comment.body ... }}
|
|
- pattern: ${{ ... github.event.pages ... .page_name ... }}
|
|
- pattern: ${{ ... github.event.head_commit.message ... }}
|
|
- pattern: ${{ ... github.event.head_commit.author.email ... }}
|
|
- pattern: ${{ ... github.event.head_commit.author.name ... }}
|
|
- pattern: ${{ ... github.event.commits ... .author.email ... }}
|
|
- pattern: ${{ ... github.event.commits ... .author.name ... }}
|
|
- pattern: ${{ ... github.event.commits ... .message ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.ref ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.label ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.repo.default_branch ...
|
|
}}
|
|
- pattern: ${{ ... github.ref ... }}
|
|
- pattern: ${{ ... github.base_ref ... }}
|
|
- pattern: ${{ ... github.head_ref ... }}
|
|
- pattern: ${{ ... github.ref_name ... }}
|
|
- pattern: ${{ ... github.workflow ... }}
|
|
- pattern: ${{ ... github.event.inputs ... }}
|
|
- pattern: ${{ ... github.event.discussion.title ... }}
|
|
- pattern: ${{ ... github.event.discussion.body ... }}
|
|
- pattern: ${{ ... github.event.workflow_run.head_branch ... }}
|
|
- pattern: ${{ ... github.event.workflow_run.head_commit.message ... }}
|
|
- pattern: ${{ ... github.event.milestone.title ... }}
|
|
- pattern: ${{ ... github.event.milestone.description ... }}
|
|
- pattern: ${{ ... github.event.project_card.note ... }}
|
|
- pattern: ${{ ... github.event.project.name ... }}
|
|
- pattern: ${{ ... github.event.project_column.name ... }}
|
|
- pattern: ${{ ... github.event.release.name ... }}
|
|
- pattern: ${{ ... github.event.release.body ... }}
|
|
- pattern: ${{ ... github.event.deployment.ref ... }}
|
|
- pattern: ${{ ... inputs ... }}
|
|
- pattern-not: ${{ ... github.event.issue.title && ... }}
|
|
- pattern-not: ${{ ... github.event.issue.body && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.title && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.body && ... }}
|
|
- pattern-not: ${{ ... github.event.comment.body && ... }}
|
|
- pattern-not: ${{ ... github.event.review.body && ... }}
|
|
- pattern-not: ${{ ... github.event.review_comment.body && ... }}
|
|
- pattern-not: ${{ ... github.event.pages ... .page_name && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.message && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.author.email && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.author.name && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .author.email && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .author.name && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .message && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.ref && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.label && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch &&
|
|
... }}
|
|
- pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ...
|
|
}}
|
|
- pattern-not: ${{ ... github.ref && ... }}
|
|
- pattern-not: ${{ ... github.base_ref && ... }}
|
|
- pattern-not: ${{ ... github.head_ref && ... }}
|
|
- pattern-not: ${{ ... github.ref_name && ... }}
|
|
- pattern-not: ${{ ... github.workflow && ... }}
|
|
- pattern-not: ${{ ... github.event.inputs && ... }}
|
|
- pattern-not: ${{ ... github.event.discussion.title && ... }}
|
|
- pattern-not: ${{ ... github.event.discussion.body && ... }}
|
|
- pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }}
|
|
- pattern-not: ${{ ... github.event.milestone.title && ... }}
|
|
- pattern-not: ${{ ... github.event.milestone.description && ... }}
|
|
- pattern-not: ${{ ... github.event.project_card.note && ... }}
|
|
- pattern-not: ${{ ... github.event.project.name && ... }}
|
|
- pattern-not: ${{ ... github.event.project_column.name && ... }}
|
|
- pattern-not: ${{ ... github.event.release.name && ... }}
|
|
- pattern-not: ${{ ... github.event.release.body && ... }}
|
|
- pattern-not: ${{ ... github.event.deployment.ref && ... }}
|
|
severity: ERROR
|
|
- id: yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout
|
|
languages:
|
|
- yaml
|
|
message: This GitHub Actions workflow file uses `pull_request_target` and checks
|
|
out code from the incoming pull request. When using `pull_request_target`, the
|
|
Action runs in the context of the target repository, which includes access to
|
|
all repository secrets. Normally, this is safe because the Action only runs code
|
|
from the target repository, not the incoming PR. However, by checking out the
|
|
incoming PR code, you're now using the incoming code for the rest of the action.
|
|
You may be inadvertently executing arbitrary code from the incoming PR with access
|
|
to repository secrets, which would let an attacker steal repository secrets. This
|
|
normally happens by running build scripts (e.g., `npm build` and `make`) or dependency
|
|
installation scripts (e.g., `python setup.py install`). Audit your workflow file
|
|
to make sure no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
|
|
for additional mitigations.
|
|
metadata:
|
|
category: security
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software and Data Integrity Failures
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
references:
|
|
- https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
|
|
- https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target
|
|
- https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md
|
|
technology:
|
|
- github-actions
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout
|
|
shortlink: https://sg.run/jkdn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13365
|
|
rv_id: 1413423
|
|
rule_id: d8Ulkd
|
|
version_id: O9TQ2nX
|
|
url: https://semgrep.dev/playground/r/O9TQ2nX/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
on:
|
|
...
|
|
pull_request_target: ...
|
|
...
|
|
...
|
|
- pattern-inside: |
|
|
on: [..., pull_request_target, ...]
|
|
...
|
|
- pattern-inside: |
|
|
on: pull_request_target
|
|
...
|
|
- pattern-inside: |
|
|
jobs:
|
|
...
|
|
$JOBNAME:
|
|
...
|
|
steps:
|
|
...
|
|
- pattern: |
|
|
...
|
|
uses: "$ACTION"
|
|
with:
|
|
...
|
|
ref: $EXPR
|
|
- metavariable-regex:
|
|
metavariable: $ACTION
|
|
regex: actions/checkout@.*
|
|
- metavariable-pattern:
|
|
language: generic
|
|
metavariable: $EXPR
|
|
patterns:
|
|
- pattern-inside: ${{ ... }}
|
|
- pattern-either:
|
|
- pattern: github.event.pull_request ...
|
|
- pattern: github.head_ref ...
|
|
severity: ERROR
|
|
- id: yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
message: The environment variable `ACTIONS_ALLOW_UNSECURE_COMMANDS` grants this
|
|
workflow permissions to use the `set-env` and `add-path` commands. There is a
|
|
vulnerability in these commands that could result in environment variables being
|
|
modified by an attacker. Depending on the use of the environment variable, this
|
|
could enable an attacker to, at worst, modify the system path to run a different
|
|
command than intended, resulting in arbitrary code execution. This could result
|
|
in stolen code or secrets. Don't use `ACTIONS_ALLOW_UNSECURE_COMMANDS`. Instead,
|
|
use Environment Files. See https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files
|
|
for more information.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-749: Exposed Dangerous Method or Function'
|
|
owasp: A06:2017 - Security Misconfiguration
|
|
references:
|
|
- https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/
|
|
- https://github.com/actions/toolkit/security/advisories/GHSA-mfwh-5m23-j46w
|
|
- https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files
|
|
category: security
|
|
technology:
|
|
- github-actions
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Dangerous Method or Function
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands
|
|
shortlink: https://sg.run/qq78
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13412
|
|
rv_id: 947039
|
|
rule_id: EwUQ9x
|
|
version_id: jQTzq34
|
|
url: https://semgrep.dev/playground/r/jQTzq34/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: '{env: ...}'
|
|
- pattern: 'ACTIONS_ALLOW_UNSECURE_COMMANDS: true'
|
|
- id: json.aws.security.public-s3-bucket.public-s3-bucket
|
|
languages:
|
|
- json
|
|
message: Detected public S3 bucket. This policy allows anyone to have some kind
|
|
of access to the bucket. The exact level of access and types of actions allowed
|
|
will depend on the configuration of bucket policy and ACLs. Please review the
|
|
bucket configuration to make sure they are set with intended values.
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html
|
|
technology:
|
|
- aws
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/json.aws.security.public-s3-bucket.public-s3-bucket
|
|
shortlink: https://sg.run/lxv5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13413
|
|
rv_id: 1263254
|
|
rule_id: 7KUpLy
|
|
version_id: RGT0Ld0
|
|
url: https://semgrep.dev/playground/r/RGT0Ld0/json.aws.security.public-s3-bucket.public-s3-bucket
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
$BUCKETNAME: {
|
|
"Type": "AWS::S3::Bucket",
|
|
"Properties": {
|
|
...,
|
|
},
|
|
...,
|
|
}
|
|
- pattern-either:
|
|
- pattern: |
|
|
"PublicAccessBlockConfiguration": {
|
|
...,
|
|
"RestrictPublicBuckets": false,
|
|
...,
|
|
},
|
|
- pattern: |
|
|
"PublicAccessBlockConfiguration": {
|
|
...,
|
|
"IgnorePublicAcls": false,
|
|
...,
|
|
},
|
|
- pattern: |
|
|
"PublicAccessBlockConfiguration": {
|
|
...,
|
|
"BlockPublicAcls": false,
|
|
...,
|
|
},
|
|
- pattern: |
|
|
"PublicAccessBlockConfiguration": {
|
|
...,
|
|
"BlockPublicPolicy": false,
|
|
...,
|
|
},
|
|
severity: WARNING
|
|
- id: javascript.express.security.cors-misconfiguration.cors-misconfiguration
|
|
message: By letting user input control CORS parameters, there is a risk that software
|
|
does not properly verify that the source of data or communication is valid. Use
|
|
literal values for CORS settings.
|
|
metadata:
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe:
|
|
- 'CWE-346: Origin Validation Error'
|
|
category: security
|
|
references:
|
|
- https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS
|
|
technology:
|
|
- express
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/javascript.express.security.cors-misconfiguration.cors-misconfiguration
|
|
shortlink: https://sg.run/nKXO
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13580
|
|
rv_id: 1263162
|
|
rule_id: 5rULJQ
|
|
version_id: YDTZe8Y
|
|
url: https://semgrep.dev/playground/r/YDTZe8Y/javascript.express.security.cors-misconfiguration.cors-misconfiguration
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $RES.set($HEADER, $X)
|
|
- pattern: $RES.header($HEADER, $X)
|
|
- pattern: $RES.setHeader($HEADER, $X)
|
|
- pattern: |
|
|
$RES.set({$HEADER: $X}, ...)
|
|
- pattern: |
|
|
$RES.writeHead($STATUS, {$HEADER: $X}, ...)
|
|
- focus-metavariable: $X
|
|
- metavariable-regex:
|
|
metavariable: $HEADER
|
|
regex: .*(Access-Control-Allow-Origin|access-control-allow-origin).*
|
|
- id: javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration
|
|
message: By letting user input control `X-Frame-Options` header, there is a risk
|
|
that software does not properly verify whether or not a browser should be allowed
|
|
to render a page in an `iframe`.
|
|
metadata:
|
|
references:
|
|
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options
|
|
owasp:
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
cwe:
|
|
- 'CWE-451: User Interface (UI) Misrepresentation of Critical Information'
|
|
category: security
|
|
technology:
|
|
- express
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration
|
|
shortlink: https://sg.run/EvjA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13581
|
|
rv_id: 1263178
|
|
rule_id: GdUrLy
|
|
version_id: xyTjz3D
|
|
url: https://semgrep.dev/playground/r/xyTjz3D/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $RES.set($HEADER, ...)
|
|
- pattern: $RES.header($HEADER, ...)
|
|
- pattern: $RES.setHeader($HEADER, ...)
|
|
- pattern: |
|
|
$RES.set({$HEADER: ...}, ...)
|
|
- pattern: |
|
|
$RES.writeHead($STATUS, {$HEADER: ...}, ...)
|
|
- metavariable-regex:
|
|
metavariable: $HEADER
|
|
regex: .*(X-Frame-Options|x-frame-options).*
|
|
- id: ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation
|
|
metadata:
|
|
shortDescription: Allowing an attacker to manipulate the session may lead to unintended
|
|
behavior.
|
|
tags:
|
|
- security
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-276: Incorrect Default Permissions'
|
|
references:
|
|
- https://brakemanscanner.org/docs/warning_types/session_manipulation/
|
|
category: security
|
|
technology:
|
|
- rails
|
|
help: |
|
|
## Remediation
|
|
Session manipulation can occur when an application allows user-input in session keys. Since sessions are typically considered a source of truth (e.g. to check the logged-in user or to match CSRF tokens), allowing an attacker to manipulate the session may lead to unintended behavior.
|
|
|
|
## References
|
|
[Session Manipulation](https://brakemanscanner.org/docs/warning_types/session_manipulation/)
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation
|
|
shortlink: https://sg.run/86q7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13584
|
|
rv_id: 1263621
|
|
rule_id: BYUdW6
|
|
version_id: qkTR76G
|
|
url: https://semgrep.dev/playground/r/qkTR76G/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation
|
|
origin: community
|
|
message: This gets data from session using user inputs. A malicious user may be
|
|
able to retrieve information from your session that you didn't intend them to.
|
|
Do not use user input as a session key.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: params
|
|
- pattern: cookies
|
|
- pattern: request.env
|
|
pattern-sinks:
|
|
- pattern: session[...]
|
|
- id: ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access
|
|
metadata:
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
references:
|
|
- https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown
|
|
category: security
|
|
technology:
|
|
- rails
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access
|
|
shortlink: https://sg.run/gYln
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13585
|
|
rv_id: 1263622
|
|
rule_id: DbU1dr
|
|
version_id: l4TJRkk
|
|
url: https://semgrep.dev/playground/r/l4TJRkk/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access
|
|
origin: community
|
|
message: Using user input when accessing files is potentially dangerous. A malicious
|
|
actor could use this to modify or access files they have no right to.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: params
|
|
- pattern: cookies
|
|
- pattern: request.env
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: Dir.$X(...)
|
|
- pattern: File.$X(...)
|
|
- pattern: IO.$X(...)
|
|
- pattern: Kernel.$X(...)
|
|
- pattern: PStore.$X(...)
|
|
- pattern: Pathname.$X(...)
|
|
- metavariable-pattern:
|
|
metavariable: $X
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: chdir
|
|
- pattern: chroot
|
|
- pattern: delete
|
|
- pattern: entries
|
|
- pattern: foreach
|
|
- pattern: glob
|
|
- pattern: install
|
|
- pattern: lchmod
|
|
- pattern: lchown
|
|
- pattern: link
|
|
- pattern: load
|
|
- pattern: load_file
|
|
- pattern: makedirs
|
|
- pattern: move
|
|
- pattern: new
|
|
- pattern: open
|
|
- pattern: read
|
|
- pattern: readlines
|
|
- pattern: rename
|
|
- pattern: rmdir
|
|
- pattern: safe_unlink
|
|
- pattern: symlink
|
|
- pattern: syscopy
|
|
- pattern: sysopen
|
|
- pattern: truncate
|
|
- pattern: unlink
|
|
- id: ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call
|
|
metadata:
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
references:
|
|
- https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown
|
|
category: security
|
|
technology:
|
|
- rails
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call
|
|
shortlink: https://sg.run/Q9gP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13586
|
|
rv_id: 1263623
|
|
rule_id: WAUyzp
|
|
version_id: YDTZeWL
|
|
url: https://semgrep.dev/playground/r/YDTZeWL/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call
|
|
origin: community
|
|
message: Using user input when accessing files is potentially dangerous. A malicious
|
|
actor could use this to modify or access files they have no right to.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: params
|
|
- pattern: cookies
|
|
- pattern: request.env
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- pattern: Net::FTP.$X(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$FTP = Net::FTP.$OPEN(...)
|
|
...
|
|
$FTP.$METHOD(...)
|
|
- pattern: $FTP.$METHOD(...)
|
|
- id: ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request
|
|
metadata:
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
references:
|
|
- https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown
|
|
category: security
|
|
technology:
|
|
- rails
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request
|
|
shortlink: https://sg.run/3rLb
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13587
|
|
rv_id: 1263624
|
|
rule_id: 0oU2x3
|
|
version_id: 6xT29nN
|
|
url: https://semgrep.dev/playground/r/6xT29nN/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request
|
|
origin: community
|
|
message: Using user input when accessing files is potentially dangerous. A malicious
|
|
actor could use this to modify or access files they have no right to.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: params
|
|
- pattern: cookies
|
|
- pattern: request.env
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: Net::HTTP::$METHOD.new(...)
|
|
- metavariable-pattern:
|
|
metavariable: $METHOD
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: Copy
|
|
- pattern: Delete
|
|
- pattern: Get
|
|
- pattern: Head
|
|
- pattern: Lock
|
|
- pattern: Mkcol
|
|
- pattern: Move
|
|
- pattern: Options
|
|
- pattern: Patch
|
|
- pattern: Post
|
|
- pattern: Propfind
|
|
- pattern: Proppatch
|
|
- pattern: Put
|
|
- pattern: Trace
|
|
- pattern: Unlock
|
|
- patterns:
|
|
- pattern: Net::HTTP.$X(...)
|
|
- metavariable-pattern:
|
|
metavariable: $X
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: get
|
|
- pattern: get2
|
|
- pattern: head
|
|
- pattern: head2
|
|
- pattern: options
|
|
- pattern: patch
|
|
- pattern: post
|
|
- pattern: post2
|
|
- pattern: post_form
|
|
- pattern: put
|
|
- pattern: request
|
|
- pattern: request_get
|
|
- pattern: request_head
|
|
- pattern: request_post
|
|
- pattern: send_request
|
|
- pattern: trace
|
|
- pattern: get_print
|
|
- pattern: get_response
|
|
- pattern: start
|
|
- id: ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call
|
|
metadata:
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
references:
|
|
- https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown
|
|
category: security
|
|
technology:
|
|
- rails
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call
|
|
shortlink: https://sg.run/4e8E
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13588
|
|
rv_id: 1263625
|
|
rule_id: KxU72k
|
|
version_id: o5TbDq8
|
|
url: https://semgrep.dev/playground/r/o5TbDq8/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call
|
|
origin: community
|
|
message: Using user input when accessing files is potentially dangerous. A malicious
|
|
actor could use this to modify or access files they have no right to.
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- pattern: params[...]
|
|
- pattern: cookies
|
|
- pattern: request.env
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: Kernel.$X(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: Shell.$X(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$SHELL = Shell.$ANY(...)
|
|
...
|
|
$SHELL.$X(...)
|
|
- pattern: $SHELL.$X(...)
|
|
- metavariable-pattern:
|
|
metavariable: $X
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: cat
|
|
- pattern: chdir
|
|
- pattern: chroot
|
|
- pattern: delete
|
|
- pattern: entries
|
|
- pattern: exec
|
|
- pattern: foreach
|
|
- pattern: glob
|
|
- pattern: install
|
|
- pattern: lchmod
|
|
- pattern: lchown
|
|
- pattern: link
|
|
- pattern: load
|
|
- pattern: load_file
|
|
- pattern: makedirs
|
|
- pattern: move
|
|
- pattern: new
|
|
- pattern: open
|
|
- pattern: read
|
|
- pattern: readlines
|
|
- pattern: rename
|
|
- pattern: rmdir
|
|
- pattern: safe_unlink
|
|
- pattern: symlink
|
|
- pattern: syscopy
|
|
- pattern: sysopen
|
|
- pattern: system
|
|
- pattern: truncate
|
|
- pattern: unlink
|
|
- id: ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_link_to.rb
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
references:
|
|
- https://brakemanscanner.org/docs/warning_types/link_to/
|
|
- https://brakemanscanner.org/docs/warning_types/link_to_href/
|
|
category: security
|
|
technology:
|
|
- rails
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to
|
|
shortlink: https://sg.run/JxXQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13590
|
|
rv_id: 1263632
|
|
rule_id: lBU8Qj
|
|
version_id: 9lT4brj
|
|
url: https://semgrep.dev/playground/r/9lT4brj/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to
|
|
origin: community
|
|
message: This code includes user input in `link_to`. In Rails 2.x, the body of `link_to`
|
|
is not escaped. This means that user input which reaches the body will be executed
|
|
when the HTML is rendered. Even in other versions, values starting with `javascript:`
|
|
or `data:` are not escaped. It is better to create and use a safer function which
|
|
checks the body argument.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: params
|
|
- pattern: cookies
|
|
- pattern: request.env
|
|
- pattern-either:
|
|
- pattern: $MODEL.url(...)
|
|
- pattern: $MODEL.uri(...)
|
|
- pattern: $MODEL.link(...)
|
|
- pattern: $MODEL.page(...)
|
|
- pattern: $MODEL.site(...)
|
|
pattern-sinks:
|
|
- pattern: link_to(...)
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: |
|
|
"...#{...}..."
|
|
- pattern-not: |
|
|
"#{...}..."
|
|
- id: ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect
|
|
metadata:
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
|
|
references:
|
|
- https://brakemanscanner.org/docs/warning_types/redirect/
|
|
category: security
|
|
technology:
|
|
- rails
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Open Redirect
|
|
source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect
|
|
shortlink: https://sg.run/5DY3
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13591
|
|
rv_id: 1263634
|
|
rule_id: YGUDqJ
|
|
version_id: rxTAKdY
|
|
url: https://semgrep.dev/playground/r/rxTAKdY/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect
|
|
origin: community
|
|
message: When a redirect uses user input, a malicious user can spoof a website under
|
|
a trusted URL or access restricted parts of a site. When using user-supplied values,
|
|
sanitize the value before using it for the redirect.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: params
|
|
- pattern: cookies
|
|
- pattern: request.env
|
|
- patterns:
|
|
- pattern: $MODEL.$X(...)
|
|
- pattern-not: $MODEL.$X("...")
|
|
- metavariable-pattern:
|
|
metavariable: $X
|
|
pattern-either:
|
|
- pattern: all
|
|
- pattern: create
|
|
- pattern: create!
|
|
- pattern: find
|
|
- pattern: find_by_sql
|
|
- pattern: first
|
|
- pattern: last
|
|
- pattern: new
|
|
- pattern: from
|
|
- pattern: group
|
|
- pattern: having
|
|
- pattern: joins
|
|
- pattern: lock
|
|
- pattern: order
|
|
- pattern: reorder
|
|
- pattern: select
|
|
- pattern: where
|
|
- pattern: find_by
|
|
- pattern: find_by!
|
|
- pattern: take
|
|
pattern-sinks:
|
|
- pattern: redirect_to(...)
|
|
pattern-sanitizers:
|
|
- pattern: params.merge(:only_path => true)
|
|
- pattern: params.merge(:host => ...)
|
|
- id: ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path
|
|
metadata:
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
references:
|
|
- https://brakemanscanner.org/docs/warning_types/dynamic_render_paths/
|
|
category: security
|
|
technology:
|
|
- rails
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path
|
|
shortlink: https://sg.run/GO2n
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13592
|
|
rv_id: 1263635
|
|
rule_id: 6JU1bL
|
|
version_id: bZT53p0
|
|
url: https://semgrep.dev/playground/r/bZT53p0/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path
|
|
origin: community
|
|
message: Avoid rendering user input. It may be possible for a malicious user to
|
|
input a path that lets them access a template they shouldn't. To prevent this,
|
|
check dynamic template paths against a predefined allowlist to make sure it's
|
|
an allowed template.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: params
|
|
- pattern: cookies
|
|
- pattern: request.env
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: render($X => $INPUT, ...)
|
|
- pattern: $INPUT
|
|
- metavariable-pattern:
|
|
metavariable: $X
|
|
pattern-either:
|
|
- pattern: action
|
|
- pattern: template
|
|
- pattern: partial
|
|
- pattern: file
|
|
- id: python.lang.security.audit.insecure-file-permissions.insecure-file-permissions
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-276: Incorrect Default Permissions'
|
|
technology:
|
|
- python
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions
|
|
shortlink: https://sg.run/AXY4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13594
|
|
rv_id: 1263482
|
|
rule_id: zdUYqR
|
|
version_id: O9Tpxqr
|
|
url: https://semgrep.dev/playground/r/O9Tpxqr/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions
|
|
origin: community
|
|
message: These permissions `$BITS` are widely permissive and grant access to more
|
|
people than may be necessary. A good default is `0o644` which gives read and write
|
|
access to yourself and read access to everyone else.
|
|
patterns:
|
|
- pattern-inside: os.$METHOD(...)
|
|
- metavariable-pattern:
|
|
metavariable: $METHOD
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: chmod
|
|
- pattern: lchmod
|
|
- pattern: fchmod
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: os.$METHOD($FILE, $BITS, ...)
|
|
- metavariable-comparison:
|
|
metavariable: $BITS
|
|
comparison: $BITS >= 0o650 and $BITS < 0o100000
|
|
- patterns:
|
|
- pattern: os.$METHOD($FILE, $BITS)
|
|
- metavariable-comparison:
|
|
metavariable: $BITS
|
|
comparison: $BITS >= 0o100650
|
|
- patterns:
|
|
- pattern: os.$METHOD($FILE, $BITS, ...)
|
|
- metavariable-pattern:
|
|
metavariable: $BITS
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: <... stat.S_IWGRP ...>
|
|
- pattern: <... stat.S_IXGRP ...>
|
|
- pattern: <... stat.S_IWOTH ...>
|
|
- pattern: <... stat.S_IXOTH ...>
|
|
- pattern: <... stat.S_IRWXO ...>
|
|
- pattern: <... stat.S_IRWXG ...>
|
|
- patterns:
|
|
- pattern: os.$METHOD($FILE, $EXPR | $MOD, ...)
|
|
- metavariable-comparison:
|
|
metavariable: $MOD
|
|
comparison: $MOD == 0o111
|
|
- id: php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query
|
|
languages:
|
|
- php
|
|
message: '`$QUERY` Detected string concatenation with a non-literal variable in
|
|
a Doctrine QueryBuilder method. This could lead to SQL injection if the variable
|
|
is user-controlled and not properly sanitized. In order to prevent SQL injection,
|
|
use parameterized queries or prepared statements instead.'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://www.doctrine-project.org/projects/doctrine-dbal/en/current/reference/query-builder.html#security-safely-preventing-sql-injection
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
|
|
technology:
|
|
- doctrine
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query
|
|
shortlink: https://sg.run/jwDJ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 13965
|
|
rv_id: 1263271
|
|
rule_id: kxUw23
|
|
version_id: 1QTypnG
|
|
url: https://semgrep.dev/playground/r/1QTypnG/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query
|
|
origin: community
|
|
mode: taint
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $SINK
|
|
- pattern-either:
|
|
- pattern: $QUERY->add(...,$SINK,...)
|
|
- pattern: $QUERY->select(...,$SINK,...)
|
|
- pattern: $QUERY->addSelect(...,$SINK,...)
|
|
- pattern: $QUERY->delete(...,$SINK,...)
|
|
- pattern: $QUERY->update(...,$SINK,...)
|
|
- pattern: $QUERY->insert(...,$SINK,...)
|
|
- pattern: $QUERY->from(...,$SINK,...)
|
|
- pattern: $QUERY->join(...,$SINK,...)
|
|
- pattern: $QUERY->innerJoin(...,$SINK,...)
|
|
- pattern: $QUERY->leftJoin(...,$SINK,...)
|
|
- pattern: $QUERY->rightJoin(...,$SINK,...)
|
|
- pattern: $QUERY->where(...,$SINK,...)
|
|
- pattern: $QUERY->andWhere(...,$SINK,...)
|
|
- pattern: $QUERY->orWhere(...,$SINK,...)
|
|
- pattern: $QUERY->groupBy(...,$SINK,...)
|
|
- pattern: $QUERY->addGroupBy(...,$SINK,...)
|
|
- pattern: $QUERY->having(...,$SINK,...)
|
|
- pattern: $QUERY->andHaving(...,$SINK,...)
|
|
- pattern: $QUERY->orHaving(...,$SINK,...)
|
|
- pattern: $QUERY->orderBy(...,$SINK,...)
|
|
- pattern: $QUERY->addOrderBy(...,$SINK,...)
|
|
- pattern: $QUERY->set($SINK,...)
|
|
- pattern: $QUERY->setValue($SINK,...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$Q = $X->createQueryBuilder();
|
|
...
|
|
- pattern-inside: |
|
|
$Q = new QueryBuilder(...);
|
|
...
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sprintf(...)
|
|
- pattern: |
|
|
"...".$SMTH
|
|
severity: WARNING
|
|
- id: python.django.security.injection.raw-html-format.raw-html-format
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
message: Detected user input flowing into a manually constructed HTML string. You
|
|
may be accidentally bypassing secure methods of rendering HTML by manually constructing
|
|
HTML and this could create a cross-site scripting vulnerability, which could let
|
|
attackers steal sensitive user data. To be sure this is safe, check that the HTML
|
|
is rendered safely. Otherwise, use templates (`django.shortcuts.render`) which
|
|
will safely render HTML instead.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- django
|
|
references:
|
|
- https://docs.djangoproject.com/en/3.2/topics/http/shortcuts/#render
|
|
- https://docs.djangoproject.com/en/3.2/topics/security/#cross-site-scripting-xss-protection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/python.django.security.injection.raw-html-format.raw-html-format
|
|
shortlink: https://sg.run/oYj1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14360
|
|
rv_id: 1263397
|
|
rule_id: 2ZUPER
|
|
version_id: 5PTo100
|
|
url: https://semgrep.dev/playground/r/5PTo100/python.django.security.injection.raw-html-format.raw-html-format
|
|
origin: community
|
|
mode: taint
|
|
pattern-sanitizers:
|
|
- pattern: django.utils.html.escape(...)
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: request.$ANYTHING
|
|
- pattern-not: request.build_absolute_uri
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: '"$HTMLSTR" % ...'
|
|
- pattern: '"$HTMLSTR".format(...)'
|
|
- pattern: '"$HTMLSTR" + ...'
|
|
- pattern: f"$HTMLSTR{...}..."
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$HTML = "$HTMLSTR"
|
|
...
|
|
- pattern-either:
|
|
- pattern: $HTML % ...
|
|
- pattern: $HTML.format(...)
|
|
- pattern: $HTML + ...
|
|
- metavariable-pattern:
|
|
metavariable: $HTMLSTR
|
|
language: generic
|
|
pattern: <$TAG ...
|
|
- id: python.flask.security.injection.raw-html-concat.raw-html-format
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
message: Detected user input flowing into a manually constructed HTML string. You
|
|
may be accidentally bypassing secure methods of rendering HTML by manually constructing
|
|
HTML and this could create a cross-site scripting vulnerability, which could let
|
|
attackers steal sensitive user data. To be sure this is safe, check that the HTML
|
|
is rendered safely. Otherwise, use templates (`flask.render_template`) which will
|
|
safely render HTML instead.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- flask
|
|
references:
|
|
- https://flask.palletsprojects.com/en/2.0.x/security/#cross-site-scripting-xss
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/python.flask.security.injection.raw-html-concat.raw-html-format
|
|
shortlink: https://sg.run/Pb7e
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14389
|
|
rv_id: 1409401
|
|
rule_id: GdUrJv
|
|
version_id: RGTEN1l
|
|
url: https://semgrep.dev/playground/r/RGTEN1l/python.flask.security.injection.raw-html-concat.raw-html-format
|
|
origin: community
|
|
mode: taint
|
|
pattern-sanitizers:
|
|
- pattern: jinja2.escape(...)
|
|
- pattern: flask.escape(...)
|
|
- patterns:
|
|
- pattern: flask.render_template($TPL, ...)
|
|
- metavariable-regex:
|
|
metavariable: $TPL
|
|
regex: .*\.html
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.$ANYTHING
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route(...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- pattern: $ROUTEVAR
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: '"$HTMLSTR" % ...'
|
|
- pattern: '"$HTMLSTR".format(...)'
|
|
- pattern: '"$HTMLSTR" + ...'
|
|
- pattern: f"$HTMLSTR{...}..."
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$HTML = "$HTMLSTR"
|
|
...
|
|
- pattern-either:
|
|
- pattern: $HTML % ...
|
|
- pattern: $HTML.format(...)
|
|
- pattern: $HTML + ...
|
|
- metavariable-pattern:
|
|
metavariable: $HTMLSTR
|
|
language: generic
|
|
pattern: <$TAG ...
|
|
- id: go.lang.security.injection.tainted-url-host.tainted-url-host
|
|
languages:
|
|
- go
|
|
message: A request was found to be crafted from user-input `$REQUEST`. This can
|
|
lead to Server-Side Request Forgery (SSRF) vulnerabilities, potentially exposing
|
|
sensitive data. It is recommend where possible to not allow user-input to craft
|
|
the base request, but to be treated as part of the path or query parameter. When
|
|
user-input is necessary to craft the request, it is recommended to follow OWASP
|
|
best practices to prevent abuse, including using an allowlist.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://goteleport.com/blog/ssrf-attacks/
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host
|
|
shortlink: https://sg.run/5DjW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14391
|
|
rv_id: 1262970
|
|
rule_id: AbUQLr
|
|
version_id: yeTxpOj
|
|
url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- label: INPUT
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
($REQUEST : *http.Request).$ANYTHING
|
|
- pattern: |
|
|
($REQUEST : http.Request).$ANYTHING
|
|
- metavariable-regex:
|
|
metavariable: $ANYTHING
|
|
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
|
|
- label: CLEAN
|
|
requires: INPUT
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$URLSTR" + $INPUT
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...)
|
|
- pattern: fmt.Sprintf("$URLSTR", $INPUT, ...)
|
|
- pattern: fmt.Printf("$URLSTR", $INPUT, ...)
|
|
- metavariable-regex:
|
|
metavariable: $URLSTR
|
|
regex: .*//[a-zA-Z0-10]+\..*
|
|
pattern-sinks:
|
|
- requires: INPUT and not CLEAN
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$CLIENT := &http.Client{...}
|
|
...
|
|
- pattern: $CLIENT.$METHOD($URL, ...)
|
|
- pattern: http.$METHOD($URL, ...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(Get|Head|Post|PostForm)$
|
|
- patterns:
|
|
- pattern: |
|
|
http.NewRequest("$METHOD", $URL, ...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(GET|HEAD|POST|POSTFORM)$
|
|
- focus-metavariable: $URL
|
|
severity: WARNING
|
|
- id: go.lang.security.injection.raw-html-format.raw-html-format
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
message: Detected user input flowing into a manually constructed HTML string. You
|
|
may be accidentally bypassing secure methods of rendering HTML by manually constructing
|
|
HTML and this could create a cross-site scripting vulnerability, which could let
|
|
attackers steal sensitive user data. Use the `html/template` package which will
|
|
safely render HTML instead, or inspect that the HTML is rendered safely.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- go
|
|
references:
|
|
- https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/go.lang.security.injection.raw-html-format.raw-html-format
|
|
shortlink: https://sg.run/3r1G
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14443
|
|
rv_id: 1262968
|
|
rule_id: PeUonQ
|
|
version_id: 1QTyp2p
|
|
url: https://semgrep.dev/playground/r/1QTyp2p/go.lang.security.injection.raw-html-format.raw-html-format
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
($REQUEST : *http.Request).$ANYTHING
|
|
- pattern: |
|
|
($REQUEST : http.Request).$ANYTHING
|
|
- metavariable-regex:
|
|
metavariable: $ANYTHING
|
|
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
|
|
pattern-sanitizers:
|
|
- pattern: html.EscapeString(...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: fmt.Printf("$HTMLSTR", ...)
|
|
- pattern: fmt.Sprintf("$HTMLSTR", ...)
|
|
- pattern: fmt.Fprintf($W, "$HTMLSTR", ...)
|
|
- pattern: '"$HTMLSTR" + ...'
|
|
- metavariable-pattern:
|
|
metavariable: $HTMLSTR
|
|
language: generic
|
|
pattern: <$TAG ...
|
|
- id: ruby.rails.security.injection.raw-html-format.raw-html-format
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
message: Detected user input flowing into a manually constructed HTML string. You
|
|
may be accidentally bypassing secure methods of rendering HTML by manually constructing
|
|
HTML and this could create a cross-site scripting vulnerability, which could let
|
|
attackers steal sensitive user data. Use the `render template` and make template
|
|
files which will safely render HTML instead, or inspect that the HTML is absolutely
|
|
rendered safely with a function like `sanitize`.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- rails
|
|
references:
|
|
- https://www.netsparker.com/blog/web-security/preventing-xss-ruby-on-rails-web-applications/
|
|
- https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/ruby.rails.security.injection.raw-html-format.raw-html-format
|
|
shortlink: https://sg.run/b2JQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14470
|
|
rv_id: 1409408
|
|
rule_id: kxUwZX
|
|
version_id: qkTvgYY
|
|
url: https://semgrep.dev/playground/r/qkTvgYY/ruby.rails.security.injection.raw-html-format.raw-html-format
|
|
origin: community
|
|
mode: taint
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: sanitize(...)
|
|
- pattern: strip_tags(...)
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: request
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
$HTMLSTR
|
|
- pattern-regex: <\w+.*
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: Kernel::sprintf("$HTMLSTR", ...)
|
|
- pattern: |
|
|
"$HTMLSTR" + $EXPR
|
|
- pattern: |
|
|
"$HTMLSTR" % $EXPR
|
|
- metavariable-pattern:
|
|
metavariable: $HTMLSTR
|
|
language: generic
|
|
pattern: <$TAG ...
|
|
- id: bash.curl.security.curl-eval.curl-eval
|
|
severity: WARNING
|
|
languages:
|
|
- bash
|
|
message: Data is being eval'd from a `curl` command. An attacker with control of
|
|
the server in the `curl` command could inject malicious code into the `eval`,
|
|
resulting in a system comrpomise. Avoid eval'ing untrusted data if you can. If
|
|
you must do this, consider checking the SHA sum of the content returned by the
|
|
server to verify its integrity.
|
|
metadata:
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
category: security
|
|
technology:
|
|
- bash
|
|
- curl
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/bash.curl.security.curl-eval.curl-eval
|
|
shortlink: https://sg.run/0yqJ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14554
|
|
rv_id: 1262601
|
|
rule_id: KxU7Rq
|
|
version_id: JdTzxL2
|
|
url: https://semgrep.dev/playground/r/JdTzxL2/bash.curl.security.curl-eval.curl-eval
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: |
|
|
$(curl ...)
|
|
- pattern: |
|
|
`curl ...`
|
|
pattern-sinks:
|
|
- pattern: eval ...
|
|
- id: python.flask.security.injection.tainted-url-host.tainted-url-host
|
|
languages:
|
|
- python
|
|
message: User data flows into the host portion of this manually-constructed URL.
|
|
This could allow an attacker to send data to their own server, potentially exposing
|
|
sensitive data such as cookies or authorization information sent with this request.
|
|
They could also probe internal servers or other resources that the server running
|
|
this code can access. (This is called server-side request forgery, or SSRF.) Do
|
|
not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or
|
|
hardcode the correct host.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
technology:
|
|
- flask
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/python.flask.security.injection.tainted-url-host.tainted-url-host
|
|
shortlink: https://sg.run/RXpK
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14649
|
|
rv_id: 1409403
|
|
rule_id: ReU3Wb
|
|
version_id: BjTy42w
|
|
url: https://semgrep.dev/playground/r/BjTy42w/python.flask.security.injection.tainted-url-host.tainted-url-host
|
|
origin: community
|
|
mode: taint
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: '"$URLSTR" % ...'
|
|
- metavariable-pattern:
|
|
metavariable: $URLSTR
|
|
language: generic
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: $SCHEME://%s
|
|
- pattern: $SCHEME://%r
|
|
- patterns:
|
|
- pattern: '"$URLSTR".format(...)'
|
|
- metavariable-pattern:
|
|
metavariable: $URLSTR
|
|
language: generic
|
|
pattern: $SCHEME:// { ... }
|
|
- patterns:
|
|
- pattern: '"$URLSTR" + ...'
|
|
- metavariable-regex:
|
|
metavariable: $URLSTR
|
|
regex: .*://$
|
|
- patterns:
|
|
- pattern: f"$URLSTR{...}..."
|
|
- metavariable-regex:
|
|
metavariable: $URLSTR
|
|
regex: .*://$
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$URL = "$URLSTR"
|
|
...
|
|
- pattern: $URL += ...
|
|
- metavariable-regex:
|
|
metavariable: $URLSTR
|
|
regex: .*://$
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.$ANYTHING
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route(...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- pattern: $ROUTEVAR
|
|
severity: WARNING
|
|
- id: go.lang.security.audit.md5-used-as-password.md5-used-as-password
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
message: It looks like MD5 is used as a password hash. MD5 is not considered a secure
|
|
password hash because it can be cracked by an attacker in a short amount of time.
|
|
Use a suitable password hashing function such as bcrypt. You can use the `golang.org/x/crypto/bcrypt`
|
|
package.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- md5
|
|
references:
|
|
- https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html
|
|
- https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords
|
|
- https://github.com/returntocorp/semgrep-rules/issues/1609
|
|
- https://pkg.go.dev/golang.org/x/crypto/bcrypt
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/go.lang.security.audit.md5-used-as-password.md5-used-as-password
|
|
shortlink: https://sg.run/4eOE
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14688
|
|
rv_id: 1262938
|
|
rule_id: 4bU1Wj
|
|
version_id: nWT2L9r
|
|
url: https://semgrep.dev/playground/r/nWT2L9r/go.lang.security.audit.md5-used-as-password.md5-used-as-password
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: md5.New
|
|
- pattern: md5.Sum
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $FUNCTION(...)
|
|
- metavariable-regex:
|
|
metavariable: $FUNCTION
|
|
regex: (?i)(.*password.*)
|
|
- id: go.lang.security.injection.tainted-sql-string.tainted-sql-string
|
|
languages:
|
|
- go
|
|
message: User data flows into this manually-constructed SQL string. User data can
|
|
be safely inserted into SQL strings using prepared statements or an object-relational
|
|
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
|
|
injection, which could let an attacker steal or manipulate data from the database.
|
|
Instead, use prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`)
|
|
or a safe library.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://golang.org/doc/database/sql-injection
|
|
- https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string
|
|
shortlink: https://sg.run/PbEq
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14689
|
|
rv_id: 1409388
|
|
rule_id: PeUoqy
|
|
version_id: nWTQ5qD
|
|
url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string
|
|
origin: community
|
|
mode: taint
|
|
severity: ERROR
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
($REQUEST : *http.Request).$ANYTHING
|
|
- pattern: |
|
|
($REQUEST : http.Request).$ANYTHING
|
|
- metavariable-regex:
|
|
metavariable: $ANYTHING
|
|
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$SQLSTR" + ...
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VAR = "$SQLSTR";
|
|
...
|
|
- pattern: $VAR += ...
|
|
- patterns:
|
|
- pattern-inside: |
|
|
var $SB strings.Builder
|
|
...
|
|
- pattern-inside: |
|
|
$SB.WriteString("$SQLSTR")
|
|
...
|
|
$SB.String(...)
|
|
- pattern: |
|
|
$SB.WriteString(...)
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(select|delete|insert|create|update|alter|drop).*
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: fmt.Fprintf($F, "$SQLSTR", ...)
|
|
- pattern: fmt.Sprintf("$SQLSTR", ...)
|
|
- pattern: fmt.Printf("$SQLSTR", ...)
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).*
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: strconv.Atoi(...)
|
|
- pattern: |
|
|
($X: bool)
|
|
- id: java.lang.security.audit.md5-used-as-password.md5-used-as-password
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
message: It looks like MD5 is used as a password hash. MD5 is not considered a secure
|
|
password hash because it can be cracked by an attacker in a short amount of time.
|
|
Use a suitable password hashing function such as PBKDF2 or bcrypt. You can use
|
|
`javax.crypto.SecretKeyFactory` with `SecretKeyFactory.getInstance("PBKDF2WithHmacSHA1")`
|
|
or, if using Spring, `org.springframework.security.crypto.bcrypt`.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- java
|
|
- md5
|
|
references:
|
|
- https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html
|
|
- https://github.com/returntocorp/semgrep-rules/issues/1609
|
|
- https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#SecretKeyFactory
|
|
- https://docs.spring.io/spring-security/site/docs/current/api/org/springframework/security/crypto/bcrypt/BCryptPasswordEncoder.html
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.md5-used-as-password.md5-used-as-password
|
|
shortlink: https://sg.run/JxEQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14690
|
|
rv_id: 1263029
|
|
rule_id: JDULAW
|
|
version_id: bZT53QB
|
|
url: https://semgrep.dev/playground/r/bZT53QB/java.lang.security.audit.md5-used-as-password.md5-used-as-password
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$TYPE $MD = MessageDigest.getInstance("MD5");
|
|
...
|
|
- pattern: $MD.digest(...);
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $MODEL.$METHOD(...);
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (?i)(.*password.*)
|
|
- id: javascript.express.security.injection.raw-html-format.raw-html-format
|
|
message: User data flows into the host portion of this manually-constructed HTML.
|
|
This can introduce a Cross-Site-Scripting (XSS) vulnerability if this comes from
|
|
user-provided input. Consider using a sanitization library such as DOMPurify to
|
|
sanitize the HTML within.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/javascript.express.security.injection.raw-html-format.raw-html-format
|
|
shortlink: https://sg.run/5DO3
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14691
|
|
rv_id: 1263175
|
|
rule_id: 5rUL0X
|
|
version_id: NdTzyQv
|
|
url: https://semgrep.dev/playground/r/NdTzyQv/javascript.express.security.injection.raw-html-format.raw-html-format
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- label: EXPRESS
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- label: EXPRESSTS
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
- label: CLEAN
|
|
by-side-effect: true
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: $A($SOURCE)
|
|
- pattern: $SANITIZE. ... .$A($SOURCE)
|
|
- pattern: $A. ... .$SANITIZE($SOURCE)
|
|
- focus-metavariable: $SOURCE
|
|
- metavariable-regex:
|
|
metavariable: $A
|
|
regex: (?i)(.*valid|.*sanitiz)
|
|
pattern-sinks:
|
|
- requires: (EXPRESS and not CLEAN) or (EXPRESSTS and not CLEAN)
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: '"$HTMLSTR" + $EXPR'
|
|
- pattern: '"$HTMLSTR".concat(...)'
|
|
- pattern: util.format($HTMLSTR, ...)
|
|
- metavariable-pattern:
|
|
metavariable: $HTMLSTR
|
|
language: generic
|
|
pattern: <$TAG ...
|
|
- patterns:
|
|
- pattern: |
|
|
`...`
|
|
- pattern-regex: |
|
|
.*<\w+.*
|
|
- id: kotlin.lang.security.ecb-cipher.ecb-cipher
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE
|
|
category: security
|
|
technology:
|
|
- kotlin
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/kotlin.lang.security.ecb-cipher.ecb-cipher
|
|
shortlink: https://sg.run/DzLj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14696
|
|
rv_id: 1263263
|
|
rule_id: DbU1Zd
|
|
version_id: YDTZexg
|
|
url: https://semgrep.dev/playground/r/YDTZexg/kotlin.lang.security.ecb-cipher.ecb-cipher
|
|
origin: community
|
|
message: Cipher in ECB mode is detected. ECB mode produces the same output for the
|
|
same input each time which allows an attacker to intercept and replay the data.
|
|
Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY.
|
|
severity: WARNING
|
|
languages:
|
|
- kt
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
val $VAR : Cipher = $CIPHER.getInstance($MODE)
|
|
- pattern: |
|
|
var $VAR : Cipher = $CIPHER.getInstance($MODE)
|
|
- pattern: |
|
|
val $VAR = $CIPHER.getInstance($MODE)
|
|
- pattern: |
|
|
var $VAR = $CIPHER.getInstance($MODE)
|
|
- metavariable-regex:
|
|
metavariable: $MODE
|
|
regex: .*ECB.*
|
|
- id: kotlin.lang.security.no-null-cipher.no-null-cipher
|
|
pattern: NullCipher(...)
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- kotlin
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/kotlin.lang.security.no-null-cipher.no-null-cipher
|
|
shortlink: https://sg.run/0ywb
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14698
|
|
rv_id: 1263265
|
|
rule_id: 0oU2Yy
|
|
version_id: o5TbDPj
|
|
url: https://semgrep.dev/playground/r/o5TbDPj/kotlin.lang.security.no-null-cipher.no-null-cipher
|
|
origin: community
|
|
message: 'NullCipher was detected. This will not encrypt anything; the cipher text
|
|
will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING").
|
|
See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for
|
|
more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- kt
|
|
- scala
|
|
- id: kotlin.lang.security.use-of-md5.use-of-md5
|
|
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use SHA256
|
|
or SHA3 instead.
|
|
languages:
|
|
- kt
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5
|
|
category: security
|
|
technology:
|
|
- kotlin
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/kotlin.lang.security.use-of-md5.use-of-md5
|
|
shortlink: https://sg.run/4eQx
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14700
|
|
rv_id: 1263267
|
|
rule_id: qNUXPj
|
|
version_id: pZT03Jd
|
|
url: https://semgrep.dev/playground/r/pZT03Jd/kotlin.lang.security.use-of-md5.use-of-md5
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: |
|
|
java.security.MessageDigest.getInstance("MD5")
|
|
- pattern: |
|
|
org.apache.commons.codec.digest.DigestUtils.getMd5Digest()
|
|
- id: python.flask.security.injection.tainted-sql-string.tainted-sql-string
|
|
message: Detected user input used to manually construct a SQL string. This is usually
|
|
bad practice because manual construction could accidentally result in a SQL injection.
|
|
An attacker could use a SQL injection to steal or modify contents of the database.
|
|
Instead, use a parameterized query which is available by default in most database
|
|
engines. Alternatively, consider using an object-relational mapper (ORM) such
|
|
as SQLAlchemy which will protect your queries.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-704: Incorrect Type Conversion or Cast'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql
|
|
- https://www.tutorialspoint.com/sqlalchemy/sqlalchemy_quick_guide.htm
|
|
- https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-more-specific-text-with-table-expression-literal-column-and-expression-column
|
|
category: security
|
|
technology:
|
|
- sqlalchemy
|
|
- flask
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/python.flask.security.injection.tainted-sql-string.tainted-sql-string
|
|
shortlink: https://sg.run/JxZj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14702
|
|
rv_id: 1409402
|
|
rule_id: YGUDKQ
|
|
version_id: A8TEvb4
|
|
url: https://semgrep.dev/playground/r/A8TEvb4/python.flask.security.injection.tainted-sql-string.tainted-sql-string
|
|
origin: community
|
|
severity: ERROR
|
|
languages:
|
|
- python
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.$ANYTHING
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route(...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- pattern: $ROUTEVAR
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$SQLSTR" + ...
|
|
- pattern: |
|
|
"$SQLSTR" % ...
|
|
- pattern: |
|
|
"$SQLSTR".format(...)
|
|
- pattern: |
|
|
f"$SQLSTR{...}..."
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*
|
|
- id: python.lang.security.audit.md5-used-as-password.md5-used-as-password
|
|
severity: WARNING
|
|
message: It looks like MD5 is used as a password hash. MD5 is not considered a secure
|
|
password hash because it can be cracked by an attacker in a short amount of time.
|
|
Use a suitable password hashing function such as scrypt. You can use `hashlib.scrypt`.
|
|
languages:
|
|
- python
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://tools.ietf.org/html/rfc6151
|
|
- https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
- https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords
|
|
- https://github.com/returntocorp/semgrep-rules/issues/1609
|
|
- https://docs.python.org/3/library/hashlib.html#hashlib.scrypt
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
- hashlib
|
|
- md5
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.lang.security.audit.md5-used-as-password.md5-used-as-password
|
|
shortlink: https://sg.run/5DwD
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14703
|
|
rv_id: 1263504
|
|
rule_id: 6JU1w1
|
|
version_id: WrTqKDz
|
|
url: https://semgrep.dev/playground/r/WrTqKDz/python.lang.security.audit.md5-used-as-password.md5-used-as-password
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: hashlib.md5
|
|
- pattern: hashlib.new(..., name="MD5", ...)
|
|
- pattern: Cryptodome.Hash.MD5
|
|
- pattern: Crypto.Hash.MD5
|
|
- pattern: cryptography.hazmat.primitives.hashes.MD5
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $FUNCTION(...)
|
|
- metavariable-regex:
|
|
metavariable: $FUNCTION
|
|
regex: (?i)(.*password.*)
|
|
- id: ruby.lang.security.md5-used-as-password.md5-used-as-password
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
message: It looks like MD5 is used as a password hash. MD5 is not considered a secure
|
|
password hash because it can be cracked by an attacker in a short amount of time.
|
|
Instead, use a suitable password hashing function such as bcrypt. You can use
|
|
the `bcrypt` gem.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- md5
|
|
references:
|
|
- https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html
|
|
- https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords
|
|
- https://github.com/returntocorp/semgrep-rules/issues/1609
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/ruby.lang.security.md5-used-as-password.md5-used-as-password
|
|
shortlink: https://sg.run/GOZy
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14704
|
|
rv_id: 1263611
|
|
rule_id: oqU4p2
|
|
version_id: JdTzx0e
|
|
url: https://semgrep.dev/playground/r/JdTzx0e/ruby.lang.security.md5-used-as-password.md5-used-as-password
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: Digest::MD5
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $FUNCTION(...);
|
|
- metavariable-regex:
|
|
metavariable: $FUNCTION
|
|
regex: (?i)(.*password.*)
|
|
- id: json.aws.security.wildcard-assume-role.wildcard-assume-role
|
|
patterns:
|
|
- pattern-inside: |
|
|
"Statement": [...]
|
|
- pattern-inside: |
|
|
{..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...}
|
|
- pattern: |
|
|
"Principal": {..., "AWS": "*", ...}
|
|
message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone
|
|
with your AWS account ID and the name of the role can assume the role. Instead,
|
|
limit to a specific identity in your account, like this: `arn:aws:iam::<account_id>:root`.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-250: Execution with Unnecessary Privileges'
|
|
category: security
|
|
technology:
|
|
- aws
|
|
references:
|
|
- https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/
|
|
owasp:
|
|
- A06:2017 - Security Misconfiguration
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/json.aws.security.wildcard-assume-role.wildcard-assume-role
|
|
shortlink: https://sg.run/7YEZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15138
|
|
rv_id: 1263256
|
|
rule_id: JDULx5
|
|
version_id: BjTkZoy
|
|
url: https://semgrep.dev/playground/r/BjTkZoy/json.aws.security.wildcard-assume-role.wildcard-assume-role
|
|
origin: community
|
|
languages:
|
|
- json
|
|
severity: ERROR
|
|
- id: ruby.rails.security.injection.tainted-url-host.tainted-url-host
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
message: User data flows into the host portion of this manually-constructed URL.
|
|
This could allow an attacker to send data to their own server, potentially exposing
|
|
sensitive data such as cookies or authorization information sent with this request.
|
|
They could also probe internal servers or other resources that the server running
|
|
this code can access. (This is called server-side request forgery, or SSRF.) Do
|
|
not allow arbitrary hosts. Use the `ssrf_filter` gem and guard the url construction
|
|
with `SsrfFilter(...)`, or create an allowlist for approved hosts.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- rails
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
|
|
- https://github.com/arkadiyt/ssrf_filter
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-url-host.tainted-url-host
|
|
shortlink: https://sg.run/RX3g
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14705
|
|
rv_id: 1263668
|
|
rule_id: zdUY0W
|
|
version_id: 6xT29BN
|
|
url: https://semgrep.dev/playground/r/6xT29BN/ruby.rails.security.injection.tainted-url-host.tainted-url-host
|
|
origin: community
|
|
mode: taint
|
|
pattern-sanitizers:
|
|
- pattern: SsrfFilter
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: request
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
$URLSTR
|
|
- pattern-regex: \w+:\/\/#{.*}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: Kernel::sprintf("$URLSTR", ...)
|
|
- pattern: |
|
|
"$URLSTR" + $EXPR
|
|
- pattern: |
|
|
"$URLSTR" % $EXPR
|
|
- metavariable-pattern:
|
|
metavariable: $URLSTR
|
|
language: generic
|
|
pattern: $SCHEME:// ...
|
|
- id: terraform.aws.security.wildcard-assume-role.wildcard-assume-role
|
|
patterns:
|
|
- pattern-inside: |
|
|
resource "aws_iam_role" $NAME {
|
|
...
|
|
}
|
|
- pattern: assume_role_policy = "$STATEMENT"
|
|
- metavariable-pattern:
|
|
metavariable: $STATEMENT
|
|
language: json
|
|
patterns:
|
|
- pattern-inside: |
|
|
{..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...}
|
|
- pattern: |
|
|
"Principal": {..., "AWS": "*", ...}
|
|
message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone
|
|
with your AWS account ID and the name of the role can assume the role. Instead,
|
|
limit to a specific identity in your account, like this: `arn:aws:iam::<account_id>:root`.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-250: Execution with Unnecessary Privileges'
|
|
category: security
|
|
technology:
|
|
- aws
|
|
references:
|
|
- https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/
|
|
owasp:
|
|
- A06:2017 - Security Misconfiguration
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/terraform.aws.security.wildcard-assume-role.wildcard-assume-role
|
|
shortlink: https://sg.run/LXWr
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15139
|
|
rv_id: 1263749
|
|
rule_id: 5rUL1P
|
|
version_id: LjTkg8D
|
|
url: https://semgrep.dev/playground/r/LjTkg8D/terraform.aws.security.wildcard-assume-role.wildcard-assume-role
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy
|
|
message: 'Azure Storage currently supports three versions of the TLS protocol: 1.0,
|
|
1.1, and 1.2. Azure Storage uses TLS 1.2 on public HTTPS endpoints, but TLS 1.0
|
|
and TLS 1.1 are still supported for backward compatibility. This check will warn
|
|
if the minimum TLS is not set to TLS1_2.'
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
resource "azurerm_storage_account" "..." {
|
|
...
|
|
min_tls_version = "$ANYTHING"
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "azurerm_storage_account" "..." {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "azurerm_storage_account" "..." {
|
|
...
|
|
min_tls_version = "TLS1_2"
|
|
...
|
|
}
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#min_tls_version
|
|
- https://docs.microsoft.com/en-us/azure/storage/common/transport-layer-security-configure-minimum-version
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy
|
|
shortlink: https://sg.run/KXD7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15155
|
|
rv_id: 1263807
|
|
rule_id: AbUQdL
|
|
version_id: WrTqKpv
|
|
url: https://semgrep.dev/playground/r/WrTqKpv/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: scala.lang.security.audit.rsa-padding-set.rsa-padding-set
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-780: Use of RSA Algorithm without OAEP'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- scala
|
|
- cryptography
|
|
resources:
|
|
- https://blog.codacy.com/9-scala-security-issues/
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/scala.lang.security.audit.rsa-padding-set.rsa-padding-set
|
|
shortlink: https://sg.run/GO5p
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15192
|
|
rv_id: 1263677
|
|
rule_id: 3qUj1Q
|
|
version_id: yeTxpoX
|
|
url: https://semgrep.dev/playground/r/yeTxpoX/scala.lang.security.audit.rsa-padding-set.rsa-padding-set
|
|
origin: community
|
|
message: Usage of RSA without OAEP (Optimal Asymmetric Encryption Padding) may weaken
|
|
encryption. This could lead to sensitive data exposure. Instead, use RSA with
|
|
`OAEPWithMD5AndMGF1Padding` instead.
|
|
severity: WARNING
|
|
languages:
|
|
- scala
|
|
patterns:
|
|
- pattern: |
|
|
$VAR = $CIPHER.getInstance($MODE)
|
|
- metavariable-regex:
|
|
metavariable: $MODE
|
|
regex: .*RSA/.*/NoPadding.*
|
|
- id: typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption
|
|
message: 'Add "encryption: $Y.BucketEncryption.KMS_MANAGED" or "encryption: $Y.BucketEncryption.S3_MANAGED"
|
|
to the bucket props for Bucket construct $X'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-311: Missing Encryption of Sensitive Data'
|
|
category: security
|
|
technology:
|
|
- AWS-CDK
|
|
references:
|
|
- https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption
|
|
shortlink: https://sg.run/eowX
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15276
|
|
rv_id: 1263903
|
|
rule_id: bwU8qz
|
|
version_id: GxTkeRx
|
|
url: https://semgrep.dev/playground/r/GxTkeRx/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption
|
|
origin: community
|
|
languages:
|
|
- typescript
|
|
severity: ERROR
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import {Bucket} from '@aws-cdk/aws-s3'
|
|
...
|
|
- pattern: const $X = new Bucket(...)
|
|
- pattern-not: |
|
|
const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS_MANAGED, ...})
|
|
- pattern-not: |
|
|
const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS, ...})
|
|
- pattern-not: |
|
|
const $X = new Bucket(..., {..., encryption: BucketEncryption.S3_MANAGED, ...})
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import * as $Y from '@aws-cdk/aws-s3'
|
|
...
|
|
- pattern: const $X = new $Y.Bucket(...)
|
|
- pattern-not: |
|
|
const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS_MANAGED, ...})
|
|
- pattern-not: |
|
|
const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS, ...})
|
|
- pattern-not: |
|
|
const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.S3_MANAGED, ...})
|
|
- id: typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl
|
|
message: Bucket $X is not set to enforce encryption-in-transit, if not explictly
|
|
setting this on the bucket policy - the property "enforceSSL" should be set to
|
|
true
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
category: security
|
|
technology:
|
|
- AWS-CDK
|
|
references:
|
|
- https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl
|
|
shortlink: https://sg.run/vqBX
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15277
|
|
rv_id: 1263904
|
|
rule_id: NbUN8B
|
|
version_id: RGT0Llg
|
|
url: https://semgrep.dev/playground/r/RGT0Llg/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl
|
|
origin: community
|
|
languages:
|
|
- ts
|
|
severity: ERROR
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import {Bucket} from '@aws-cdk/aws-s3';
|
|
...
|
|
- pattern: const $X = new Bucket(...)
|
|
- pattern-not: |
|
|
const $X = new Bucket(..., {enforceSSL: true}, ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import * as $Y from '@aws-cdk/aws-s3';
|
|
...
|
|
- pattern: const $X = new $Y.Bucket(...)
|
|
- pattern-not: |
|
|
const $X = new $Y.Bucket(..., {..., enforceSSL: true, ...})
|
|
- id: typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue
|
|
message: 'Queue $X is missing encryption at rest. Add "encryption: $Y.QueueEncryption.KMS"
|
|
or "encryption: $Y.QueueEncryption.KMS_MANAGED" to the queue props to enable encryption
|
|
at rest for the queue.'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-311: Missing Encryption of Sensitive Data'
|
|
technology:
|
|
- AWS-CDK
|
|
references:
|
|
- https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-data-protection.html
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue
|
|
shortlink: https://sg.run/d23P
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15278
|
|
rv_id: 1263905
|
|
rule_id: kxUwqO
|
|
version_id: A8Tgd2W
|
|
url: https://semgrep.dev/playground/r/A8Tgd2W/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue
|
|
origin: community
|
|
languages:
|
|
- ts
|
|
severity: WARNING
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import {Queue} from '@aws-cdk/aws-sqs'
|
|
...
|
|
- pattern: const $X = new Queue(...)
|
|
- pattern-not: |
|
|
const $X = new Queue(..., {..., encryption: QueueEncryption.KMS_MANAGED, ...})
|
|
- pattern-not: |
|
|
const $X = new Queue(..., {..., encryption: QueueEncryption.KMS, ...})
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import * as $Y from '@aws-cdk/aws-sqs'
|
|
...
|
|
- pattern: const $X = new $Y.Queue(...)
|
|
- pattern-not: |
|
|
const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS_MANAGED, ...})
|
|
- pattern-not: |
|
|
const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS, ...})
|
|
- id: typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod
|
|
message: Using the GrantPublicAccess method on bucket contruct $X will make the
|
|
objects in the bucket world accessible. Verify if this is intentional.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-306: Missing Authentication for Critical Function'
|
|
category: security
|
|
technology:
|
|
- AWS-CDK
|
|
references:
|
|
- https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-overview.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod
|
|
shortlink: https://sg.run/Z4p7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15279
|
|
rv_id: 1263906
|
|
rule_id: wdUjZK
|
|
version_id: BjTkZA7
|
|
url: https://semgrep.dev/playground/r/BjTkZA7/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod
|
|
origin: community
|
|
languages:
|
|
- ts
|
|
severity: WARNING
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import {Bucket} from '@aws-cdk/aws-s3'
|
|
...
|
|
- pattern: |
|
|
const $X = new Bucket(...)
|
|
...
|
|
$X.grantPublicAccess(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import * as $Y from '@aws-cdk/aws-s3'
|
|
...
|
|
- pattern: |
|
|
const $X = new $Y.Bucket(...)
|
|
...
|
|
$X.grantPublicAccess(...)
|
|
- id: typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public
|
|
message: CodeBuild Project $X is set to have a public URL. This will make the build
|
|
results, logs, artifacts publically accessible, including builds prior to the
|
|
project being public. Ensure this is acceptable for the project.
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-306: Missing Authentication for Critical Function'
|
|
technology:
|
|
- AWS-CDK
|
|
references:
|
|
- https://docs.aws.amazon.com/codebuild/latest/userguide/public-builds.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public
|
|
shortlink: https://sg.run/nK7G
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15280
|
|
rv_id: 1263907
|
|
rule_id: x8UxXZ
|
|
version_id: DkTRbj1
|
|
url: https://semgrep.dev/playground/r/DkTRbj1/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public
|
|
origin: community
|
|
languages:
|
|
- ts
|
|
severity: WARNING
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import {Project} from '@aws-cdk/aws-codebuild'
|
|
...
|
|
- pattern: |
|
|
const $X = new Project(..., {..., badge: true, ...})
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import * as $Y from '@aws-cdk/aws-codebuild'
|
|
...
|
|
- pattern: |
|
|
const $X = new $Y.Project(..., {..., badge: true, ...})
|
|
- id: python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text
|
|
mode: taint
|
|
pattern-sinks:
|
|
- pattern: |
|
|
sqlalchemy.text(...)
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: |
|
|
$X + $Y
|
|
- metavariable-type:
|
|
metavariable: $X
|
|
type: string
|
|
- patterns:
|
|
- pattern: |
|
|
$X + $Y
|
|
- metavariable-type:
|
|
metavariable: $Y
|
|
type: string
|
|
- patterns:
|
|
- pattern: |
|
|
f"..."
|
|
- patterns:
|
|
- pattern: |
|
|
$X.format(...)
|
|
- metavariable-type:
|
|
metavariable: $X
|
|
type: string
|
|
- patterns:
|
|
- pattern: |
|
|
$X % $Y
|
|
- metavariable-type:
|
|
metavariable: $X
|
|
type: string
|
|
message: sqlalchemy.text passes the constructed SQL statement to the database mostly
|
|
unchanged. This means that the usual SQL injection protections are not applied
|
|
and this function is vulnerable to SQL injection if user input can reach here.
|
|
Use normal SQLAlchemy operators (such as `or_()`, `and_()`, etc.) to construct
|
|
SQL.
|
|
metadata:
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
category: security
|
|
technology:
|
|
- sqlalchemy
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text
|
|
shortlink: https://sg.run/yP1O
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15824
|
|
rv_id: 1263577
|
|
rule_id: r6U2wE
|
|
version_id: rxTAKqq
|
|
url: https://semgrep.dev/playground/r/rxTAKqq/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: password = "..."
|
|
- pattern-inside: |
|
|
resource "aws_db_instance" "..." {
|
|
...
|
|
}
|
|
- patterns:
|
|
- pattern: master_password = "..."
|
|
- pattern-inside: |
|
|
resource "aws_rds_cluster" "..." {
|
|
...
|
|
}
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
message: RDS instance or cluster with hardcoded credentials in source code. It is
|
|
recommended to pass the credentials at runtime, or generate random credentials
|
|
using the random_password resource.
|
|
metadata:
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/db_instance#master_password
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/rds_cluster#master_password
|
|
- https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/password
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
- secrets
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code
|
|
shortlink: https://sg.run/x4qA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15830
|
|
rv_id: 1263896
|
|
rule_id: OrUl6W
|
|
version_id: gETB77b
|
|
url: https://semgrep.dev/playground/r/gETB77b/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code
|
|
origin: community
|
|
- id: generic.ci.security.bash-reverse-shell.bash_reverse_shell
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
category: security
|
|
technology:
|
|
- ci
|
|
confidence: HIGH
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/generic.ci.security.bash-reverse-shell.bash_reverse_shell
|
|
shortlink: https://sg.run/4l9l
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 16200
|
|
rv_id: 1262664
|
|
rule_id: gxUJrJ
|
|
version_id: jQTn5QE
|
|
url: https://semgrep.dev/playground/r/jQTn5QE/generic.ci.security.bash-reverse-shell.bash_reverse_shell
|
|
origin: community
|
|
message: Semgrep found a bash reverse shell
|
|
severity: ERROR
|
|
languages:
|
|
- generic
|
|
pattern-either:
|
|
- pattern: |
|
|
sh -i >& /dev/udp/.../... 0>&1
|
|
- pattern: |
|
|
<...>/dev/tcp/.../...; sh <&... >&... 2>&
|
|
- pattern: |
|
|
<...>/dev/tcp/.../...; cat <&... | while read line; do $line 2>&... >&...;done
|
|
- pattern: |
|
|
sh -i ...<...> /dev/tcp/.../... ...<&... 1>&... 2>&
|
|
- id: terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket
|
|
patterns:
|
|
- pattern: a
|
|
- pattern: b
|
|
languages:
|
|
- hcl
|
|
severity: INFO
|
|
message: This rule has been deprecated, as all s3 buckets are encrypted by default
|
|
with no way to disable it. See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket_server_side_encryption_configuration
|
|
for more info.
|
|
metadata:
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#server_side_encryption_configuration
|
|
- https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-encryption.html
|
|
cwe:
|
|
- 'CWE-311: Missing Encryption of Sensitive Data'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
deprecated: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket
|
|
shortlink: https://sg.run/Jezw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 16202
|
|
rv_id: 1263901
|
|
rule_id: 3qU62L
|
|
version_id: JdTzxjN
|
|
url: https://semgrep.dev/playground/r/JdTzxjN/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket
|
|
origin: community
|
|
- id: php.lang.security.injection.tainted-filename.tainted-filename
|
|
severity: WARNING
|
|
message: File name based on user input risks server-side request forgery.
|
|
metadata:
|
|
technology:
|
|
- php
|
|
category: security
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/php.lang.security.injection.tainted-filename.tainted-filename
|
|
shortlink: https://sg.run/Ayqp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 16250
|
|
rv_id: 1263287
|
|
rule_id: 5rUpro
|
|
version_id: 7ZTE3J1
|
|
url: https://semgrep.dev/playground/r/7ZTE3J1/php.lang.security.injection.tainted-filename.tainted-filename
|
|
origin: community
|
|
languages:
|
|
- php
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
- pattern: $_COOKIE
|
|
- pattern: $_REQUEST
|
|
- pattern: $_SERVER
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: basename($PATH, ...)
|
|
- pattern-inside: linkinfo($PATH, ...)
|
|
- pattern-inside: readlink($PATH, ...)
|
|
- pattern-inside: realpath($PATH, ...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: opcache_compile_file($FILENAME, ...)
|
|
- pattern-inside: opcache_invalidate($FILENAME, ...)
|
|
- pattern-inside: opcache_is_script_cached($FILENAME, ...)
|
|
- pattern-inside: runkit7_import($FILENAME, ...)
|
|
- pattern-inside: readline_read_history($FILENAME, ...)
|
|
- pattern-inside: readline_write_history($FILENAME, ...)
|
|
- pattern-inside: rar_open($FILENAME, ...)
|
|
- pattern-inside: zip_open($FILENAME, ...)
|
|
- pattern-inside: gzfile($FILENAME, ...)
|
|
- pattern-inside: gzopen($FILENAME, ...)
|
|
- pattern-inside: readgzfile($FILENAME, ...)
|
|
- pattern-inside: hash_file($ALGO, $FILENAME, ...)
|
|
- pattern-inside: hash_update_file($CONTEXT, $FILENAME, ...)
|
|
- pattern-inside: pg_trace($FILENAME, ...)
|
|
- pattern-inside: dio_open($FILENAME, ...)
|
|
- pattern-inside: finfo_file($FINFO, $FILENAME, ...)
|
|
- pattern-inside: mime_content_type($FILENAME, ...)
|
|
- pattern-inside: chgrp($FILENAME, ...)
|
|
- pattern-inside: chmod($FILENAME, ...)
|
|
- pattern-inside: chown($FILENAME, ...)
|
|
- pattern-inside: clearstatcache($CLEAR_REALPATH_CACHE, $FILENAME, ...)
|
|
- pattern-inside: file_exists($FILENAME, ...)
|
|
- pattern-inside: file_get_contents($FILENAME, ...)
|
|
- pattern-inside: file_put_contents($FILENAME, ...)
|
|
- pattern-inside: file($FILENAME, ...)
|
|
- pattern-inside: fileatime($FILENAME, ...)
|
|
- pattern-inside: filectime($FILENAME, ...)
|
|
- pattern-inside: filegroup($FILENAME, ...)
|
|
- pattern-inside: fileinode($FILENAME, ...)
|
|
- pattern-inside: filemtime($FILENAME, ...)
|
|
- pattern-inside: fileowner($FILENAME, ...)
|
|
- pattern-inside: fileperms($FILENAME, ...)
|
|
- pattern-inside: filesize($FILENAME, ...)
|
|
- pattern-inside: filetype($FILENAME, ...)
|
|
- pattern-inside: fnmatch($PATTERN, $FILENAME, ...)
|
|
- pattern-inside: fopen($FILENAME, ...)
|
|
- pattern-inside: is_dir($FILENAME, ...)
|
|
- pattern-inside: is_executable($FILENAME, ...)
|
|
- pattern-inside: is_file($FILENAME, ...)
|
|
- pattern-inside: is_link($FILENAME, ...)
|
|
- pattern-inside: is_readable($FILENAME, ...)
|
|
- pattern-inside: is_uploaded_file($FILENAME, ...)
|
|
- pattern-inside: is_writable($FILENAME, ...)
|
|
- pattern-inside: lchgrp($FILENAME, ...)
|
|
- pattern-inside: lchown($FILENAME, ...)
|
|
- pattern-inside: lstat($FILENAME, ...)
|
|
- pattern-inside: parse_ini_file($FILENAME, ...)
|
|
- pattern-inside: readfile($FILENAME, ...)
|
|
- pattern-inside: stat($FILENAME, ...)
|
|
- pattern-inside: touch($FILENAME, ...)
|
|
- pattern-inside: unlink($FILENAME, ...)
|
|
- pattern-inside: xattr_get($FILENAME, ...)
|
|
- pattern-inside: xattr_list($FILENAME, ...)
|
|
- pattern-inside: xattr_remove($FILENAME, ...)
|
|
- pattern-inside: xattr_set($FILENAME, ...)
|
|
- pattern-inside: xattr_supported($FILENAME, ...)
|
|
- pattern-inside: enchant_broker_request_pwl_dict($BROKER, $FILENAME, ...)
|
|
- pattern-inside: pspell_config_personal($CONFIG, $FILENAME, ...)
|
|
- pattern-inside: pspell_config_repl($CONFIG, $FILENAME, ...)
|
|
- pattern-inside: pspell_new_personal($FILENAME, ...)
|
|
- pattern-inside: exif_imagetype($FILENAME, ...)
|
|
- pattern-inside: getimagesize($FILENAME, ...)
|
|
- pattern-inside: image2wbmp($IMAGE, $FILENAME, ...)
|
|
- pattern-inside: imagecreatefromavif($FILENAME, ...)
|
|
- pattern-inside: imagecreatefrombmp($FILENAME, ...)
|
|
- pattern-inside: imagecreatefromgd2($FILENAME, ...)
|
|
- pattern-inside: imagecreatefromgd2part($FILENAME, ...)
|
|
- pattern-inside: imagecreatefromgd($FILENAME, ...)
|
|
- pattern-inside: imagecreatefromgif($FILENAME, ...)
|
|
- pattern-inside: imagecreatefromjpeg($FILENAME, ...)
|
|
- pattern-inside: imagecreatefrompng($FILENAME, ...)
|
|
- pattern-inside: imagecreatefromtga($FILENAME, ...)
|
|
- pattern-inside: imagecreatefromwbmp($FILENAME, ...)
|
|
- pattern-inside: imagecreatefromwebp($FILENAME, ...)
|
|
- pattern-inside: imagecreatefromxbm($FILENAME, ...)
|
|
- pattern-inside: imagecreatefromxpm($FILENAME, ...)
|
|
- pattern-inside: imageloadfont($FILENAME, ...)
|
|
- pattern-inside: imagexbm($IMAGE, $FILENAME, ...)
|
|
- pattern-inside: iptcembed($IPTC_DATA, $FILENAME, ...)
|
|
- pattern-inside: mailparse_msg_extract_part_file($MIMEMAIL, $FILENAME, ...)
|
|
- pattern-inside: mailparse_msg_extract_whole_part_file($MIMEMAIL, $FILENAME,
|
|
...)
|
|
- pattern-inside: mailparse_msg_parse_file($FILENAME, ...)
|
|
- pattern-inside: fdf_add_template($FDF_DOCUMENT, $NEWPAGE, $FILENAME, ...)
|
|
- pattern-inside: fdf_get_ap($FDF_DOCUMENT, $FIELD, $FACE, $FILENAME, ...)
|
|
- pattern-inside: fdf_open($FILENAME, ...)
|
|
- pattern-inside: fdf_save($FDF_DOCUMENT, $FILENAME, ...)
|
|
- pattern-inside: fdf_set_ap($FDF_DOCUMENT, $FIELD_NAME, $FACE, $FILENAME, ...)
|
|
- pattern-inside: ps_add_launchlink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME,
|
|
...)
|
|
- pattern-inside: ps_add_pdflink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME,
|
|
...)
|
|
- pattern-inside: ps_open_file($PSDOC, $FILENAME, ...)
|
|
- pattern-inside: ps_open_image_file($PSDOC, $TYPE, $FILENAME, ...)
|
|
- pattern-inside: posix_access($FILENAME, ...)
|
|
- pattern-inside: posix_mkfifo($FILENAME, ...)
|
|
- pattern-inside: posix_mknod($FILENAME, ...)
|
|
- pattern-inside: ftok($FILENAME, ...)
|
|
- pattern-inside: fann_cascadetrain_on_file($ANN, $FILENAME, ...)
|
|
- pattern-inside: fann_read_train_from_file($FILENAME, ...)
|
|
- pattern-inside: fann_train_on_file($ANN, $FILENAME, ...)
|
|
- pattern-inside: highlight_file($FILENAME, ...)
|
|
- pattern-inside: php_strip_whitespace($FILENAME, ...)
|
|
- pattern-inside: stream_resolve_include_path($FILENAME, ...)
|
|
- pattern-inside: swoole_async_read($FILENAME, ...)
|
|
- pattern-inside: swoole_async_readfile($FILENAME, ...)
|
|
- pattern-inside: swoole_async_write($FILENAME, ...)
|
|
- pattern-inside: swoole_async_writefile($FILENAME, ...)
|
|
- pattern-inside: swoole_load_module($FILENAME, ...)
|
|
- pattern-inside: tidy_parse_file($FILENAME, ...)
|
|
- pattern-inside: tidy_repair_file($FILENAME, ...)
|
|
- pattern-inside: get_meta_tags($FILENAME, ...)
|
|
- pattern-inside: yaml_emit_file($FILENAME, ...)
|
|
- pattern-inside: yaml_parse_file($FILENAME, ...)
|
|
- pattern-inside: curl_file_create($FILENAME, ...)
|
|
- pattern-inside: ftp_chmod($FTP, $PERMISSIONS, $FILENAME, ...)
|
|
- pattern-inside: ftp_delete($FTP, $FILENAME, ...)
|
|
- pattern-inside: ftp_mdtm($FTP, $FILENAME, ...)
|
|
- pattern-inside: ftp_size($FTP, $FILENAME, ...)
|
|
- pattern-inside: rrd_create($FILENAME, ...)
|
|
- pattern-inside: rrd_fetch($FILENAME, ...)
|
|
- pattern-inside: rrd_graph($FILENAME, ...)
|
|
- pattern-inside: rrd_info($FILENAME, ...)
|
|
- pattern-inside: rrd_last($FILENAME, ...)
|
|
- pattern-inside: rrd_lastupdate($FILENAME, ...)
|
|
- pattern-inside: rrd_tune($FILENAME, ...)
|
|
- pattern-inside: rrd_update($FILENAME, ...)
|
|
- pattern-inside: snmp_read_mib($FILENAME, ...)
|
|
- pattern-inside: ssh2_sftp_chmod($SFTP, $FILENAME, ...)
|
|
- pattern-inside: ssh2_sftp_realpath($SFTP, $FILENAME, ...)
|
|
- pattern-inside: ssh2_sftp_unlink($SFTP, $FILENAME, ...)
|
|
- pattern-inside: apache_lookup_uri($FILENAME, ...)
|
|
- pattern-inside: md5_file($FILENAME, ...)
|
|
- pattern-inside: sha1_file($FILENAME, ...)
|
|
- pattern-inside: simplexml_load_file($FILENAME, ...)
|
|
- pattern: $FILENAME
|
|
- id: php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation
|
|
languages:
|
|
- php
|
|
severity: WARNING
|
|
message: <- A new object is created where the class name is based on user input.
|
|
This could lead to remote code execution, as it allows to instantiate any class
|
|
in the application.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-470: Use of Externally-Controlled Input to Select Classes or Code (''Unsafe
|
|
Reflection'')'
|
|
category: security
|
|
technology:
|
|
- php
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation
|
|
shortlink: https://sg.run/7ndw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 16438
|
|
rv_id: 1263288
|
|
rule_id: v8U4DA
|
|
version_id: LjTkgLy
|
|
url: https://semgrep.dev/playground/r/LjTkgLy/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
- pattern: $_COOKIE
|
|
- pattern: $_REQUEST
|
|
- pattern: $_SERVER
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: new $SINK(...)
|
|
- pattern: $SINK
|
|
- id: terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials
|
|
patterns:
|
|
- pattern-inside: |
|
|
provider "aws" {
|
|
...
|
|
secret_key = "$SECRET"
|
|
}
|
|
- focus-metavariable: $SECRET
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
technology:
|
|
- secrets
|
|
- aws
|
|
- terraform
|
|
category: security
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials
|
|
shortlink: https://sg.run/L3kn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 16439
|
|
rv_id: 1263735
|
|
rule_id: d8U4n0
|
|
version_id: rxTAK76
|
|
url: https://semgrep.dev/playground/r/rxTAK76/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials
|
|
origin: community
|
|
- id: php.laravel.security.laravel-sql-injection.laravel-sql-injection
|
|
metadata:
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
category: security
|
|
technology:
|
|
- laravel
|
|
references:
|
|
- https://laravel.com/docs/8.x/queries
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/php.laravel.security.laravel-sql-injection.laravel-sql-injection
|
|
shortlink: https://sg.run/x40p
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 16830
|
|
rv_id: 1263313
|
|
rule_id: j2UQdp
|
|
version_id: BjTkZ45
|
|
url: https://semgrep.dev/playground/r/BjTkZ45/php.laravel.security.laravel-sql-injection.laravel-sql-injection
|
|
origin: community
|
|
severity: WARNING
|
|
message: Detected a SQL query based on user input. This could lead to SQL injection,
|
|
which could potentially result in sensitive data being exfiltrated by attackers.
|
|
Instead, use parameterized queries and prepared statements.
|
|
languages:
|
|
- php
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
- pattern: $_COOKIE
|
|
- pattern: $_REQUEST
|
|
- pattern: $_SERVER
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: $SQL
|
|
- pattern-either:
|
|
- pattern-inside: DB::table(...)->whereRaw($SQL, ...)
|
|
- pattern-inside: DB::table(...)->orWhereRaw($SQL, ...)
|
|
- pattern-inside: DB::table(...)->groupByRaw($SQL, ...)
|
|
- pattern-inside: DB::table(...)->havingRaw($SQL, ...)
|
|
- pattern-inside: DB::table(...)->orHavingRaw($SQL, ...)
|
|
- pattern-inside: DB::table(...)->orderByRaw($SQL, ...)
|
|
- patterns:
|
|
- pattern: $EXPRESSION
|
|
- pattern-either:
|
|
- pattern-inside: DB::table(...)->selectRaw($EXPRESSION, ...)
|
|
- pattern-inside: DB::table(...)->fromRaw($EXPRESSION, ...)
|
|
- patterns:
|
|
- pattern: $COLUMNS
|
|
- pattern-either:
|
|
- pattern-inside: DB::table(...)->whereNull($COLUMNS, ...)
|
|
- pattern-inside: DB::table(...)->orWhereNull($COLUMN)
|
|
- pattern-inside: DB::table(...)->whereNotNull($COLUMNS, ...)
|
|
- pattern-inside: DB::table(...)->whereRowValues($COLUMNS, ...)
|
|
- pattern-inside: DB::table(...)->orWhereRowValues($COLUMNS, ...)
|
|
- pattern-inside: DB::table(...)->find($ID, $COLUMNS)
|
|
- pattern-inside: DB::table(...)->paginate($PERPAGE, $COLUMNS, ...)
|
|
- pattern-inside: DB::table(...)->simplePaginate($PERPAGE, $COLUMNS, ...)
|
|
- pattern-inside: DB::table(...)->cursorPaginate($PERPAGE, $COLUMNS, ...)
|
|
- pattern-inside: DB::table(...)->getCountForPagination($COLUMNS)
|
|
- pattern-inside: DB::table(...)->aggregate($FUNCTION, $COLUMNS)
|
|
- pattern-inside: DB::table(...)->numericAggregate($FUNCTION, $COLUMNS)
|
|
- pattern-inside: DB::table(...)->insertUsing($COLUMNS, ...)
|
|
- pattern-inside: DB::table(...)->select($COLUMNS)
|
|
- pattern-inside: DB::table(...)->get($COLUMNS)
|
|
- pattern-inside: DB::table(...)->count($COLUMNS)
|
|
- patterns:
|
|
- pattern: $COLUMN
|
|
- pattern-either:
|
|
- pattern-inside: DB::table(...)->whereIn($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereIn($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereNotIn($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereNotIn($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereIntegerInRaw($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereIntegerInRaw($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereIntegerNotInRaw($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereIntegerNotInRaw($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereBetweenColumns($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereBetween($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereBetweenColumns($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereNotBetween($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereNotBetweenColumns($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereNotBetween($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereNotBetweenColumns($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereNotNull($COLUMN)
|
|
- pattern-inside: DB::table(...)->whereDate($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereDate($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereTime($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereTime($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereDay($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereDay($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereMonth($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereMonth($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereYear($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereYear($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereJsonContains($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereJsonContains($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereJsonDoesntContain($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereJsonDoesntContain($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->whereJsonLength($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhereJsonLength($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->having($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orHaving($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->havingBetween($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orderBy($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orderByDesc($COLUMN)
|
|
- pattern-inside: DB::table(...)->latest($COLUMN)
|
|
- pattern-inside: DB::table(...)->oldest($COLUMN)
|
|
- pattern-inside: DB::table(...)->forPageBeforeId($PERPAGE, $LASTID, $COLUMN)
|
|
- pattern-inside: DB::table(...)->forPageAfterId($PERPAGE, $LASTID, $COLUMN)
|
|
- pattern-inside: DB::table(...)->value($COLUMN)
|
|
- pattern-inside: DB::table(...)->pluck($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->implode($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->min($COLUMN)
|
|
- pattern-inside: DB::table(...)->max($COLUMN)
|
|
- pattern-inside: DB::table(...)->sum($COLUMN)
|
|
- pattern-inside: DB::table(...)->avg($COLUMN)
|
|
- pattern-inside: DB::table(...)->average($COLUMN)
|
|
- pattern-inside: DB::table(...)->increment($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->decrement($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->where($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->orWhere($COLUMN, ...)
|
|
- pattern-inside: DB::table(...)->addSelect($COLUMN)
|
|
- patterns:
|
|
- pattern: $QUERY
|
|
- pattern-inside: DB::unprepared($QUERY)
|
|
- id: java.lang.security.audit.crypto.use-of-md5.use-of-md5
|
|
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use HMAC
|
|
instead.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::java.security
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5.use-of-md5
|
|
shortlink: https://sg.run/ryJn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17325
|
|
rv_id: 1263013
|
|
rule_id: KxU5lW
|
|
version_id: 0bTKzGX
|
|
url: https://semgrep.dev/playground/r/0bTKzGX/java.lang.security.audit.crypto.use-of-md5.use-of-md5
|
|
origin: community
|
|
patterns:
|
|
- pattern: |
|
|
java.security.MessageDigest.getInstance($ALGO, ...);
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: (?i)(.MD5.)
|
|
- focus-metavariable: $ALGO
|
|
fix: |
|
|
"SHA-512"
|
|
- id: java.lang.security.audit.crypto.use-of-sha1.use-of-sha1
|
|
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
|
|
collision resistant and is therefore not suitable as a cryptographic signature.
|
|
Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function
|
|
applications.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::javax.crypto
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1
|
|
shortlink: https://sg.run/bXNp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17326
|
|
rv_id: 1263016
|
|
rule_id: qNUWNn
|
|
version_id: l4TJRpL
|
|
url: https://semgrep.dev/playground/r/l4TJRpL/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1
|
|
origin: community
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
java.security.MessageDigest.getInstance("$ALGO", ...);
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: (SHA1|SHA-1)
|
|
- pattern: |
|
|
$DU.getSha1Digest().digest(...)
|
|
- id: terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_cloudfront_distribution" $ANYTHING {
|
|
...
|
|
viewer_certificate {
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_cloudfront_distribution" $ANYTHING {
|
|
...
|
|
viewer_certificate {
|
|
...
|
|
minimum_protocol_version = "TLSv1.2_2018"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_cloudfront_distribution" $ANYTHING {
|
|
...
|
|
viewer_certificate {
|
|
...
|
|
minimum_protocol_version = "TLSv1.2_2019"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_cloudfront_distribution" $ANYTHING {
|
|
...
|
|
viewer_certificate {
|
|
...
|
|
minimum_protocol_version = "TLSv1.2_2021"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_cloudfront_distribution" $ANYTHING {
|
|
...
|
|
viewer_certificate {
|
|
...
|
|
minimum_protocol_version = "TLSv1.2_2025"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_cloudfront_distribution" $ANYTHING {
|
|
...
|
|
viewer_certificate {
|
|
...
|
|
minimum_protocol_version = "TLSv1.3_2025"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
message: Detected an AWS CloudFront Distribution with an insecure TLS version. TLS
|
|
versions less than 1.2 are considered insecure because they can be broken. To
|
|
fix this, set your `minimum_protocol_version` to `"TLSv1.2_2018", "TLSv1.2_2019",
|
|
"TLSv1.2_2021", "TLSv1.2_2025" or "TLSv1.3_2025"`.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version
|
|
shortlink: https://sg.run/Q6o4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17342
|
|
rv_id: 1263700
|
|
rule_id: kxU6A8
|
|
version_id: 5PTo1bY
|
|
url: https://semgrep.dev/playground/r/5PTo1bY/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_cloudwatch_log_group" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_cloudwatch_log_group" $ANYTHING {
|
|
...
|
|
retention_in_days = ...
|
|
...
|
|
}
|
|
message: The AWS CloudWatch Log Group has no retention. Missing retention in log
|
|
groups can cause losing important event information.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
cwe:
|
|
- 'CWE-320: CWE CATEGORY: Key Management Errors'
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
category: security
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention
|
|
shortlink: https://sg.run/4lwl
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17344
|
|
rv_id: 946665
|
|
rule_id: x8UGBG
|
|
version_id: BjT1N2B
|
|
url: https://semgrep.dev/playground/r/BjT1N2B/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention
|
|
origin: community
|
|
- id: terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_codebuild_project" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_codebuild_project" $ANYTHING {
|
|
...
|
|
encryption_key = ...
|
|
...
|
|
}
|
|
message: The AWS CodeBuild Project is unencrypted. The AWS KMS encryption key protects
|
|
projects in the CodeBuild. To create your own, create a aws_kms_key resource or
|
|
use the ARN string of a key in your account.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
cwe:
|
|
- 'CWE-320: CWE CATEGORY: Key Management Errors'
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
category: security
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted
|
|
shortlink: https://sg.run/5yxA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17347
|
|
rv_id: 946669
|
|
rule_id: v8U4kG
|
|
version_id: K3TJbNr
|
|
url: https://semgrep.dev/playground/r/K3TJbNr/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted
|
|
origin: community
|
|
- id: terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_db_instance" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_db_instance" $ANYTHING {
|
|
...
|
|
enabled_cloudwatch_logs_exports = [$SOMETHING, ...]
|
|
...
|
|
}
|
|
message: Database instance has no logging. Missing logs can cause missing important
|
|
event information.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
cwe:
|
|
- 'CWE-311: Missing Encryption of Sensitive Data'
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
category: security
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging
|
|
shortlink: https://sg.run/GyAp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17348
|
|
rv_id: 1263704
|
|
rule_id: d8U4RA
|
|
version_id: BjTkZ6j
|
|
url: https://semgrep.dev/playground/r/BjTkZ6j/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging
|
|
origin: community
|
|
- id: terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_dynamodb_table" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_dynamodb_table" $ANYTHING {
|
|
...
|
|
server_side_encryption {
|
|
enabled = true
|
|
kms_key_arn = ...
|
|
}
|
|
...
|
|
}
|
|
message: By default, AWS DynamoDB Table is encrypted using AWS-managed keys. However,
|
|
for added security, it's recommended to configure your own AWS KMS encryption
|
|
key to protect your data in the DynamoDB table. You can either create a new aws_kms_key
|
|
resource or use the ARN of an existing key in your AWS account to do so.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
category: security
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted
|
|
shortlink: https://sg.run/Ay4p
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17350
|
|
rv_id: 1263707
|
|
rule_id: nJUGe2
|
|
version_id: 0bTKzj8
|
|
url: https://semgrep.dev/playground/r/0bTKzj8/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted
|
|
origin: community
|
|
- id: terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_ebs_snapshot_copy" $ANYTHING {
|
|
...
|
|
encrypted = true
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_ebs_snapshot_copy" $ANYTHING {
|
|
...
|
|
encrypted = true
|
|
kms_key_id = ...
|
|
...
|
|
}
|
|
message: Ensure EBS Snapshot is encrypted at rest using KMS CMKs. CMKs gives you
|
|
control over the encryption key in terms of access and rotation.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
cwe:
|
|
- 'CWE-320: CWE CATEGORY: Key Management Errors'
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk
|
|
shortlink: https://sg.run/ByPW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17351
|
|
rv_id: 946677
|
|
rule_id: EwUqko
|
|
version_id: A8TJzb0
|
|
url: https://semgrep.dev/playground/r/A8TJzb0/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_ebs_encryption_by_default" $ANYTHING {
|
|
...
|
|
enabled = false
|
|
...
|
|
}
|
|
message: The AWS EBS is unencrypted. The AWS EBS encryption protects data in the
|
|
EBS.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
cwe:
|
|
- 'CWE-320: CWE CATEGORY: Key Management Errors'
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
category: security
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted
|
|
shortlink: https://sg.run/Dy5Y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17352
|
|
rv_id: 946678
|
|
rule_id: 7KUW7K
|
|
version_id: BjT1N2v
|
|
url: https://semgrep.dev/playground/r/BjT1N2v/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted
|
|
origin: community
|
|
- id: terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
resource "aws_instance" $ANYTHING {
|
|
...
|
|
associate_public_ip_address = true
|
|
...
|
|
}
|
|
- pattern: |
|
|
resource "aws_launch_template" $ANYTHING {
|
|
...
|
|
network_interfaces {
|
|
...
|
|
associate_public_ip_address = true
|
|
...
|
|
}
|
|
...
|
|
}
|
|
message: EC2 instances should not have a public IP address attached in order to
|
|
block public access to the instances. To fix this, set your `associate_public_ip_address`
|
|
to `"false"`.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-1220: Insufficient Granularity of Access Control'
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip
|
|
shortlink: https://sg.run/08rv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17354
|
|
rv_id: 1263709
|
|
rule_id: 8GUA2n
|
|
version_id: qkTR73G
|
|
url: https://semgrep.dev/playground/r/qkTR73G/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_efs_file_system" $ANYTHING {
|
|
...
|
|
encrypted = true
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_efs_file_system" $ANYTHING {
|
|
...
|
|
encrypted = true
|
|
kms_key_id = ...
|
|
...
|
|
}
|
|
message: Ensure EFS filesystem is encrypted at rest using KMS CMKs. CMKs gives you
|
|
control over the encryption key in terms of access and rotation.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
cwe:
|
|
- 'CWE-320: CWE CATEGORY: Key Management Errors'
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk
|
|
shortlink: https://sg.run/Kk07
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17355
|
|
rv_id: 946690
|
|
rule_id: gxUJ4n
|
|
version_id: 2KTYbWy
|
|
url: https://semgrep.dev/playground/r/2KTYbWy/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
resource "aws_elasticsearch_domain" $ANYTHING {
|
|
...
|
|
node_to_node_encryption {
|
|
...
|
|
enabled = false
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: |
|
|
resource "aws_elasticsearch_domain" $ANYTHING {
|
|
...
|
|
cluster_config {
|
|
...
|
|
instance_count = $COUNT
|
|
...
|
|
}
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_elasticsearch_domain" $ANYTHING {
|
|
...
|
|
cluster_config {
|
|
...
|
|
instance_count = $COUNT
|
|
...
|
|
}
|
|
node_to_node_encryption {
|
|
...
|
|
enabled = true
|
|
...
|
|
}
|
|
}
|
|
- metavariable-comparison:
|
|
metavariable: $COUNT
|
|
comparison: $COUNT > 1
|
|
message: "Ensure all Elasticsearch has node-to-node encryption enabled.\t"
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled
|
|
shortlink: https://sg.run/lp3y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17357
|
|
rv_id: 1263719
|
|
rule_id: 3qU6J7
|
|
version_id: WrTqK0v
|
|
url: https://semgrep.dev/playground/r/WrTqK0v/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal
|
|
patterns:
|
|
- pattern-inside: |
|
|
resource "aws_glacier_vault" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern: access_policy = "$STATEMENT"
|
|
- metavariable-pattern:
|
|
metavariable: $STATEMENT
|
|
language: json
|
|
patterns:
|
|
- pattern-inside: |
|
|
{..., "Effect": "Allow", ...}
|
|
- pattern-either:
|
|
- pattern: |
|
|
"Principal": "*"
|
|
- pattern: |
|
|
"Principal": {..., "AWS": "*", ...}
|
|
- pattern-inside: |
|
|
"Principal": {..., "AWS": ..., ...}
|
|
- pattern-regex: |
|
|
(^\"arn:aws:iam::\*:(.*)\"$)
|
|
message: 'Detected wildcard access granted to Glacier Vault. This means anyone within
|
|
your AWS account ID can perform actions on Glacier resources. Instead, limit to
|
|
a specific identity in your account, like this: `arn:aws:iam::<account_id>:<identity>`.'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- aws
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/732.html
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal
|
|
shortlink: https://sg.run/XN9K
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17364
|
|
rv_id: 1263723
|
|
rule_id: AbUeYK
|
|
version_id: l4TJRGB
|
|
url: https://semgrep.dev/playground/r/l4TJRGB/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin
|
|
patterns:
|
|
- pattern-inside: |
|
|
resource "aws_ssoadmin_permission_set_inline_policy" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern: inline_policy = "$STATEMENT"
|
|
- metavariable-pattern:
|
|
metavariable: $STATEMENT
|
|
language: json
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
{..., "Effect": "Deny", ...}
|
|
- pattern-either:
|
|
- pattern: |
|
|
{..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...}
|
|
- pattern: |
|
|
{..., "Action": "*", "Resource": "*", ...}
|
|
- pattern: |
|
|
{..., "Action": "*", "Resource": [...], ...}
|
|
- pattern: |
|
|
{..., "Action": [...], "Resource": "*", ...}
|
|
message: Detected admin access granted in your policy. This means anyone with this
|
|
policy can perform administrative actions. Instead, limit actions and resources
|
|
to what you need according to least privilege.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- aws
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/732.html
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin
|
|
shortlink: https://sg.run/jzgY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17365
|
|
rv_id: 1263724
|
|
rule_id: BYUzY5
|
|
version_id: YDTZe9q
|
|
url: https://semgrep.dev/playground/r/YDTZe9q/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy
|
|
patterns:
|
|
- pattern-inside: |
|
|
resource "aws_iam_policy" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern: policy = "$STATEMENT"
|
|
- metavariable-pattern:
|
|
metavariable: $STATEMENT
|
|
language: json
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
{..., "Effect": "Deny", ...}
|
|
- pattern-either:
|
|
- pattern: |
|
|
{..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...}
|
|
- pattern: |
|
|
{..., "Action": "*", "Resource": "*", ...}
|
|
- pattern: |
|
|
{..., "Action": "*", "Resource": [...], ...}
|
|
- pattern: |
|
|
{..., "Action": [...], "Resource": "*", ...}
|
|
message: Detected admin access granted in your policy. This means anyone with this
|
|
policy can perform administrative actions. Instead, limit actions and resources
|
|
to what you need according to least privilege.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/732.html
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy
|
|
shortlink: https://sg.run/1zbw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17366
|
|
rv_id: 1263725
|
|
rule_id: DbUx8l
|
|
version_id: 6xT29Pv
|
|
url: https://semgrep.dev/playground/r/6xT29Pv/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_redshift_parameter_group" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_redshift_parameter_group" $ANYTHING {
|
|
...
|
|
parameter {
|
|
name = "require_ssl"
|
|
value = "true"
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_redshift_parameter_group" $ANYTHING {
|
|
...
|
|
parameter {
|
|
name = "require_ssl"
|
|
value = true
|
|
}
|
|
...
|
|
}
|
|
message: Detected an AWS Redshift configuration with a SSL disabled. To fix this,
|
|
set your `require_ssl` to `"true"`.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration
|
|
shortlink: https://sg.run/yPYx
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17368
|
|
rv_id: 1263727
|
|
rule_id: 0oUrOj
|
|
version_id: zyTb27A
|
|
url: https://semgrep.dev/playground/r/zyTb27A/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal
|
|
patterns:
|
|
- pattern-inside: |
|
|
resource "aws_kms_key" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern: policy = "$STATEMENT"
|
|
- metavariable-pattern:
|
|
metavariable: $STATEMENT
|
|
language: json
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
{..., "Effect": "Deny", ...}
|
|
- pattern-either:
|
|
- pattern: |
|
|
{..., "Principal": "*", "Action": "kms:*", "Resource": "*", ...}
|
|
- pattern: |
|
|
{..., "Principal": [..., "*", ...], "Action": "kms:*", "Resource": "*", ...}
|
|
- pattern: |
|
|
{..., "Principal": { "AWS": "*" }, "Action": "kms:*", "Resource": "*", ...}
|
|
- pattern: |
|
|
{..., "Principal": { "AWS": [..., "*", ...] }, "Action": "kms:*", "Resource": "*", ...}
|
|
message: Detected wildcard access granted in your KMS key. This means anyone with
|
|
this policy can perform administrative actions over the keys. Instead, limit principals,
|
|
actions and resources to what you need according to least privilege.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/732.html
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal
|
|
shortlink: https://sg.run/Nwlp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17371
|
|
rv_id: 1263729
|
|
rule_id: lBUWPD
|
|
version_id: 2KTv2J4
|
|
url: https://semgrep.dev/playground/r/2KTv2J4/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
resource "aws_kms_key" $ANYTHING {
|
|
...
|
|
enable_key_rotation = false
|
|
...
|
|
}
|
|
- pattern: |
|
|
resource "aws_kms_key" $ANYTHING {
|
|
...
|
|
customer_master_key_spec = "SYMMETRIC_DEFAULT"
|
|
enable_key_rotation = false
|
|
...
|
|
}
|
|
- pattern: |
|
|
resource "aws_kms_key" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_kms_key" $ANYTHING {
|
|
...
|
|
enable_key_rotation = true
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_kms_key" $ANYTHING {
|
|
...
|
|
customer_master_key_spec = "RSA_2096"
|
|
...
|
|
}
|
|
message: The AWS KMS has no rotation. Missing rotation can cause leaked key to be
|
|
used by attackers. To fix this, set a `enable_key_rotation`.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
category: security
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation
|
|
shortlink: https://sg.run/kz47
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17372
|
|
rv_id: 1263730
|
|
rule_id: PeU0L3
|
|
version_id: X0Tzy67
|
|
url: https://semgrep.dev/playground/r/X0Tzy67/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation
|
|
origin: community
|
|
- id: terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials
|
|
patterns:
|
|
- pattern-inside: |
|
|
resource "$ANYTING" $ANYTHING {
|
|
...
|
|
environment {
|
|
variables = {
|
|
...
|
|
}
|
|
}
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
AWS_ACCESS_KEY_ID = "$Y"
|
|
- pattern-regex: |
|
|
(?<![A-Z0-9])[A-Z0-9]{20}(?![A-Z0-9])
|
|
- pattern-inside: |
|
|
AWS_SECRET_ACCESS_KEY = "$Y"
|
|
- pattern-regex: |
|
|
(?<![A-Za-z0-9/+=])[A-Za-z0-9/+=]{40}(?![A-Za-z0-9/+=])
|
|
- focus-metavariable: $Y
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
metadata:
|
|
category: security
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
- secrets
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials
|
|
shortlink: https://sg.run/wZqY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17373
|
|
rv_id: 1263731
|
|
rule_id: JDU6gj
|
|
version_id: jQTn573
|
|
url: https://semgrep.dev/playground/r/jQTn573/terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: terraform.aws.security.aws-rds-backup-no-retention.aws-rds-backup-no-retention
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
resource "aws_rds_cluster" $ANYTHING {
|
|
...
|
|
backup_retention_period = 0
|
|
...
|
|
}
|
|
- pattern: |
|
|
resource "aws_db_instance" $ANYTHING {
|
|
...
|
|
backup_retention_period = 0
|
|
...
|
|
}
|
|
message: The AWS RDS has no retention. Missing retention can cause losing important
|
|
event information. To fix this, set a `backup_retention_period`.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
cwe:
|
|
- 'CWE-320: CWE CATEGORY: Key Management Errors'
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
category: security
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-rds-backup-no-retention.aws-rds-backup-no-retention
|
|
shortlink: https://sg.run/OyYB
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 17375
|
|
rv_id: 946719
|
|
rule_id: GdUzwQ
|
|
version_id: GxTP0Lq
|
|
url: https://semgrep.dev/playground/r/GxTP0Lq/terraform.aws.security.aws-rds-backup-no-retention.aws-rds-backup-no-retention
|
|
origin: community
|
|
- id: csharp.dotnet.security.razor-template-injection.razor-template-injection
|
|
message: User-controllable string passed to Razor.Parse. This leads directly to
|
|
code execution in the context of the process.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
cwe2022-top25: true
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://clement.notin.org/blog/2020/04/15/Server-Side-Template-Injection-(SSTI)-in-ASP.NET-Razor/
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
- razor
|
|
- asp
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.razor-template-injection.razor-template-injection
|
|
shortlink: https://sg.run/oyj0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18216
|
|
rv_id: 1262621
|
|
rule_id: EwUr68
|
|
version_id: 1QTypdj
|
|
url: https://semgrep.dev/playground/r/1QTypdj/csharp.dotnet.security.razor-template-injection.razor-template-injection
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- focus-metavariable: $ARG
|
|
- pattern-inside: |
|
|
public ActionResult $METHOD(..., string $ARG,...){...}
|
|
pattern-sinks:
|
|
- pattern: |
|
|
Razor.Parse(...)
|
|
pattern-sanitizers:
|
|
- not_conflicting: true
|
|
pattern: $F(...)
|
|
- id: csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation
|
|
severity: WARNING
|
|
languages:
|
|
- csharp
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-295: Improper Certificate Validation'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
references:
|
|
- https://docs.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.issuernameregistry?view=netframework-4.8
|
|
category: security
|
|
technology:
|
|
- .net
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation
|
|
shortlink: https://sg.run/XZ6B
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18220
|
|
rv_id: 1262629
|
|
rule_id: gxUy01
|
|
version_id: xyTjzGW
|
|
url: https://semgrep.dev/playground/r/xyTjzGW/csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation
|
|
origin: community
|
|
message: Validating certificates based on subject name is bad practice. Use the
|
|
X509Certificate2.Verify() method instead.
|
|
patterns:
|
|
- pattern-inside: |
|
|
using System.IdentityModel.Tokens;
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
X509SecurityToken $TOK = $RHS;
|
|
...
|
|
- pattern-inside: |
|
|
$T $M(..., X509SecurityToken $TOK, ...) {
|
|
...
|
|
}
|
|
- metavariable-pattern:
|
|
metavariable: $RHS
|
|
pattern-either:
|
|
- pattern: $T as X509SecurityToken
|
|
- pattern: new X509SecurityToken(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
X509Certificate2 $CERT = new X509Certificate2(...);
|
|
...
|
|
- pattern-inside: |
|
|
$T $M(..., X509Certificate2 $CERT, ...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
foreach (X509Certificate2 $CERT in $COLLECTION) {
|
|
...
|
|
}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: String.Equals($NAME, "...")
|
|
- pattern: String.Equals("...", $NAME)
|
|
- pattern: $NAME.Equals("...")
|
|
- pattern: $NAME == "..."
|
|
- pattern: $NAME != "..."
|
|
- pattern: |
|
|
"..." == $NAME
|
|
- pattern: |
|
|
"..." != $NAME
|
|
- metavariable-pattern:
|
|
metavariable: $NAME
|
|
pattern-either:
|
|
- pattern: $TOK.Certificate.SubjectName.Name
|
|
- pattern: $CERT.SubjectName.Name
|
|
- pattern: $CERT.GetNameInfo(...)
|
|
- id: csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: $A
|
|
- pattern-inside: |
|
|
Path.Combine(...,$A,...)
|
|
- pattern-inside: |
|
|
public $TYPE $M(...,$A,...){...}
|
|
- pattern-not-inside: |
|
|
<... Path.GetFileName($A) != $A ...>
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $X
|
|
- pattern: |
|
|
File.$METHOD($X,...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (?i)^(read|write)
|
|
pattern-sanitizers:
|
|
- pattern: |
|
|
Path.GetFileName(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$X = Path.GetFileName(...);
|
|
...
|
|
- pattern: $X
|
|
- patterns:
|
|
- pattern: $X
|
|
- pattern-inside: |
|
|
if(<... Path.GetFileName($X) != $X ...>){
|
|
...
|
|
throw new $EXCEPTION(...);
|
|
}
|
|
...
|
|
message: String argument $A is used to read or write data from a file via Path.Combine
|
|
without direct sanitization via Path.GetFileName. If the path is user-supplied
|
|
data this can lead to path traversal.
|
|
languages:
|
|
- csharp
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://www.praetorian.com/blog/pathcombine-security-issues-in-aspnet-applications/
|
|
- https://docs.microsoft.com/en-us/dotnet/api/system.io.path.combine?view=net-6.0#remarks
|
|
technology:
|
|
- .net
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine
|
|
shortlink: https://sg.run/1RvG
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18222
|
|
rv_id: 1262632
|
|
rule_id: 3qU3bE
|
|
version_id: vdT0644
|
|
url: https://semgrep.dev/playground/r/vdT0644/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine
|
|
origin: community
|
|
- id: csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings
|
|
severity: WARNING
|
|
languages:
|
|
- C#
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-706: Use of Incorrectly-Resolved Name or Reference'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://docs.microsoft.com/en-us/dotnet/api/system.net.httplistener?view=net-6.0
|
|
category: security
|
|
technology:
|
|
- .net
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings
|
|
shortlink: https://sg.run/9LJr
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18223
|
|
rv_id: 1262633
|
|
rule_id: 4bUQ81
|
|
version_id: d6Tyx4K
|
|
url: https://semgrep.dev/playground/r/d6Tyx4K/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings
|
|
origin: community
|
|
message: The top level wildcard bindings $PREFIX leaves your application open to
|
|
security vulnerabilities and give attackers more control over where traffic is
|
|
routed. If you must use wildcards, consider using subdomain wildcard binding.
|
|
For example, you can use "*.asdf.gov" if you own all of "asdf.gov".
|
|
patterns:
|
|
- pattern-inside: |
|
|
using System.Net;
|
|
...
|
|
- pattern: $LISTENER.Prefixes.Add("$PREFIX")
|
|
- metavariable-regex:
|
|
metavariable: $PREFIX
|
|
regex: (http|https)://(\*|\+)(.[a-zA-Z]{2,})?:[0-9]+
|
|
- id: csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout
|
|
severity: WARNING
|
|
languages:
|
|
- C#
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1333: Inefficient Regular Expression Complexity'
|
|
owasp: A01:2017 - Injection
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS
|
|
- https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.infinitematchtimeout
|
|
- https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0
|
|
category: security
|
|
technology:
|
|
- .net
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Denial-of-Service (DoS)
|
|
source: https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout
|
|
shortlink: https://sg.run/NgRy
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18227
|
|
rv_id: 945224
|
|
rule_id: GdUDBP
|
|
version_id: yeT0nDq
|
|
url: https://semgrep.dev/playground/r/yeT0nDq/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout
|
|
origin: community
|
|
message: 'Specifying the regex timeout leaves the system vulnerable to a regex-based
|
|
Denial of Service (DoS) attack. Consider setting the timeout to a short amount
|
|
of time like 2 or 3 seconds. If you are sure you need an infinite timeout, double
|
|
check that your context meets the conditions outlined in the "Notes to Callers"
|
|
section at the bottom of this page: https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0'
|
|
patterns:
|
|
- pattern-inside: |
|
|
using System.Text.RegularExpressions;
|
|
...
|
|
- pattern-either:
|
|
- pattern: new Regex(..., TimeSpan.InfiniteMatchTimeout)
|
|
- patterns:
|
|
- pattern: new Regex(..., TimeSpan.FromSeconds($TIME))
|
|
- metavariable-comparison:
|
|
metavariable: $TIME
|
|
comparison: $TIME > 5
|
|
- pattern: new Regex(..., TimeSpan.FromMinutes(...))
|
|
- pattern: new Regex(..., TimeSpan.FromHours(...))
|
|
- id: csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- focus-metavariable: $ARG
|
|
- pattern-inside: |
|
|
public $T $M(...,string $ARG,...){...}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
$XMLDOCUMENT.$METHOD(...)
|
|
- pattern-inside: "XmlDocument $XMLDOCUMENT = new XmlDocument(...);\n...\n$XMLDOCUMENT.XmlResolver
|
|
= new XmlUrlResolver(...);\n... \n"
|
|
message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling
|
|
a string argument from a public method. Enabling Document Type Definition (DTD)
|
|
parsing may cause XML External Entity (XXE) injection if supplied with user-controllable
|
|
data.
|
|
languages:
|
|
- csharp
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
references:
|
|
- https://www.jardinesoftware.net/2016/05/26/xxe-and-net/
|
|
- https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks
|
|
technology:
|
|
- .net
|
|
- xml
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override
|
|
shortlink: https://sg.run/k98P
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18228
|
|
rv_id: 1262654
|
|
rule_id: ReUK9k
|
|
version_id: K3TKk5E
|
|
url: https://semgrep.dev/playground/r/K3TKk5E/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override
|
|
origin: community
|
|
- id: csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- focus-metavariable: $ARG
|
|
- pattern-inside: |
|
|
public $T $M(...,string $ARG,...){...}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
XmlReader $READER = XmlReader.Create(...,$RS,...);
|
|
- pattern-inside: "XmlReaderSettings $RS = new XmlReaderSettings();\n...\n$RS.DtdProcessing
|
|
= DtdProcessing.Parse;\n... \n"
|
|
message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling
|
|
a string argument from a public method. Enabling Document Type Definition (DTD)
|
|
parsing may cause XML External Entity (XXE) injection if supplied with user-controllable
|
|
data.
|
|
languages:
|
|
- csharp
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
references:
|
|
- https://www.jardinesoftware.net/2016/05/26/xxe-and-net/
|
|
- https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks
|
|
technology:
|
|
- .net
|
|
- xml
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override
|
|
shortlink: https://sg.run/wXjA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18229
|
|
rv_id: 1262655
|
|
rule_id: AbU3pX
|
|
version_id: qkTR7WD
|
|
url: https://semgrep.dev/playground/r/qkTR7WD/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override
|
|
origin: community
|
|
- id: csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- focus-metavariable: $ARG
|
|
- pattern-inside: |
|
|
public $T $M(...,string $ARG,...){...}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
$READER.$METHOD(...)
|
|
- pattern-not-inside: |
|
|
$READER.DtdProcessing = DtdProcessing.Prohibit;
|
|
...
|
|
- pattern-inside: |
|
|
XmlTextReader $READER = new XmlTextReader(...);
|
|
...
|
|
message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling
|
|
a string argument from a public method. Enabling Document Type Definition (DTD)
|
|
parsing may cause XML External Entity (XXE) injection if supplied with user-controllable
|
|
data.
|
|
languages:
|
|
- csharp
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
references:
|
|
- https://www.jardinesoftware.net/2016/05/26/xxe-and-net/
|
|
- https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks
|
|
technology:
|
|
- .net
|
|
- xml
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults
|
|
shortlink: https://sg.run/xXjL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18230
|
|
rv_id: 1262656
|
|
rule_id: BYUevk
|
|
version_id: l4TJRWG
|
|
url: https://semgrep.dev/playground/r/l4TJRWG/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults
|
|
origin: community
|
|
- id: go.aws-lambda.security.database-sqli.database-sqli
|
|
languages:
|
|
- go
|
|
message: Detected SQL statement that is tainted by `$EVENT` object. This could lead
|
|
to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use prepared statements with the 'Prepare' and 'PrepareContext'
|
|
calls.
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://pkg.go.dev/database/sql#DB.Query
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- database
|
|
- sql
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/go.aws-lambda.security.database-sqli.database-sqli
|
|
shortlink: https://sg.run/e5e8
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18232
|
|
rv_id: 1262909
|
|
rule_id: WAUdJ7
|
|
version_id: BjTkZkQ
|
|
url: https://semgrep.dev/playground/r/BjTkZkQ/go.aws-lambda.security.database-sqli.database-sqli
|
|
origin: community
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $QUERY
|
|
- pattern-either:
|
|
- pattern: $DB.Exec($QUERY,...)
|
|
- pattern: $DB.ExecContent($QUERY,...)
|
|
- pattern: $DB.Query($QUERY,...)
|
|
- pattern: $DB.QueryContext($QUERY,...)
|
|
- pattern: $DB.QueryRow($QUERY,...)
|
|
- pattern: $DB.QueryRowContext($QUERY,...)
|
|
- pattern-inside: |
|
|
import "database/sql"
|
|
...
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...}
|
|
...
|
|
lambda.Start($HANDLER, ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
func $HANDLER($EVENT $TYPE) {...}
|
|
...
|
|
lambda.Start($HANDLER, ...)
|
|
- pattern-not-inside: |
|
|
func $HANDLER($EVENT context.Context) {...}
|
|
...
|
|
lambda.Start($HANDLER, ...)
|
|
- focus-metavariable: $EVENT
|
|
severity: WARNING
|
|
- id: go.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
languages:
|
|
- go
|
|
severity: ERROR
|
|
message: Detected user input used to manually construct a SQL string. This is usually
|
|
bad practice because manual construction could accidentally result in a SQL injection.
|
|
An attacker could use a SQL injection to steal or modify contents of the database.
|
|
Instead, use a parameterized query which is available by default in most database
|
|
engines. Alternatively, consider using an object-relational mapper (ORM) such
|
|
as Sequelize which will protect your queries.
|
|
metadata:
|
|
references:
|
|
- https://owasp.org/www-community/attacks/SQL_Injection
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/go.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
shortlink: https://sg.run/vX3Y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18233
|
|
rv_id: 1262910
|
|
rule_id: 0oUwqg
|
|
version_id: DkTRbRL
|
|
url: https://semgrep.dev/playground/r/DkTRbRL/go.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...}
|
|
...
|
|
lambda.Start($HANDLER, ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
func $HANDLER($EVENT $TYPE) {...}
|
|
...
|
|
lambda.Start($HANDLER, ...)
|
|
- pattern-not-inside: |
|
|
func $HANDLER($EVENT context.Context) {...}
|
|
...
|
|
lambda.Start($HANDLER, ...)
|
|
- focus-metavariable: $EVENT
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
"$SQLSTR" + ...
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(\s*select|\s*delete|\s*insert|\s*create|\s*update|\s*alter|\s*drop).*
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: fmt.Fprintf($F, "$SQLSTR", ...)
|
|
- pattern: fmt.Sprintf("$SQLSTR", ...)
|
|
- pattern: fmt.Printf("$SQLSTR", ...)
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).*
|
|
- pattern-not-inside: |
|
|
log.$PRINT(...)
|
|
pattern-sanitizers:
|
|
- pattern: strconv.Atoi(...)
|
|
- id: go.lang.security.filepath-clean-misuse.filepath-clean-misuse
|
|
message: '`Clean` is not intended to sanitize against path traversal attacks. This
|
|
function is for finding the shortest path name equivalent to the given input.
|
|
Using `Clean` to sanitize file reads may expose this application to path traversal
|
|
attacks, where an attacker could access arbitrary files on the server. To fix
|
|
this easily, write this: `filepath.FromSlash(path.Clean("/"+strings.Trim(req.URL.Path,
|
|
"/")))` However, a better solution is using the `SecureJoin` function in the package
|
|
`filepath-securejoin`. See https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme.'
|
|
severity: ERROR
|
|
languages:
|
|
- go
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
($REQUEST : *http.Request).$ANYTHING
|
|
- pattern: |
|
|
($REQUEST : http.Request).$ANYTHING
|
|
- metavariable-regex:
|
|
metavariable: $ANYTHING
|
|
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: filepath.Clean($...INNER)
|
|
- pattern: path.Clean($...INNER)
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"/" + ...
|
|
fix: filepath.FromSlash(filepath.Clean("/"+strings.Trim($...INNER, "/")))
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
references:
|
|
- https://pkg.go.dev/path#Clean
|
|
- http://technosophos.com/2016/03/31/go-quickly-cleaning-filepaths.html
|
|
- https://labs.detectify.com/2021/12/15/zero-day-path-traversal-grafana/
|
|
- https://dzx.cz/2021/04/02/go_path_traversal/
|
|
- https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- go
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/go.lang.security.filepath-clean-misuse.filepath-clean-misuse
|
|
shortlink: https://sg.run/ZKzw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18235
|
|
rv_id: 1262967
|
|
rule_id: qNUQJe
|
|
version_id: jQTn5Bj
|
|
url: https://semgrep.dev/playground/r/jQTn5Bj/go.lang.security.filepath-clean-misuse.filepath-clean-misuse
|
|
origin: community
|
|
- id: java.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
message: Detected user input used to manually construct a SQL string. This is usually
|
|
bad practice because manual construction could accidentally result in a SQL injection.
|
|
An attacker could use a SQL injection to steal or modify contents of the database.
|
|
Instead, use a parameterized query which is available by default in most database
|
|
engines. Alternatively, consider using an object-relational mapper (ORM) such
|
|
as Sequelize which will protect your queries.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
references:
|
|
- https://owasp.org/www-community/attacks/SQL_Injection
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
shortlink: https://sg.run/EBYN
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18237
|
|
rv_id: 1262977
|
|
rule_id: YGUl4z
|
|
version_id: O9TpxQN
|
|
url: https://semgrep.dev/playground/r/O9TpxQN/java.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- focus-metavariable: $EVENT
|
|
- pattern-either:
|
|
- pattern: |
|
|
$HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) {
|
|
...
|
|
}
|
|
- pattern: |
|
|
$HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) {
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$SQLSTR" + ...
|
|
- pattern: |
|
|
"$SQLSTR".concat(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
StringBuilder $SB = new StringBuilder("$SQLSTR");
|
|
...
|
|
- pattern: $SB.append(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VAR = "$SQLSTR";
|
|
...
|
|
- pattern: $VAR += ...
|
|
- pattern: String.format("$SQLSTR", ...)
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(select|delete|insert|create|update|alter|drop)\b
|
|
- pattern-not-inside: |
|
|
System.out.$PRINTLN(...)
|
|
- id: java.aws-lambda.security.tainted-sqli.tainted-sqli
|
|
message: Detected SQL statement that is tainted by `$EVENT` object. This could lead
|
|
to SQL injection if variables in the SQL statement are not properly sanitized.
|
|
Use parameterized SQL queries or properly sanitize user input instead.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- focus-metavariable: $EVENT
|
|
- pattern-either:
|
|
- pattern: |
|
|
$HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) {
|
|
...
|
|
}
|
|
- pattern: |
|
|
$HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) {
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: "(java.sql.CallableStatement $STMT) = ...; \n"
|
|
- pattern: |
|
|
(java.sql.Statement $STMT) = ...;
|
|
- pattern: |
|
|
(java.sql.PreparedStatement $STMT) = ...;
|
|
- pattern: |
|
|
$VAR = $CONN.prepareStatement(...)
|
|
- pattern: |
|
|
$PATH.queryForObject(...);
|
|
- pattern: |
|
|
(java.util.Map<String, Object> $STMT) = $PATH.queryForMap(...);
|
|
- pattern: |
|
|
(org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...;
|
|
- patterns:
|
|
- pattern-inside: |
|
|
(String $SQL) = "$SQLSTR" + ...;
|
|
...
|
|
- pattern: $PATH.$SQLCMD(..., $SQL, ...);
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*)
|
|
- metavariable-regex:
|
|
metavariable: $SQLCMD
|
|
regex: (execute|query|executeUpdate|batchUpdate)
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- sql
|
|
- java
|
|
- aws-lambda
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sqli.tainted-sqli
|
|
shortlink: https://sg.run/7942
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18238
|
|
rv_id: 1262978
|
|
rule_id: 6JUDWk
|
|
version_id: e1Tyj4g
|
|
url: https://semgrep.dev/playground/r/e1Tyj4g/java.aws-lambda.security.tainted-sqli.tainted-sqli
|
|
origin: community
|
|
- id: java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
message: Detected input from a HTTPServletRequest going into a SQL sink or statement.
|
|
This could lead to SQL injection if variables in the SQL statement are not properly
|
|
sanitized. Use parameterized SQL queries or properly sanitize user input instead.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
category: security
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
cwe2021-top25: true
|
|
cwe2022-top25: true
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
|
|
- https://owasp.org/www-community/attacks/SQL_Injection
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- sql
|
|
- java
|
|
- servlets
|
|
- spring
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
shortlink: https://sg.run/Lg56
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18239
|
|
rv_id: 1409390
|
|
rule_id: oqUBJG
|
|
version_id: 7ZTKJNj
|
|
url: https://semgrep.dev/playground/r/7ZTKJNj/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
origin: community
|
|
languages:
|
|
- java
|
|
mode: taint
|
|
options:
|
|
taint_assume_safe_numbers: true
|
|
taint_assume_safe_booleans: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(HttpServletRequest $REQ).$REQFUNC(...)
|
|
- pattern: "(ServletRequest $REQ).$REQFUNC(...) \n"
|
|
- metavariable-regex:
|
|
metavariable: $REQFUNC
|
|
regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: "(java.sql.CallableStatement $STMT) = ...; \n"
|
|
- pattern: |
|
|
(java.sql.Statement $STMT) = ...;
|
|
...
|
|
$OUTPUT = $STMT.$FUNC(...);
|
|
- pattern: |
|
|
(java.sql.PreparedStatement $STMT) = ...;
|
|
- pattern: |
|
|
$VAR = $CONN.prepareStatement(...)
|
|
- pattern: |
|
|
$PATH.queryForObject(...);
|
|
- pattern: |
|
|
(java.util.Map<String, Object> $STMT) = $PATH.queryForMap(...);
|
|
- pattern: |
|
|
(org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...;
|
|
- pattern: |
|
|
(org.springframework.jdbc.core.JdbcTemplate $TEMPL).batchUpdate(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
(String $SQL) = "$SQLSTR" + ...;
|
|
...
|
|
- pattern: $PATH.$SQLCMD(..., $SQL, ...);
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*)
|
|
- metavariable-regex:
|
|
metavariable: $SQLCMD
|
|
regex: (execute|query|executeUpdate|batchUpdate)
|
|
- id: java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request
|
|
message: Detected input from a HTTPServletRequest going into a 'ProcessBuilder'
|
|
or 'exec' command. This could lead to command injection if variables passed into
|
|
the exec commands are not properly sanitized. Instead, avoid using these OS commands
|
|
with user-supplied input, or, if you must use these commands, use a whitelist
|
|
of specific values.
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(HttpServletRequest $REQ)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);
|
|
...
|
|
for (javax.servlet.http.Cookie $COOKIE: $COOKIES) {
|
|
...
|
|
}
|
|
- pattern: |
|
|
$COOKIE.getValue(...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(ProcessBuilder $PB) = ...;
|
|
- patterns:
|
|
- pattern: |
|
|
(Process $P) = ...;
|
|
- pattern-not: |
|
|
(Process $P) = (java.lang.Runtime $R).exec(...);
|
|
- patterns:
|
|
- pattern: (java.lang.Runtime $R).exec($CMD, ...);
|
|
- focus-metavariable: $CMD
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder
|
|
$PB) = ...;\n...\n$PB.command($ARGLIST);\n"
|
|
- pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder
|
|
$PB) = ...;\n"
|
|
- pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(Process
|
|
$P) = ...;\n"
|
|
- pattern: |
|
|
$ARGLIST.add(...);
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- java
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request
|
|
shortlink: https://sg.run/8zPN
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18240
|
|
rv_id: 1263042
|
|
rule_id: zdUWrg
|
|
version_id: LjTkg9J
|
|
url: https://semgrep.dev/playground/r/LjTkg9J/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request
|
|
origin: community
|
|
- id: java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request
|
|
message: Detected input from a HTTPServletRequest going into an LDAP query. This
|
|
could lead to LDAP injection if the input is not properly sanitized, which could
|
|
result in attackers modifying objects in the LDAP tree structure. Ensure data
|
|
passed to an LDAP query is not controllable or properly sanitize the data.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP
|
|
Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://sensei.securecodewarrior.com/recipes/scw%3Ajava%3ALDAP-injection
|
|
category: security
|
|
technology:
|
|
- java
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- LDAP Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request
|
|
shortlink: https://sg.run/gRg0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18241
|
|
rv_id: 1409392
|
|
rule_id: pKUXAv
|
|
version_id: 8KT3Pe6
|
|
url: https://semgrep.dev/playground/r/8KT3Pe6/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: (HttpServletRequest $REQ)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(javax.naming.directory.InitialDirContext $IDC).search(...)
|
|
- pattern: |
|
|
(javax.naming.directory.DirContext $CTX).search(...)
|
|
- pattern-not: |
|
|
(javax.naming.directory.InitialDirContext $IDC).search($Y, "...", ...)
|
|
- pattern-not: |
|
|
(javax.naming.directory.DirContext $CTX).search($Y, "...", ...)
|
|
- id: java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request
|
|
message: Detected input from a HTTPServletRequest going into a session command,
|
|
like `setAttribute`. User input into such a command could lead to an attacker
|
|
inputting malicious code into your session parameters, blurring the line between
|
|
what's trusted and untrusted, and therefore leading to a trust boundary violation.
|
|
This could lead to programmers trusting unvalidated data. Instead, thoroughly
|
|
sanitize user input before passing it into such function calls.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
(HttpServletRequest $REQ).$FUNC(...)
|
|
- pattern-not: |
|
|
(HttpServletRequest $REQ).getSession()
|
|
- patterns:
|
|
- pattern-inside: |
|
|
(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);
|
|
...
|
|
for (javax.servlet.http.Cookie $COOKIE: $COOKIES) {
|
|
...
|
|
}
|
|
- pattern: |
|
|
$COOKIE.getValue(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(... );
|
|
...
|
|
- pattern: |
|
|
$PARAM = $VALS[$INDEX];
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$HEADERS = (HttpServletRequest $REQ).getHeaders(...);
|
|
...
|
|
$PARAM = $HEADERS.$FUNC(...);
|
|
...
|
|
- pattern: |
|
|
java.net.URLDecoder.decode($PARAM, ...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: (HttpServletRequest $REQ).getSession().$FUNC($NAME, $VALUE);
|
|
- metavariable-regex:
|
|
metavariable: $FUNC
|
|
regex: ^(putValue|setAttribute)$
|
|
- focus-metavariable: $VALUE
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- java
|
|
cwe:
|
|
- 'CWE-501: Trust Boundary Violation'
|
|
owasp:
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request
|
|
shortlink: https://sg.run/QbDZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18242
|
|
rv_id: 1409393
|
|
rule_id: 2ZU7Eo
|
|
version_id: gETrv9j
|
|
url: https://semgrep.dev/playground/r/gETrv9j/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request
|
|
origin: community
|
|
- id: java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request
|
|
message: Detected input from a HTTPServletRequest going into a XPath evaluate or
|
|
compile command. This could lead to xpath injection if variables passed into the
|
|
evaluate or compile commands are not properly sanitized. Xpath injection could
|
|
lead to unauthorized access to sensitive information in XML documents. Instead,
|
|
thoroughly sanitize user input or use parameterized xpath queries if you can.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: |
|
|
(HttpServletRequest $REQ).$FUNC(...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(javax.xml.xpath.XPath $XP).evaluate(...)
|
|
- pattern: |
|
|
(javax.xml.xpath.XPath $XP).compile(...).evaluate(...)
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- java
|
|
cwe:
|
|
- 'CWE-643: Improper Neutralization of Data within XPath Expressions (''XPath
|
|
Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XPath Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request
|
|
shortlink: https://sg.run/3BvK
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18243
|
|
rv_id: 1409394
|
|
rule_id: X5U5nj
|
|
version_id: QkTERKP
|
|
url: https://semgrep.dev/playground/r/QkTERKP/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request
|
|
origin: community
|
|
- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
- https://xerces.apache.org/xerces2-j/features.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false
|
|
shortlink: https://sg.run/4Dv5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18244
|
|
rv_id: 1263057
|
|
rule_id: j2UrJ8
|
|
version_id: 0bTKzgX
|
|
url: https://semgrep.dev/playground/r/0bTKzgX/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false
|
|
origin: community
|
|
message: DOCTYPE declarations are enabled for $DBFACTORY. Without prohibiting external
|
|
entity declarations, this is vulnerable to XML external entity attacks. Disable
|
|
this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl"
|
|
to true. Alternatively, allow DOCTYPE declarations and only prohibit external
|
|
entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities"
|
|
and "http://xml.org/sax/features/external-parameter-entities" to false.
|
|
patterns:
|
|
- pattern: $DBFACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl",
|
|
false);
|
|
- pattern-not-inside: |
|
|
$RETURNTYPE $METHOD(...){
|
|
...
|
|
$DBF.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
$RETURNTYPE $METHOD(...){
|
|
...
|
|
$DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$DBF.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
$RETURNTYPE $METHOD(...){
|
|
...
|
|
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, "");
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
$RETURNTYPE $METHOD(...){
|
|
...
|
|
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, "");
|
|
...
|
|
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
}
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
- https://xerces.apache.org/xerces2-j/features.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing
|
|
shortlink: https://sg.run/PYBz
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18245
|
|
rv_id: 1263058
|
|
rule_id: 10UPQB
|
|
version_id: K3TKk80
|
|
url: https://semgrep.dev/playground/r/K3TKk80/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing
|
|
origin: community
|
|
message: DOCTYPE declarations are enabled for this DocumentBuilderFactory. This
|
|
is vulnerable to XML external entity attacks. Disable this by setting the feature
|
|
"http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively,
|
|
allow DOCTYPE declarations and only prohibit external entities declarations. This
|
|
can be done by setting the features "http://xml.org/sax/features/external-general-entities"
|
|
and "http://xml.org/sax/features/external-parameter-entities" to false.
|
|
mode: taint
|
|
pattern-sources:
|
|
- by-side-effect: true
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY = DocumentBuilderFactory.newInstance();
|
|
- patterns:
|
|
- pattern: $FACTORY
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = DocumentBuilderFactory.newInstance();
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = DocumentBuilderFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = DocumentBuilderFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = DocumentBuilderFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $FACTORY.newDocumentBuilder();
|
|
pattern-sanitizers:
|
|
- by-side-effect: true
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
- focus-metavariable: $FACTORY
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl",
|
|
true);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: $M($X)
|
|
- focus-metavariable: $X
|
|
fix: |
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
$FACTORY.newDocumentBuilder();
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true
|
|
shortlink: https://sg.run/JgPy
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18246
|
|
rv_id: 1263059
|
|
rule_id: 9AUJ6r
|
|
version_id: qkTR7Lk
|
|
url: https://semgrep.dev/playground/r/qkTR7Lk/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true
|
|
origin: community
|
|
message: External entities are allowed for $DBFACTORY. This is vulnerable to XML
|
|
external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-general-entities"
|
|
to false.
|
|
pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities",
|
|
true);
|
|
fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities",
|
|
false);
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true
|
|
shortlink: https://sg.run/5Lv0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18247
|
|
rv_id: 1263060
|
|
rule_id: yyUNeo
|
|
version_id: l4TJRoL
|
|
url: https://semgrep.dev/playground/r/l4TJRoL/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true
|
|
origin: community
|
|
message: External entities are allowed for $DBFACTORY. This is vulnerable to XML
|
|
external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-parameter-entities"
|
|
to false.
|
|
pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities",
|
|
true);
|
|
fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities",
|
|
false);
|
|
languages:
|
|
- java
|
|
- id: javascript.aws-lambda.security.detect-child-process.detect-child-process
|
|
message: Allowing spawning arbitrary programs or running shell processes with arbitrary
|
|
arguments may end up in a command injection vulnerability. Try to avoid non-literal
|
|
values for the command string. If it is not possible, then do not let running
|
|
arbitrary commands, use a white list for inputs.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- javascript
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/javascript.aws-lambda.security.detect-child-process.detect-child-process
|
|
shortlink: https://sg.run/Ggoq
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18248
|
|
rv_id: 1263105
|
|
rule_id: r6UDNQ
|
|
version_id: YDTZe4o
|
|
url: https://semgrep.dev/playground/r/YDTZe4o/javascript.aws-lambda.security.detect-child-process.detect-child-process
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: $EVENT
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
exports.handler = function ($EVENT, ...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $FUNC ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern-inside: |
|
|
$FUNC = function ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $CMD
|
|
- pattern-either:
|
|
- pattern: exec($CMD,...)
|
|
- pattern: execSync($CMD,...)
|
|
- pattern: spawn($CMD,...)
|
|
- pattern: spawnSync($CMD,...)
|
|
- pattern: $CP.exec($CMD,...)
|
|
- pattern: $CP.execSync($CMD,...)
|
|
- pattern: $CP.spawn($CMD,...)
|
|
- pattern: $CP.spawnSync($CMD,...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('child_process')
|
|
...
|
|
- pattern-inside: |
|
|
import 'child_process'
|
|
...
|
|
- id: javascript.aws-lambda.security.knex-sqli.knex-sqli
|
|
message: 'Detected SQL statement that is tainted by `$EVENT` object. This could
|
|
lead to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `knex.raw(''SELECT $1 from
|
|
table'', [userinput])`'
|
|
metadata:
|
|
references:
|
|
- https://knexjs.org/#Builder-fromRaw
|
|
- https://knexjs.org/#Builder-whereRaw
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- knex
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/javascript.aws-lambda.security.knex-sqli.knex-sqli
|
|
shortlink: https://sg.run/RgWq
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18249
|
|
rv_id: 1263106
|
|
rule_id: bwUBlj
|
|
version_id: JdTzxKg
|
|
url: https://semgrep.dev/playground/r/JdTzxKg/javascript.aws-lambda.security.knex-sqli.knex-sqli
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
exports.handler = function ($EVENT, ...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $FUNC ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern-inside: |
|
|
$FUNC = function ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern: $EVENT
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $QUERY
|
|
- pattern-either:
|
|
- pattern: $KNEX.fromRaw($QUERY, ...)
|
|
- pattern: $KNEX.whereRaw($QUERY, ...)
|
|
- pattern: $KNEX.raw($QUERY, ...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('knex')
|
|
...
|
|
- pattern-inside: |
|
|
import 'knex'
|
|
...
|
|
- id: javascript.aws-lambda.security.mysql-sqli.mysql-sqli
|
|
message: 'Detected SQL statement that is tainted by `$EVENT` object. This could
|
|
lead to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `connection.query(''SELECT
|
|
$1 from table'', [userinput])`'
|
|
metadata:
|
|
references:
|
|
- https://www.npmjs.com/package/mysql2
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- mysql
|
|
- mysql2
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/javascript.aws-lambda.security.mysql-sqli.mysql-sqli
|
|
shortlink: https://sg.run/A502
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18250
|
|
rv_id: 1263107
|
|
rule_id: NbUBJ2
|
|
version_id: 5PTo1En
|
|
url: https://semgrep.dev/playground/r/5PTo1En/javascript.aws-lambda.security.mysql-sqli.mysql-sqli
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
exports.handler = function ($EVENT, ...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $FUNC ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern-inside: |
|
|
$FUNC = function ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern: $EVENT
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $QUERY
|
|
- pattern-either:
|
|
- pattern: $POOL.query($QUERY, ...)
|
|
- pattern: $POOL.execute($QUERY, ...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('mysql')
|
|
...
|
|
- pattern-inside: |
|
|
require('mysql2')
|
|
...
|
|
- pattern-inside: |
|
|
require('mysql2/promise')
|
|
...
|
|
- pattern-inside: |
|
|
import 'mysql'
|
|
...
|
|
- pattern-inside: |
|
|
import 'mysql2'
|
|
...
|
|
- pattern-inside: |
|
|
import 'mysql2/promise'
|
|
...
|
|
- id: javascript.aws-lambda.security.pg-sqli.pg-sqli
|
|
message: 'Detected SQL statement that is tainted by `$EVENT` object. This could
|
|
lead to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `connection.query(''SELECT
|
|
$1 from table'', [userinput])`'
|
|
metadata:
|
|
references:
|
|
- https://node-postgres.com/features/queries
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- postgres
|
|
- pg
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/javascript.aws-lambda.security.pg-sqli.pg-sqli
|
|
shortlink: https://sg.run/BGKA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18251
|
|
rv_id: 1263108
|
|
rule_id: kxU25P
|
|
version_id: GxTkeJL
|
|
url: https://semgrep.dev/playground/r/GxTkeJL/javascript.aws-lambda.security.pg-sqli.pg-sqli
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
exports.handler = function ($EVENT, ...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $FUNC ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern-inside: |
|
|
$FUNC = function ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern: $EVENT
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $QUERY
|
|
- pattern-either:
|
|
- pattern: $DB.query($QUERY, ...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('pg')
|
|
...
|
|
- pattern-inside: |
|
|
import 'pg'
|
|
...
|
|
- id: javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli
|
|
message: 'Detected SQL statement that is tainted by `$EVENT` object. This could
|
|
lead to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `sequelize.query(''SELECT
|
|
* FROM projects WHERE status = ?'', { replacements: [''active''], type: QueryTypes.SELECT
|
|
});`'
|
|
metadata:
|
|
references:
|
|
- https://sequelize.org/master/manual/raw-queries.html
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- sequelize
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli
|
|
shortlink: https://sg.run/DAlP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18252
|
|
rv_id: 1263109
|
|
rule_id: wdUA5o
|
|
version_id: RGT0LrD
|
|
url: https://semgrep.dev/playground/r/RGT0LrD/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
exports.handler = function ($EVENT, ...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $FUNC ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern-inside: |
|
|
$FUNC = function ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern: $EVENT
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $QUERY
|
|
- pattern-either:
|
|
- pattern: $DB.query($QUERY, ...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('sequelize')
|
|
...
|
|
- pattern-inside: |
|
|
import 'sequelize'
|
|
...
|
|
- id: javascript.aws-lambda.security.tainted-html-response.tainted-html-response
|
|
message: Detected user input flowing into an HTML response. You may be accidentally
|
|
bypassing secure methods of rendering HTML by manually constructing HTML and this
|
|
could create a cross-site scripting vulnerability, which could let attackers steal
|
|
sensitive user data.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-response.tainted-html-response
|
|
shortlink: https://sg.run/0Gvj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18254
|
|
rv_id: 1263111
|
|
rule_id: OrUJBY
|
|
version_id: BjTkZ8D
|
|
url: https://semgrep.dev/playground/r/BjTkZ8D/javascript.aws-lambda.security.tainted-html-response.tainted-html-response
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
exports.handler = function ($EVENT, ...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $FUNC ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern-inside: |
|
|
$FUNC = function ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern: $EVENT
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $BODY
|
|
- pattern-inside: |
|
|
{..., headers: {..., 'Content-Type': 'text/html', ...}, body: $BODY, ... }
|
|
- id: javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection
|
|
message: The `vm` module enables compiling and running code within V8 Virtual Machine
|
|
contexts. The `vm` module is not a security mechanism. Do not use it to run untrusted
|
|
code. If code passed to `vm` functions is controlled by user input it could result
|
|
in command injection. Do not let user input in `vm` functions.
|
|
metadata:
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
category: security
|
|
technology:
|
|
- javascript
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection
|
|
shortlink: https://sg.run/q9w7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18256
|
|
rv_id: 1263114
|
|
rule_id: v8UOdZ
|
|
version_id: 0bTKz9J
|
|
url: https://semgrep.dev/playground/r/0bTKz9J/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: $EVENT
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
exports.handler = function ($EVENT, ...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $FUNC ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern-inside: |
|
|
$FUNC = function ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('vm');
|
|
...
|
|
- pattern-inside: |
|
|
import 'vm'
|
|
...
|
|
- pattern-either:
|
|
- pattern: $VM.runInContext($X,...)
|
|
- pattern: $VM.runInNewContext($X,...)
|
|
- pattern: $VM.runInThisContext($X,...)
|
|
- pattern: $VM.compileFunction($X,...)
|
|
- pattern: new $VM.Script($X,...)
|
|
- pattern: new $VM.SourceTextModule($X,...)
|
|
- pattern: runInContext($X,...)
|
|
- pattern: runInNewContext($X,...)
|
|
- pattern: runInThisContext($X,...)
|
|
- pattern: compileFunction($X,...)
|
|
- pattern: new Script($X,...)
|
|
- pattern: new SourceTextModule($X,...)
|
|
- id: javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli
|
|
message: 'Detected SQL statement that is tainted by `$REQ` object. This could lead
|
|
to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, it is recommended to use parameterized queries
|
|
or prepared statements. An example of parameterized queries like so: `knex.raw(''SELECT
|
|
$1 from table'', [userinput])` can help prevent SQLi.'
|
|
metadata:
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://knexjs.org/#Builder-fromRaw
|
|
- https://knexjs.org/#Builder-whereRaw
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- express
|
|
- nodejs
|
|
- knex
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli
|
|
shortlink: https://sg.run/l9eE
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18257
|
|
rv_id: 1263205
|
|
rule_id: d8UKLD
|
|
version_id: l4TJRey
|
|
url: https://semgrep.dev/playground/r/l4TJRey/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
|
|
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
- pattern: files.$ANYTHING.data.toString('utf8')
|
|
- pattern: files.$ANYTHING['data'].toString('utf8')
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $QUERY
|
|
- pattern-either:
|
|
- pattern-inside: $KNEX.fromRaw($QUERY, ...)
|
|
- pattern-inside: $KNEX.whereRaw($QUERY, ...)
|
|
- pattern-inside: $KNEX.raw($QUERY, ...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
require('knex')
|
|
...
|
|
- pattern-inside: |
|
|
import 'knex'
|
|
...
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: parseInt(...)
|
|
- id: php.lang.security.deserialization.extract-user-data
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- pattern: $_GET[...]
|
|
- pattern: $_FILES[...]
|
|
- pattern: $_POST[...]
|
|
pattern-sinks:
|
|
- pattern: extract(...)
|
|
pattern-sanitizers:
|
|
- pattern: extract($VAR, EXTR_SKIP,...)
|
|
message: Do not call 'extract()' on user-controllable data. If you must, then you
|
|
must also provide the EXTR_SKIP flag to prevent overwriting existing variables.
|
|
languages:
|
|
- php
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
technology:
|
|
- php
|
|
references:
|
|
- https://www.php.net/manual/en/function.extract.php#refsect1-function.extract-notes
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/php.lang.security.deserialization.extract-user-data
|
|
shortlink: https://sg.run/6bv1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18259
|
|
rv_id: 1263278
|
|
rule_id: nJUykq
|
|
version_id: w8TRovw
|
|
url: https://semgrep.dev/playground/r/w8TRovw/php.lang.security.deserialization.extract-user-data
|
|
origin: community
|
|
severity: ERROR
|
|
- id: python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $CMD
|
|
- pattern-either:
|
|
- pattern: asyncio.create_subprocess_exec($PROG, $CMD, ...)
|
|
- pattern: asyncio.create_subprocess_exec($PROG, [$CMD, ...], ...)
|
|
- pattern: asyncio.subprocess.create_subprocess_exec($PROG, $CMD, ...)
|
|
- pattern: asyncio.subprocess.create_subprocess_exec($PROG, [$CMD, ...], ...)
|
|
- pattern: asyncio.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/",
|
|
"-c", $CMD, ...)
|
|
- pattern: asyncio.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/",
|
|
"-c", $CMD, ...], ...)
|
|
- pattern: asyncio.subprocess.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/",
|
|
"-c", $CMD, ...)
|
|
- pattern: asyncio.subprocess.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/",
|
|
"-c", $CMD, ...], ...)
|
|
message: Detected 'create_subprocess_exec' function with argument tainted by `event`
|
|
object. If this data can be controlled by a malicious actor, it may be an instance
|
|
of command injection. Audit the use of this call to ensure it is not controllable
|
|
by an external resource. You may consider using 'shlex.escape()'.
|
|
metadata:
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
references:
|
|
- https://docs.python.org/3/library/asyncio-subprocess.html#asyncio.create_subprocess_exec
|
|
- https://docs.python.org/3/library/shlex.html
|
|
category: security
|
|
technology:
|
|
- python
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec
|
|
shortlink: https://sg.run/oyv0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18260
|
|
rv_id: 1263331
|
|
rule_id: EwUrX8
|
|
version_id: rxTAKgo
|
|
url: https://semgrep.dev/playground/r/rxTAKgo/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $CMD
|
|
- pattern-either:
|
|
- pattern: $LOOP.subprocess_exec($PROTOCOL, $CMD, ...)
|
|
- pattern: $LOOP.subprocess_exec($PROTOCOL, [$CMD, ...], ...)
|
|
- pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/",
|
|
"-c", $CMD, ...)
|
|
- pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/",
|
|
"-c", $CMD, ...], ...)
|
|
message: Detected subprocess function '$LOOP.subprocess_exec' with argument tainted
|
|
by `event` object. If this data can be controlled by a malicious actor, it may
|
|
be an instance of command injection. Audit the use of this call to ensure it is
|
|
not controllable by an external resource. You may consider using 'shlex.escape()'.
|
|
metadata:
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
references:
|
|
- https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec
|
|
- https://docs.python.org/3/library/shlex.html
|
|
category: security
|
|
technology:
|
|
- python
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec
|
|
shortlink: https://sg.run/z14d
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18261
|
|
rv_id: 1263332
|
|
rule_id: 7KUxXg
|
|
version_id: bZT53Ww
|
|
url: https://semgrep.dev/playground/r/bZT53Ww/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $CMD
|
|
- pattern-either:
|
|
- pattern: $LOOP.subprocess_shell($PROTOCOL, $CMD)
|
|
- pattern: asyncio.subprocess.create_subprocess_shell($CMD, ...)
|
|
- pattern: asyncio.create_subprocess_shell($CMD, ...)
|
|
message: Detected asyncio subprocess function with argument tainted by `event` object.
|
|
If this data can be controlled by a malicious actor, it may be an instance of
|
|
command injection. Audit the use of this call to ensure it is not controllable
|
|
by an external resource. You may consider using 'shlex.escape()'.
|
|
metadata:
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
references:
|
|
- https://docs.python.org/3/library/asyncio-subprocess.html
|
|
- https://docs.python.org/3/library/shlex.html
|
|
category: security
|
|
technology:
|
|
- python
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell
|
|
shortlink: https://sg.run/p9vZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18262
|
|
rv_id: 1263333
|
|
rule_id: L1UEl7
|
|
version_id: NdTzyWA
|
|
url: https://semgrep.dev/playground/r/NdTzyWA/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process
|
|
mode: taint
|
|
message: Detected `os` function with argument tainted by `event` object. This is
|
|
dangerous if external data can reach this function call because it allows a malicious
|
|
actor to execute commands. Ensure no external data reaches here.
|
|
metadata:
|
|
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- python
|
|
- aws-lambda
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process
|
|
shortlink: https://sg.run/2AjL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18263
|
|
rv_id: 1263334
|
|
rule_id: 8GUGBq
|
|
version_id: kbTzGv8
|
|
url: https://semgrep.dev/playground/r/kbTzGv8/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $CMD
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: os.$METHOD($MODE, $CMD, ...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile)
|
|
- patterns:
|
|
- pattern-inside: os.$METHOD($MODE, $BASH, ["-c", $CMD,...],...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp)
|
|
- metavariable-regex:
|
|
metavariable: $BASH
|
|
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
|
|
- patterns:
|
|
- pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (spawnl|spawnle|spawnlp|spawnlpe)
|
|
- metavariable-regex:
|
|
metavariable: $BASH
|
|
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
|
|
- id: python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use
|
|
mode: taint
|
|
message: Detected subprocess function with argument tainted by an `event` object. If
|
|
this data can be controlled by a malicious actor, it may be an instance of command
|
|
injection. The default option for `shell` is False, and this is secure by default.
|
|
Consider removing the `shell=True` or setting it to False explicitely. Using `shell=False`
|
|
means you have to split the command string into an array of strings for the command
|
|
and its arguments. You may consider using 'shlex.split()' for this purpose.
|
|
metadata:
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
references:
|
|
- https://docs.python.org/3/library/subprocess.html
|
|
- https://docs.python.org/3/library/shlex.html
|
|
category: security
|
|
technology:
|
|
- python
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use
|
|
shortlink: https://sg.run/XZ7B
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18264
|
|
rv_id: 1263335
|
|
rule_id: gxUyn1
|
|
version_id: w8TRogj
|
|
url: https://semgrep.dev/playground/r/w8TRogj/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(..., shell=True, ...)
|
|
pattern-sanitizers:
|
|
- pattern: shlex.split(...)
|
|
- pattern: pipes.quote(...)
|
|
- pattern: shlex.quote(...)
|
|
- id: python.aws-lambda.security.dangerous-system-call.dangerous-system-call
|
|
mode: taint
|
|
message: Detected `os` function with argument tainted by `event` object. This is
|
|
dangerous if external data can reach this function call because it allows a malicious
|
|
actor to execute commands. Use the 'subprocess' module instead, which is easier
|
|
to use without accidentally exposing a command injection vulnerability.
|
|
metadata:
|
|
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.2.4 Dyanmic Code Execution Features
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- python
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-system-call.dangerous-system-call
|
|
shortlink: https://sg.run/jDvN
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18265
|
|
rv_id: 1263336
|
|
rule_id: QrUkg6
|
|
version_id: xyTjzbG
|
|
url: https://semgrep.dev/playground/r/xyTjzbG/python.aws-lambda.security.dangerous-system-call.dangerous-system-call
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $CMD
|
|
- pattern-either:
|
|
- pattern: os.system($CMD,...)
|
|
- pattern: os.popen($CMD,...)
|
|
- pattern: os.popen2($CMD,...)
|
|
- pattern: os.popen3($CMD,...)
|
|
- pattern: os.popen4($CMD,...)
|
|
- id: python.aws-lambda.security.mysql-sqli.mysql-sqli
|
|
languages:
|
|
- python
|
|
message: 'Detected SQL statement that is tainted by `event` object. This could lead
|
|
to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `cursor.execute(''SELECT
|
|
* FROM projects WHERE status = %s'', (''active''))`'
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-execute.html
|
|
- https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-executemany.html
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- mysql
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.mysql-sqli.mysql-sqli
|
|
shortlink: https://sg.run/1RjG
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18266
|
|
rv_id: 1263337
|
|
rule_id: 3qU3eE
|
|
version_id: O9TpxLJ
|
|
url: https://semgrep.dev/playground/r/O9TpxLJ/python.aws-lambda.security.mysql-sqli.mysql-sqli
|
|
origin: community
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $QUERY
|
|
- pattern-either:
|
|
- pattern: $CURSOR.execute($QUERY,...)
|
|
- pattern: $CURSOR.executemany($QUERY,...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import mysql
|
|
...
|
|
- pattern-inside: |
|
|
import mysql.cursors
|
|
...
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
severity: WARNING
|
|
- id: python.aws-lambda.security.psycopg-sqli.psycopg-sqli
|
|
languages:
|
|
- python
|
|
message: 'Detected SQL statement that is tainted by `event` object. This could lead
|
|
to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `cursor.execute(''SELECT
|
|
* FROM projects WHERE status = %s'', ''active'')`'
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://www.psycopg.org/docs/cursor.html#cursor.execute
|
|
- https://www.psycopg.org/docs/cursor.html#cursor.executemany
|
|
- https://www.psycopg.org/docs/cursor.html#cursor.mogrify
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- psycopg
|
|
- psycopg2
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.psycopg-sqli.psycopg-sqli
|
|
shortlink: https://sg.run/9L8r
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18267
|
|
rv_id: 1263338
|
|
rule_id: 4bUQG1
|
|
version_id: e1TyjPZ
|
|
url: https://semgrep.dev/playground/r/e1TyjPZ/python.aws-lambda.security.psycopg-sqli.psycopg-sqli
|
|
origin: community
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $QUERY
|
|
- pattern-either:
|
|
- pattern: $CURSOR.execute($QUERY,...)
|
|
- pattern: $CURSOR.executemany($QUERY,...)
|
|
- pattern: $CURSOR.mogrify($QUERY,...)
|
|
- pattern-inside: |
|
|
import psycopg2
|
|
...
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
severity: WARNING
|
|
- id: python.aws-lambda.security.pymssql-sqli.pymssql-sqli
|
|
languages:
|
|
- python
|
|
message: 'Detected SQL statement that is tainted by `event` object. This could lead
|
|
to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `cursor.execute(''SELECT
|
|
* FROM projects WHERE status = %s'', ''active'')`'
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://pypi.org/project/pymssql/
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- pymssql
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.pymssql-sqli.pymssql-sqli
|
|
shortlink: https://sg.run/yXvP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18268
|
|
rv_id: 1263339
|
|
rule_id: PeUxO0
|
|
version_id: vdT06bG
|
|
url: https://semgrep.dev/playground/r/vdT06bG/python.aws-lambda.security.pymssql-sqli.pymssql-sqli
|
|
origin: community
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $QUERY
|
|
- pattern: $CURSOR.execute($QUERY,...)
|
|
- pattern-inside: |
|
|
import pymssql
|
|
...
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
severity: WARNING
|
|
- id: python.aws-lambda.security.pymysql-sqli.pymysql-sqli
|
|
languages:
|
|
- python
|
|
message: 'Detected SQL statement that is tainted by `event` object. This could lead
|
|
to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `cursor.execute(''SELECT
|
|
* FROM projects WHERE status = %s'', (''active''))`'
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://pypi.org/project/PyMySQL/#id4
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- pymysql
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.pymysql-sqli.pymysql-sqli
|
|
shortlink: https://sg.run/reve
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18269
|
|
rv_id: 1263340
|
|
rule_id: JDUlel
|
|
version_id: d6TyxNA
|
|
url: https://semgrep.dev/playground/r/d6TyxNA/python.aws-lambda.security.pymysql-sqli.pymysql-sqli
|
|
origin: community
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $QUERY
|
|
- pattern: $CURSOR.execute($QUERY,...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import pymysql
|
|
...
|
|
- pattern-inside: |
|
|
import pymysql.cursors
|
|
...
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
severity: WARNING
|
|
- id: python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli
|
|
languages:
|
|
- python
|
|
message: 'Detected SQL statement that is tainted by `event` object. This could lead
|
|
to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `cursor.execute(''SELECT
|
|
* FROM projects WHERE status = ?'', ''active'')`'
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://docs.sqlalchemy.org/en/14/core/connections.html#sqlalchemy.engine.Connection.execute
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- sqlalchemy
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli
|
|
shortlink: https://sg.run/b48W
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18270
|
|
rv_id: 1263341
|
|
rule_id: 5rUy3N
|
|
version_id: ZRTKARp
|
|
url: https://semgrep.dev/playground/r/ZRTKARp/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli
|
|
origin: community
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $QUERY
|
|
- pattern: $CURSOR.execute($QUERY,...)
|
|
- pattern-inside: |
|
|
import sqlalchemy
|
|
...
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
severity: WARNING
|
|
- id: python.aws-lambda.security.tainted-code-exec.tainted-code-exec
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: eval($CODE, ...)
|
|
- pattern: exec($CODE, ...)
|
|
message: Detected the use of `exec/eval`.This can be dangerous if used to evaluate
|
|
dynamic content. If this content can be input from outside the program, this may
|
|
be a code injection vulnerability. Ensure evaluated content is not definable by
|
|
external sources.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.2.4 Dyanmic Code Execution Features
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- python
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.tainted-code-exec.tainted-code-exec
|
|
shortlink: https://sg.run/Ng7y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18271
|
|
rv_id: 1263342
|
|
rule_id: GdUDJP
|
|
version_id: nWT2LD2
|
|
url: https://semgrep.dev/playground/r/nWT2LD2/python.aws-lambda.security.tainted-code-exec.tainted-code-exec
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.aws-lambda.security.tainted-html-response.tainted-html-response
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $BODY
|
|
- pattern-inside: |
|
|
{..., "headers": {..., "Content-Type": "text/html", ...}, "body": $BODY, ... }
|
|
message: Detected user input flowing into an HTML response. You may be accidentally
|
|
bypassing secure methods of rendering HTML by manually constructing HTML and this
|
|
could create a cross-site scripting vulnerability, which could let attackers steal
|
|
sensitive user data.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- aws-lambda
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-response.tainted-html-response
|
|
shortlink: https://sg.run/k9vP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18272
|
|
rv_id: 1263343
|
|
rule_id: ReUKrk
|
|
version_id: ExTEx5o
|
|
url: https://semgrep.dev/playground/r/ExTEx5o/python.aws-lambda.security.tainted-html-response.tainted-html-response
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
languages:
|
|
- python
|
|
message: Detected user input used to manually construct a SQL string. This is usually
|
|
bad practice because manual construction could accidentally result in a SQL injection.
|
|
An attacker could use a SQL injection to steal or modify contents of the database.
|
|
Instead, use a parameterized query which is available by default in most database
|
|
engines. Alternatively, consider using an object-relational mapper (ORM) such
|
|
as Sequelize which will protect your queries.
|
|
metadata:
|
|
references:
|
|
- https://owasp.org/www-community/attacks/SQL_Injection
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
shortlink: https://sg.run/wXvA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18273
|
|
rv_id: 1263346
|
|
rule_id: AbU3LX
|
|
version_id: 8KT5ron
|
|
url: https://semgrep.dev/playground/r/8KT5ron/python.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
origin: community
|
|
mode: taint
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$SQLSTR" + ...
|
|
- pattern: |
|
|
"$SQLSTR" % ...
|
|
- pattern: |
|
|
"$SQLSTR".format(...)
|
|
- pattern: |
|
|
f"$SQLSTR{...}..."
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*=
|
|
- pattern-not-inside: |
|
|
print(...)
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
severity: ERROR
|
|
- id: ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli
|
|
languages:
|
|
- ruby
|
|
message: 'Detected SQL statement that is tainted by `event` object. This could lead
|
|
to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `Example.find_by_sql ["SELECT
|
|
title FROM posts WHERE author = ? AND created > ?", author_id, start_date]`'
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://guides.rubyonrails.org/active_record_querying.html#finding-by-sql
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- active-record
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli
|
|
shortlink: https://sg.run/vXvY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18277
|
|
rv_id: 1263581
|
|
rule_id: 0oUw9g
|
|
version_id: w8TRor7
|
|
url: https://semgrep.dev/playground/r/w8TRor7/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli
|
|
origin: community
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $QUERY
|
|
- pattern-either:
|
|
- pattern: ActiveRecord::Base.connection.execute($QUERY,...)
|
|
- pattern: $MODEL.find_by_sql($QUERY,...)
|
|
- pattern: $MODEL.select_all($QUERY,...)
|
|
- pattern-inside: |
|
|
require 'active_record'
|
|
...
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context)
|
|
...
|
|
end
|
|
severity: WARNING
|
|
- id: ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli
|
|
languages:
|
|
- ruby
|
|
message: 'Detected SQL statement that is tainted by `event` object. This could lead
|
|
to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use sanitize statements like so: `escaped = client.escape(user_input)`'
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://github.com/brianmario/mysql2
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- mysql2
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli
|
|
shortlink: https://sg.run/dJLE
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18278
|
|
rv_id: 1263582
|
|
rule_id: KxUrQ3
|
|
version_id: xyTjzOe
|
|
url: https://semgrep.dev/playground/r/xyTjzOe/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli
|
|
origin: community
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $QUERY
|
|
- pattern-either:
|
|
- pattern: $CLIENT.query($QUERY,...)
|
|
- pattern: $CLIENT.prepare($QUERY,...)
|
|
- pattern-inside: |
|
|
require 'mysql2'
|
|
...
|
|
pattern-sanitizers:
|
|
- pattern: $CLIENT.escape(...)
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context)
|
|
...
|
|
end
|
|
severity: WARNING
|
|
- id: ruby.aws-lambda.security.pg-sqli.pg-sqli
|
|
languages:
|
|
- ruby
|
|
message: 'Detected SQL statement that is tainted by `event` object. This could lead
|
|
to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `conn.exec_params(''SELECT
|
|
$1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])`'
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://www.rubydoc.info/gems/pg/PG/Connection
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- postgres
|
|
- pg
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/ruby.aws-lambda.security.pg-sqli.pg-sqli
|
|
shortlink: https://sg.run/ZKww
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18279
|
|
rv_id: 1263583
|
|
rule_id: qNUQee
|
|
version_id: O9Tpxz7
|
|
url: https://semgrep.dev/playground/r/O9Tpxz7/ruby.aws-lambda.security.pg-sqli.pg-sqli
|
|
origin: community
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $QUERY
|
|
- pattern-either:
|
|
- pattern: $CONN.exec($QUERY,...)
|
|
- pattern: $CONN.exec_params($QUERY,...)
|
|
- pattern: $CONN.exec_prepared($QUERY,...)
|
|
- pattern: $CONN.async_exec($QUERY,...)
|
|
- pattern: $CONN.async_exec_params($QUERY,...)
|
|
- pattern: $CONN.async_exec_prepared($QUERY,...)
|
|
- pattern-inside: |
|
|
require 'pg'
|
|
...
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context)
|
|
...
|
|
end
|
|
severity: WARNING
|
|
- id: ruby.aws-lambda.security.sequel-sqli.sequel-sqli
|
|
languages:
|
|
- ruby
|
|
message: 'Detected SQL statement that is tainted by `event` object. This could lead
|
|
to SQL injection if the variable is user-controlled and not properly sanitized.
|
|
In order to prevent SQL injection, use parameterized queries or prepared statements
|
|
instead. You can use parameterized statements like so: `DB[''select * from items
|
|
where name = ?'', name]`'
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://github.com/jeremyevans/sequel#label-Arbitrary+SQL+queries
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
- sequel
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/ruby.aws-lambda.security.sequel-sqli.sequel-sqli
|
|
shortlink: https://sg.run/n9vY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18280
|
|
rv_id: 1263584
|
|
rule_id: lBUy2N
|
|
version_id: e1Tyj5j
|
|
url: https://semgrep.dev/playground/r/e1Tyj5j/ruby.aws-lambda.security.sequel-sqli.sequel-sqli
|
|
origin: community
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $QUERY
|
|
- pattern-either:
|
|
- pattern: DB[$QUERY,...]
|
|
- pattern: DB.run($QUERY,...)
|
|
- pattern-inside: |
|
|
require 'sequel'
|
|
...
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context)
|
|
...
|
|
end
|
|
severity: WARNING
|
|
- id: ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
message: Detected user input used to manually construct a SQL string. This is usually
|
|
bad practice because manual construction could accidentally result in a SQL injection.
|
|
An attacker could use a SQL injection to steal or modify contents of the database.
|
|
Instead, use a parameterized query which is available by default in most database
|
|
engines. Alternatively, consider using an object-relational mapper (ORM) such
|
|
as Sequelize which will protect your queries.
|
|
metadata:
|
|
references:
|
|
- https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet
|
|
category: security
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
technology:
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
shortlink: https://sg.run/EB7N
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18281
|
|
rv_id: 1263586
|
|
rule_id: PeUxOE
|
|
version_id: d6Tyx1Z
|
|
url: https://semgrep.dev/playground/r/d6Tyx1Z/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context)
|
|
...
|
|
end
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
"...#{...}..."
|
|
- pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].*
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: Kernel::sprintf("$SQLSTR", ...)
|
|
- pattern: |
|
|
"$SQLSTR" + $EXPR
|
|
- pattern: |
|
|
"$SQLSTR" % $EXPR
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].*
|
|
- pattern-not-inside: |
|
|
puts(...)
|
|
- id: scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings
|
|
patterns:
|
|
- pattern: secure = false
|
|
- pattern-inside: |
|
|
session = {
|
|
...
|
|
}
|
|
message: Session cookie `Secure` flag is explicitly disabled. The `secure` flag
|
|
for cookies prevents the client from transmitting the cookie over insecure channels
|
|
such as HTTP. Set the `Secure` flag by setting `secure` to `true` in configuration
|
|
file.
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
paths:
|
|
include:
|
|
- '*.conf'
|
|
metadata:
|
|
category: security
|
|
references:
|
|
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#security
|
|
- https://www.playframework.com/documentation/2.8.x/SettingsSession#Session-Configuration
|
|
technology:
|
|
- play
|
|
- scala
|
|
cwe:
|
|
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings
|
|
shortlink: https://sg.run/8z8N
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18284
|
|
rv_id: 1263685
|
|
rule_id: GdUDJO
|
|
version_id: e1TyjJv
|
|
url: https://semgrep.dev/playground/r/e1TyjJv/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings
|
|
origin: community
|
|
- id: scala.play.security.tainted-slick-sqli.tainted-slick-sqli
|
|
mode: taint
|
|
metadata:
|
|
references:
|
|
- https://scala-slick.org/doc/3.3.3/sql.html#splicing-literal-values
|
|
- https://scala-slick.org/doc/3.2.0/sql-to-slick.html#non-optimal-sql-code
|
|
category: security
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
technology:
|
|
- scala
|
|
- slick
|
|
- play
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/scala.play.security.tainted-slick-sqli.tainted-slick-sqli
|
|
shortlink: https://sg.run/k9K2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18328
|
|
rv_id: 1263687
|
|
rule_id: GdUDWO
|
|
version_id: d6TyxJe
|
|
url: https://semgrep.dev/playground/r/d6TyxJe/scala.play.security.tainted-slick-sqli.tainted-slick-sqli
|
|
origin: community
|
|
message: Detected a tainted SQL statement. This could lead to SQL injection if variables
|
|
in the SQL statement are not properly sanitized. Avoid using using user input
|
|
for generating SQL strings.
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: $REQ
|
|
- pattern-either:
|
|
- pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- patterns:
|
|
- pattern: $PARAM
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) {
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $MODEL.overrideSql(...)
|
|
- pattern: sql"..."
|
|
- pattern-inside: |
|
|
import slick.$DEPS
|
|
...
|
|
severity: ERROR
|
|
languages:
|
|
- scala
|
|
- id: go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check
|
|
patterns:
|
|
- pattern-inside: |
|
|
import ("github.com/gorilla/websocket")
|
|
...
|
|
- patterns:
|
|
- pattern-not-inside: |
|
|
$UPGRADER = websocket.Upgrader{..., CheckOrigin: $FN ,...}
|
|
...
|
|
- pattern-not-inside: |
|
|
$UPGRADER.CheckOrigin = $FN2
|
|
...
|
|
- pattern: |
|
|
$UPGRADER.Upgrade(...)
|
|
message: 'The Origin header in the HTTP WebSocket handshake is used to guarantee
|
|
that the connection accepted by the WebSocket is from a trusted origin domain.
|
|
Failure to enforce can lead to Cross Site Request Forgery (CSRF). As per "gorilla/websocket"
|
|
documentation: "A CheckOrigin function should carefully validate the request origin
|
|
to prevent cross-site request forgery."'
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-352: Cross-Site Request Forgery (CSRF)'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://pkg.go.dev/github.com/gorilla/websocket#Upgrader
|
|
technology:
|
|
- gorilla
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site Request Forgery (CSRF)
|
|
source: https://semgrep.dev/r/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check
|
|
shortlink: https://sg.run/xXpz
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18430
|
|
rv_id: 1262914
|
|
rule_id: ReUKdz
|
|
version_id: qkTR7RP
|
|
url: https://semgrep.dev/playground/r/qkTR7RP/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check
|
|
origin: community
|
|
- id: javascript.aws-lambda.security.tainted-html-string.tainted-html-string
|
|
message: Detected user input flowing into a manually constructed HTML string. You
|
|
may be accidentally bypassing secure methods of rendering HTML by manually constructing
|
|
HTML and this could create a cross-site scripting vulnerability, which could let
|
|
attackers steal sensitive user data. To be sure this is safe, check that the HTML
|
|
is rendered safely. Otherwise, use templates which will safely render HTML instead.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-string.tainted-html-string
|
|
shortlink: https://sg.run/Lgqr
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18483
|
|
rv_id: 1263112
|
|
rule_id: PeUxwW
|
|
version_id: DkTRbvp
|
|
url: https://semgrep.dev/playground/r/DkTRbvp/javascript.aws-lambda.security.tainted-html-string.tainted-html-string
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
exports.handler = function ($EVENT, ...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $FUNC ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern-inside: |
|
|
$FUNC = function ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern: $EVENT
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$HTMLSTR" + $EXPR
|
|
- pattern: |
|
|
"$HTMLSTR".concat(...)
|
|
- pattern: $UTIL.format($HTMLSTR, ...)
|
|
- pattern: format($HTMLSTR, ...)
|
|
- metavariable-pattern:
|
|
metavariable: $HTMLSTR
|
|
language: generic
|
|
pattern: <$TAG ...
|
|
- patterns:
|
|
- pattern: |
|
|
`...${...}...`
|
|
- pattern-regex: |
|
|
.*<\w+.*
|
|
- pattern-not-inside: |
|
|
console.$LOG(...)
|
|
- id: python.aws-lambda.security.tainted-html-string.tainted-html-string
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
message: Detected user input flowing into a manually constructed HTML string. You
|
|
may be accidentally bypassing secure methods of rendering HTML by manually constructing
|
|
HTML and this could create a cross-site scripting vulnerability, which could let
|
|
attackers steal sensitive user data. To be sure this is safe, check that the HTML
|
|
is rendered safely. Otherwise, use templates which will safely render HTML instead.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- aws-lambda
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-string.tainted-html-string
|
|
shortlink: https://sg.run/8zNy
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18484
|
|
rv_id: 1263344
|
|
rule_id: JDUlwy
|
|
version_id: 7ZTE36K
|
|
url: https://semgrep.dev/playground/r/7ZTE36K/python.aws-lambda.security.tainted-html-string.tainted-html-string
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: '"$HTMLSTR" % ...'
|
|
- pattern: '"$HTMLSTR".format(...)'
|
|
- pattern: '"$HTMLSTR" + ...'
|
|
- pattern: f"$HTMLSTR{...}..."
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$HTML = "$HTMLSTR"
|
|
...
|
|
- pattern-either:
|
|
- pattern: $HTML % ...
|
|
- pattern: $HTML.format(...)
|
|
- pattern: $HTML + ...
|
|
- metavariable-pattern:
|
|
metavariable: $HTMLSTR
|
|
language: generic
|
|
pattern: <$TAG ...
|
|
- pattern-not-inside: |
|
|
print(...)
|
|
- id: scala.lang.security.audit.io-source-ssrf.io-source-ssrf
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: Source.fromURL($URL,...)
|
|
- pattern: Source.fromURI($URL,...)
|
|
- pattern-inside: |
|
|
import scala.io.$SOURCE
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
def $FUNC(..., $URL: $T, ...) = $A {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $FUNC(..., $URL: $T, ...) = {
|
|
...
|
|
}
|
|
message: A parameter being passed directly into `fromURL` most likely lead to SSRF.
|
|
This could allow an attacker to send data to their own server, potentially exposing
|
|
sensitive data sent with this request. They could also probe internal servers
|
|
or other resources that the server running this code can access. Do not allow
|
|
arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode
|
|
the correct host.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
|
|
- https://www.scala-lang.org/api/current/scala/io/Source$.html#fromURL(url:java.net.URL)(implicitcodec:scala.io.Codec):scala.io.BufferedSource
|
|
category: security
|
|
technology:
|
|
- scala
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/scala.lang.security.audit.io-source-ssrf.io-source-ssrf
|
|
shortlink: https://sg.run/Qbz4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18486
|
|
rv_id: 1263675
|
|
rule_id: GdUDOZ
|
|
version_id: 1QTypG9
|
|
url: https://semgrep.dev/playground/r/1QTypG9/scala.lang.security.audit.io-source-ssrf.io-source-ssrf
|
|
origin: community
|
|
languages:
|
|
- scala
|
|
severity: WARNING
|
|
- id: scala.lang.security.audit.scalac-debug.scalac-debug
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: scalacOptions ... "-Vdebug"
|
|
- pattern: scalacOptions ... "-Ydebug"
|
|
message: Scala applications built with `debug` set to true in production may leak
|
|
debug information to attackers. Debug mode also affects performance and reliability.
|
|
Remove it from configuration.
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
paths:
|
|
include:
|
|
- '*.sbt*'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-489: Active Debug Code'
|
|
owasp: A05:2021 - Security Misconfiguration
|
|
technology:
|
|
- scala
|
|
- sbt
|
|
references:
|
|
- https://docs.scala-lang.org/overviews/compiler-options/index.html
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Active Debug Code
|
|
source: https://semgrep.dev/r/scala.lang.security.audit.scalac-debug.scalac-debug
|
|
shortlink: https://sg.run/QbGd
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18686
|
|
rv_id: 946569
|
|
rule_id: JDUlE0
|
|
version_id: qkT4j0N
|
|
url: https://semgrep.dev/playground/r/qkT4j0N/scala.lang.security.audit.scalac-debug.scalac-debug
|
|
origin: community
|
|
- id: scala.play.security.tainted-html-response.tainted-html-response
|
|
mode: taint
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
technology:
|
|
- scala
|
|
- play
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/scala.play.security.tainted-html-response.tainted-html-response
|
|
shortlink: https://sg.run/BG96
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18795
|
|
rv_id: 1263686
|
|
rule_id: 0oUwn2
|
|
version_id: vdT06yj
|
|
url: https://semgrep.dev/playground/r/vdT06yj/scala.play.security.tainted-html-response.tainted-html-response
|
|
origin: community
|
|
message: Detected a request with potential user-input going into an `Ok()` response.
|
|
This bypasses any view or template environments, including HTML escaping, which
|
|
may expose this application to cross-site scripting (XSS) vulnerabilities. Consider
|
|
using a view technology such as Twirl which automatically escapes HTML views.
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: $REQ
|
|
- pattern-either:
|
|
- pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- patterns:
|
|
- pattern: $PARAM
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) {
|
|
...
|
|
}
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: org.apache.commons.lang3.StringEscapeUtils.escapeHtml4(...)
|
|
- pattern: org.owasp.encoder.Encode.forHtml(...)
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- pattern: Html.apply(...)
|
|
- pattern: Ok(...).as(HTML)
|
|
- pattern: Ok(...).as(ContentTypes.HTML)
|
|
- patterns:
|
|
- pattern: Ok(...).as($CTYPE)
|
|
- metavariable-regex:
|
|
metavariable: $CTYPE
|
|
regex: '"[tT][eE][xX][tT]/[hH][tT][mM][lL]"'
|
|
- patterns:
|
|
- pattern: Ok(...).as($CTYPE)
|
|
- pattern-not: Ok(...).as("...")
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
def $FUNC(..., $URL: $T, ...) = $A {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $FUNC(..., $URL: $T, ...) = {
|
|
...
|
|
}
|
|
severity: WARNING
|
|
languages:
|
|
- scala
|
|
- id: terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
resource "aws_api_gateway_domain_name" $ANYTHING {
|
|
...
|
|
security_policy = "..."
|
|
...
|
|
}
|
|
- pattern: |
|
|
resource "aws_apigatewayv2_domain_name" $ANYTHING {
|
|
...
|
|
domain_name_configuration {...}
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
resource "aws_api_gateway_domain_name" $ANYTHING {
|
|
...
|
|
security_policy = "TLS_1_2"
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
resource "aws_apigatewayv2_domain_name" $ANYTHING {
|
|
...
|
|
domain_name_configuration {
|
|
...
|
|
security_policy = "TLS_1_2"
|
|
...
|
|
}
|
|
}
|
|
message: Detected AWS API Gateway to be using an insecure version of TLS. To fix
|
|
this issue make sure to set "security_policy" equal to "TLS_1_2".
|
|
languages:
|
|
- terraform
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version
|
|
shortlink: https://sg.run/p98J
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 18818
|
|
rv_id: 1263726
|
|
rule_id: v8UOle
|
|
version_id: o5TbD8k
|
|
url: https://semgrep.dev/playground/r/o5TbD8k/terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version
|
|
origin: community
|
|
- id: php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: openssl_encrypt($D, $M, $K, $FLAGS, "...",...);
|
|
- pattern: openssl_decrypt($D, $M, $K, $FLAGS, "...",...);
|
|
- metavariable-comparison:
|
|
metavariable: $M
|
|
comparison: re.match(".*-CBC",$M)
|
|
message: Static IV used with AES in CBC mode. Static IVs enable chosen-plaintext
|
|
attacks against encrypted data.
|
|
languages:
|
|
- php
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-329: Generation of Predictable IV with CBC Mode'
|
|
references:
|
|
- https://csrc.nist.gov/publications/detail/sp/800-38a/final
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
technology:
|
|
- php
|
|
- openssl
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv
|
|
shortlink: https://sg.run/LgWJ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19039
|
|
rv_id: 1263295
|
|
rule_id: DbUGbE
|
|
version_id: JdTzxOD
|
|
url: https://semgrep.dev/playground/r/JdTzxOD/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv
|
|
origin: community
|
|
- id: scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode
|
|
patterns:
|
|
- pattern-inside: |
|
|
import pdi.jwt.$DEPS
|
|
...
|
|
- pattern-either:
|
|
- pattern: $JWT.encode($X, "...", ...)
|
|
- pattern: $JWT.decode($X, "...", ...)
|
|
- pattern: $JWT.decodeRawAll($X, "...", ...)
|
|
- pattern: $JWT.decodeRaw($X, "...", ...)
|
|
- pattern: $JWT.decodeAll($X, "...", ...)
|
|
- pattern: $JWT.validate($X, "...", ...)
|
|
- pattern: $JWT.isValid($X, "...", ...)
|
|
- pattern: $JWT.decodeJson($X, "...", ...)
|
|
- pattern: $JWT.decodeJsonAll($X, "...", ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $JWT.encode($X, $KEY, ...)
|
|
- pattern: $JWT.decode($X, $KEY, ...)
|
|
- pattern: $JWT.decodeRawAll($X, $KEY, ...)
|
|
- pattern: $JWT.decodeRaw($X, $KEY, ...)
|
|
- pattern: $JWT.decodeAll($X, $KEY, ...)
|
|
- pattern: $JWT.validate($X, $KEY, ...)
|
|
- pattern: $JWT.isValid($X, $KEY, ...)
|
|
- pattern: $JWT.decodeJson($X, $KEY, ...)
|
|
- pattern: $JWT.decodeJsonAll($X, $KEY, ...)
|
|
- pattern: $JWT.encode($X, this.$KEY, ...)
|
|
- pattern: $JWT.decode($X, this.$KEY, ...)
|
|
- pattern: $JWT.decodeRawAll($X, this.$KEY, ...)
|
|
- pattern: $JWT.decodeRaw($X, this.$KEY, ...)
|
|
- pattern: $JWT.decodeAll($X, this.$KEY, ...)
|
|
- pattern: $JWT.validate($X, this.$KEY, ...)
|
|
- pattern: $JWT.isValid($X, this.$KEY, ...)
|
|
- pattern: $JWT.decodeJson($X, this.$KEY, ...)
|
|
- pattern: $JWT.decodeJsonAll($X, this.$KEY, ...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $CL {
|
|
...
|
|
$KEY = "..."
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
object $CL {
|
|
...
|
|
$KEY = "..."
|
|
...
|
|
}
|
|
- metavariable-pattern:
|
|
metavariable: $JWT
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: Jwt
|
|
- pattern: JwtArgonaut
|
|
- pattern: JwtCirce
|
|
- pattern: JwtJson4s
|
|
- pattern: JwtJson
|
|
- pattern: JwtUpickle
|
|
message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently
|
|
Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html
|
|
Consider using an appropriate security mechanism to protect the credentials (e.g.
|
|
keeping secrets in environment variables)'
|
|
languages:
|
|
- scala
|
|
severity: WARNING
|
|
metadata:
|
|
references:
|
|
- https://jwt-scala.github.io/jwt-scala/
|
|
category: security
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
technology:
|
|
- scala
|
|
confidence: HIGH
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode
|
|
shortlink: https://sg.run/8zE7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19040
|
|
rv_id: 1263669
|
|
rule_id: WAUdK0
|
|
version_id: o5TbDA8
|
|
url: https://semgrep.dev/playground/r/o5TbDA8/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode
|
|
origin: community
|
|
- id: scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$DF = DocumentBuilderFactory.newInstance(...)
|
|
...
|
|
$DB = $DF.newDocumentBuilder(...)
|
|
- patterns:
|
|
- pattern: $DB = DocumentBuilderFactory.newInstance(...)
|
|
- pattern-not-inside: |
|
|
...
|
|
$X = $DB.newDocumentBuilder(...)
|
|
- pattern: $DB = DocumentBuilderFactory.newInstance(...).newDocumentBuilder(...)
|
|
- pattern-not-inside: |
|
|
...
|
|
$DB.setXIncludeAware(true)
|
|
...
|
|
$DB.setNamespaceAware(true)
|
|
...
|
|
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$DB.setXIncludeAware(true)
|
|
...
|
|
$DB.setNamespaceAware(true)
|
|
...
|
|
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$DB.setXIncludeAware(true)
|
|
...
|
|
$DB.setNamespaceAware(true)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$DB.setXIncludeAware(true)
|
|
...
|
|
$DB.setNamespaceAware(true)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
...
|
|
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
message: Document Builder being instantiated without calling the `setFeature` functions
|
|
that are generally used for disabling entity processing. User controlled data
|
|
in XML Document builder can result in XML Internal Entity Processing vulnerabilities
|
|
like the disclosure of confidential data, denial of service, Server Side Request
|
|
Forgery (SSRF), port scanning. Make sure to disable entity processing functionality.
|
|
languages:
|
|
- scala
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
technology:
|
|
- scala
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled
|
|
shortlink: https://sg.run/gRQn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19041
|
|
rv_id: 1263673
|
|
rule_id: 0oUwzP
|
|
version_id: X0TzyRq
|
|
url: https://semgrep.dev/playground/r/X0TzyRq/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled
|
|
origin: community
|
|
- id: scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: $SR = new SAXReader(...)
|
|
- pattern: |
|
|
$SF = SAXParserFactory.newInstance(...)
|
|
...
|
|
$SR = $SF.newSAXParser(...)
|
|
- patterns:
|
|
- pattern: $SR = SAXParserFactory.newInstance(...)
|
|
- pattern-not-inside: |
|
|
...
|
|
$X = $SR.newSAXParser(...)
|
|
- pattern: $SR = SAXParserFactory.newInstance(...).newSAXParser(...)
|
|
- pattern: $SR = new SAXBuilder(...)
|
|
- pattern-not-inside: |
|
|
...
|
|
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
- pattern-not-inside: |
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
|
|
...
|
|
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
|
|
...
|
|
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
|
|
message: XML processor being instantiated without calling the `setFeature` functions
|
|
that are generally used for disabling entity processing. User controlled data
|
|
in XML Parsers can result in XML Internal Entity Processing vulnerabilities like
|
|
the disclosure of confidential data, denial of service, Server Side Request Forgery
|
|
(SSRF), port scanning. Make sure to disable entity processing functionality.
|
|
languages:
|
|
- scala
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
technology:
|
|
- scala
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled
|
|
shortlink: https://sg.run/QbYP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19042
|
|
rv_id: 1263678
|
|
rule_id: KxUrkq
|
|
version_id: rxTAKWY
|
|
url: https://semgrep.dev/playground/r/rxTAKWY/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled
|
|
origin: community
|
|
- id: scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
...
|
|
$XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false)
|
|
- pattern-either:
|
|
- pattern: $XMLFACTORY = XMLInputFactory.newFactory(...)
|
|
- pattern: $XMLFACTORY = XMLInputFactory.newInstance(...)
|
|
- pattern: $XMLFACTORY = new XMLInputFactory(...)
|
|
message: XMLInputFactory being instantiated without calling the setProperty functions
|
|
that are generally used for disabling entity processing. User controlled data
|
|
in XML Document builder can result in XML Internal Entity Processing vulnerabilities
|
|
like the disclosure of confidential data, denial of service, Server Side Request
|
|
Forgery (SSRF), port scanning. Make sure to disable entity processing functionality.
|
|
languages:
|
|
- scala
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
technology:
|
|
- scala
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled
|
|
shortlink: https://sg.run/3BEb
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19043
|
|
rv_id: 1263683
|
|
rule_id: qNUQ7w
|
|
version_id: xyTjzkA
|
|
url: https://semgrep.dev/playground/r/xyTjzkA/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled
|
|
origin: community
|
|
- id: scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: X-Requested-With = "*"
|
|
- pattern: Csrf-Token = "..."
|
|
- pattern-inside: |
|
|
bypassHeaders {...
|
|
...
|
|
...}
|
|
- pattern-not-inside: |
|
|
{...
|
|
...
|
|
...blackList = [..."application/x-www-form-urlencoded"..."multipart/form-data"..."text/plain"...]
|
|
...
|
|
...}
|
|
- pattern-not-inside: |
|
|
{...
|
|
...
|
|
...blackList = [..."application/x-www-form-urlencoded"..."text/plain"..."multipart/form-data"...]
|
|
...
|
|
...}
|
|
- pattern-not-inside: |
|
|
{...
|
|
...
|
|
...blackList = [..."multipart/form-data"..."application/x-www-form-urlencoded"..."text/plain"...]
|
|
...
|
|
...}
|
|
- pattern-not-inside: |
|
|
{...
|
|
...
|
|
...blackList = [..."multipart/form-data"..."text/plain"..."application/x-www-form-urlencoded"...]
|
|
...
|
|
...}
|
|
- pattern-not-inside: |
|
|
{...
|
|
...
|
|
...blackList = [..."text/plain"..."application/x-www-form-urlencoded"..."multipart/form-data"...]
|
|
...
|
|
...}
|
|
- pattern-not-inside: |
|
|
{...
|
|
...
|
|
...blackList = [..."text/plain"..."multipart/form-data"..."application/x-www-form-urlencoded"...]
|
|
...
|
|
...}
|
|
message: "Possibly bypassable CSRF configuration found. CSRF is an attack that forces
|
|
an end user to execute unwanted actions on a web application in which they\u2019re
|
|
currently authenticated. Make sure that Content-Type black list is configured
|
|
and CORS filter is turned on."
|
|
languages:
|
|
- generic
|
|
severity: ERROR
|
|
paths:
|
|
include:
|
|
- '*.conf'
|
|
metadata:
|
|
references:
|
|
- https://www.playframework.com/documentation/2.8.x/Migration25#CSRF-changes
|
|
- https://owasp.org/www-community/attacks/csrf
|
|
cwe:
|
|
- 'CWE-352: Cross-Site Request Forgery (CSRF)'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- scala
|
|
- play
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site Request Forgery (CSRF)
|
|
source: https://semgrep.dev/r/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass
|
|
shortlink: https://sg.run/4DEE
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19044
|
|
rv_id: 1263684
|
|
rule_id: lBUyRR
|
|
version_id: O9Tpx53
|
|
url: https://semgrep.dev/playground/r/O9Tpx53/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass
|
|
origin: community
|
|
- id: terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version
|
|
pattern: |
|
|
resource "aws_elasticsearch_domain" $ANYTHING {
|
|
...
|
|
domain_endpoint_options {
|
|
...
|
|
enforce_https = true
|
|
tls_security_policy = "Policy-Min-TLS-1-0-2019-07"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
message: Detected an AWS Elasticsearch domain using an insecure version of TLS.
|
|
To fix this, set "tls_security_policy" equal to "Policy-Min-TLS-1-2-2019-07".
|
|
languages:
|
|
- terraform
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version
|
|
shortlink: https://sg.run/PYlq
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19045
|
|
rv_id: 1263718
|
|
rule_id: YGUle7
|
|
version_id: DkTRbA5
|
|
url: https://semgrep.dev/playground/r/DkTRbA5/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version
|
|
origin: community
|
|
- id: javascript.express.security.express-insecure-template-usage.express-insecure-template-usage
|
|
message: User data from `$REQ` is being compiled into the template, which can lead
|
|
to a Server Side Template Injection (SSTI) vulnerability.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
category: security
|
|
cwe:
|
|
- 'CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A01:2017 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html
|
|
technology:
|
|
- javascript
|
|
- typescript
|
|
- express
|
|
- pug
|
|
- jade
|
|
- dot
|
|
- ejs
|
|
- nunjucks
|
|
- lodash
|
|
- handlbars
|
|
- mustache
|
|
- hogan.js
|
|
- eta
|
|
- squirrelly
|
|
source_rule_url:
|
|
- https://github.com/github/codeql/blob/2ba2642c7ab29b9eedef33bcc2b8cd1d203d0c10/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/template-sinks.js
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage
|
|
shortlink: https://sg.run/b49v
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 19226
|
|
rv_id: 1263165
|
|
rule_id: EwUr9k
|
|
version_id: zyTb2eD
|
|
url: https://semgrep.dev/playground/r/zyTb2eD/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-propagators:
|
|
- pattern: $MODEL.$FIND($E).then((...,$S,...)=>{...})
|
|
from: $E
|
|
to: $S
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PUG = require('pug')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $PUG from 'pug'
|
|
...
|
|
- pattern-inside: |
|
|
$PUG = require('jade')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $PUG from 'jade'
|
|
...
|
|
- pattern-either:
|
|
- pattern: $PUG.compile(...)
|
|
- pattern: $PUG.compileClient(...)
|
|
- pattern: $PUG.compileClientWithDependenciesTracked(...)
|
|
- pattern: $PUG.render(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PUG = require('dot')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $PUG from 'dot'
|
|
...
|
|
- pattern-either:
|
|
- pattern: $PUG.template(...)
|
|
- pattern: $PUG.compile(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PUG = require('ejs')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $PUG from 'ejs'
|
|
...
|
|
- pattern-either:
|
|
- pattern: $PUG.render(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PUG = require('nunjucks')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $PUG from 'nunjucks'
|
|
...
|
|
- pattern-either:
|
|
- pattern: $PUG.renderString(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PUG = require('lodash')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $PUG from 'lodash'
|
|
...
|
|
- pattern-either:
|
|
- pattern: $PUG.template(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PUG = require('mustache')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $PUG from 'mustache'
|
|
...
|
|
- pattern-inside: |
|
|
$PUG = require('eta')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $PUG from 'eta'
|
|
...
|
|
- pattern-inside: |
|
|
$PUG = require('squirrelly')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $PUG from 'squirrelly'
|
|
...
|
|
- pattern-either:
|
|
- pattern: $PUG.render(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$PUG = require('hogan.js')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $PUG from 'hogan.js'
|
|
...
|
|
- pattern-inside: |
|
|
$PUG = require('handlebars')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $PUG from 'handlebars'
|
|
...
|
|
- pattern-either:
|
|
- pattern: $PUG.compile(...)
|
|
- id: python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled
|
|
patterns:
|
|
- pattern: jinja2.Environment(... , autoescape=$VAL, ...)
|
|
- pattern-not: jinja2.Environment(... , autoescape=True, ...)
|
|
- pattern-not: jinja2.Environment(... , autoescape=jinja2.select_autoescape(...),
|
|
...)
|
|
- focus-metavariable: $VAL
|
|
fix: |
|
|
True
|
|
message: Detected a Jinja2 environment with 'autoescaping' disabled. This is dangerous
|
|
if you are rendering to a browser because this allows for cross-site scripting
|
|
(XSS) attacks. If you are in a web context, enable 'autoescaping' by setting 'autoescape=True.'
|
|
You may also consider using 'jinja2.select_autoescape()' to only enable automatic
|
|
escaping for certain file extensions.
|
|
metadata:
|
|
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html
|
|
cwe:
|
|
- 'CWE-116: Improper Encoding or Escaping of Output'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://jinja.palletsprojects.com/en/2.11.x/api/#basics
|
|
category: security
|
|
technology:
|
|
- jinja2
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Encoding
|
|
source: https://semgrep.dev/r/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled
|
|
shortlink: https://sg.run/L2L7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20039
|
|
rv_id: 1263448
|
|
rule_id: QrU1Xg
|
|
version_id: gETB7oN
|
|
url: https://semgrep.dev/playground/r/gETB7oN/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled
|
|
patterns:
|
|
- pattern-not: jinja2.Environment(..., autoescape=$VAL, ...)
|
|
- pattern: jinja2.Environment(...)
|
|
fix-regex:
|
|
regex: (.*)\)
|
|
replacement: \1, autoescape=True)
|
|
message: Detected a Jinja2 environment without autoescaping. Jinja2 does not autoescape
|
|
by default. This is dangerous if you are rendering to a browser because this allows
|
|
for cross-site scripting (XSS) attacks. If you are in a web context, enable autoescaping
|
|
by setting 'autoescape=True.' You may also consider using 'jinja2.select_autoescape()'
|
|
to only enable automatic escaping for certain file extensions.
|
|
metadata:
|
|
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html
|
|
cwe:
|
|
- 'CWE-116: Improper Encoding or Escaping of Output'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://jinja.palletsprojects.com/en/2.11.x/api/#basics
|
|
category: security
|
|
technology:
|
|
- jinja2
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Encoding
|
|
source: https://semgrep.dev/r/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled
|
|
shortlink: https://sg.run/8kY4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20040
|
|
rv_id: 1263449
|
|
rule_id: 3qULRx
|
|
version_id: QkTGqje
|
|
url: https://semgrep.dev/playground/r/QkTGqje/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include
|
|
mode: search
|
|
paths:
|
|
include:
|
|
- '*.erb'
|
|
patterns:
|
|
- pattern: |
|
|
params[...]
|
|
- pattern-inside: |
|
|
render :file => ...
|
|
message: Found request parameters in a call to `render` in a dynamic context. This
|
|
can allow end users to request arbitrary local files which may result in leaking
|
|
sensitive information persisted on disk.
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
metadata:
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
category: security
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb
|
|
references:
|
|
- https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion
|
|
- https://github.com/presidentbeef/brakeman/blob/f74cb53ead47f0af821d98b5b41e16d63100c240/test/apps/rails2/app/views/home/test_render.html.erb
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include
|
|
shortlink: https://sg.run/3QWl
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20043
|
|
rv_id: 1263651
|
|
rule_id: JDUokO
|
|
version_id: QkTGq9X
|
|
url: https://semgrep.dev/playground/r/QkTGq9X/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include
|
|
origin: community
|
|
- id: ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: params[...]
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
render ..., file: $X
|
|
- pattern: |
|
|
render ..., inline: $X
|
|
- pattern: |
|
|
render ..., template: $X
|
|
- pattern: |
|
|
render ..., action: $X
|
|
- pattern: |
|
|
render $X, ...
|
|
- focus-metavariable: $X
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: $MAP[...]
|
|
- metavariable-pattern:
|
|
metavariable: $MAP
|
|
patterns:
|
|
- pattern-not-regex: params
|
|
- pattern: File.basename(...)
|
|
message: Found request parameters in a call to `render`. This can allow end users
|
|
to request arbitrary local files which may result in leaking sensitive information
|
|
persisted on disk. Where possible, avoid letting users specify template paths
|
|
for `render`. If you must allow user input, use an allow-list of known templates
|
|
or normalize the user-supplied value with `File.basename(...)`.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
metadata:
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
category: security
|
|
cwe:
|
|
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
|
|
Traversal'')'
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb
|
|
references:
|
|
- https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion
|
|
- https://github.com/presidentbeef/brakeman/blob/f74cb53/test/apps/rails2/app/controllers/home_controller.rb#L48-L60
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include
|
|
shortlink: https://sg.run/Jw8Z
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20046
|
|
rv_id: 1409407
|
|
rule_id: ReU2pZ
|
|
version_id: K3TgANN
|
|
url: https://semgrep.dev/playground/r/K3TgANN/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include
|
|
origin: community
|
|
- id: ruby.rails.security.brakeman.check-secrets.check-secrets
|
|
patterns:
|
|
- pattern: $VAR = "$VALUE"
|
|
- metavariable-regex:
|
|
metavariable: $VAR
|
|
regex: (?i)password|secret|(rest_auth_site|api)_key$
|
|
- metavariable-regex:
|
|
metavariable: $VALUE
|
|
regex: .+
|
|
message: Found a Brakeman-style secret - a variable with the name password/secret/api_key/rest_auth_site_key
|
|
and a non-empty string literal value.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
metadata:
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
category: security
|
|
cwe:
|
|
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_secrets.rb
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
- https://github.com/presidentbeef/brakeman/blob/3f5d5d5f00864cdf7769c50f5bd26f1769a4ba75/test/apps/rails3.1/app/controllers/users_controller.rb
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-secrets.check-secrets
|
|
shortlink: https://sg.run/5ZKl
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20047
|
|
rv_id: 1263659
|
|
rule_id: AbUNqO
|
|
version_id: A8TgdBv
|
|
url: https://semgrep.dev/playground/r/A8TgdBv/ruby.rails.security.brakeman.check-secrets.check-secrets
|
|
origin: community
|
|
- id: ruby.rails.security.brakeman.check-send-file.check-send-file
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- pattern: |
|
|
cookies[...]
|
|
- patterns:
|
|
- pattern: |
|
|
cookies. ... .$PROPERTY[...]
|
|
- metavariable-regex:
|
|
metavariable: $PROPERTY
|
|
regex: (?!signed|encrypted)
|
|
- pattern: |
|
|
params[...]
|
|
- pattern: |
|
|
request.env[...]
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
send_file ...
|
|
message: Allowing user input to `send_file` allows a malicious user to potentially
|
|
read arbitrary files from the server. Avoid accepting user input in `send_file`
|
|
or normalize with `File.basename(...)`
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_send_file.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-73: External Control of File Name or Path'
|
|
owasp:
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Path_Traversal
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-send-file.check-send-file
|
|
shortlink: https://sg.run/GbY1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20048
|
|
rv_id: 1263660
|
|
rule_id: BYUKbl
|
|
version_id: BjTkZRj
|
|
url: https://semgrep.dev/playground/r/BjTkZRj/ruby.rails.security.brakeman.check-send-file.check-send-file
|
|
origin: community
|
|
- id: scala.lang.security.audit.tainted-sql-string.tainted-sql-string
|
|
languages:
|
|
- scala
|
|
severity: ERROR
|
|
mode: taint
|
|
message: User data flows into this manually-constructed SQL string. User data can
|
|
be safely inserted into SQL strings using prepared statements or an object-relational
|
|
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
|
|
injection, which could let an attacker steal or manipulate data from the database.
|
|
Instead, use prepared statements (`connection.PreparedStatement`) or a safe library.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html
|
|
category: security
|
|
technology:
|
|
- scala
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/scala.lang.security.audit.tainted-sql-string.tainted-sql-string
|
|
shortlink: https://sg.run/ALD6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20050
|
|
rv_id: 1263682
|
|
rule_id: WAUY8B
|
|
version_id: w8TRoO6
|
|
url: https://semgrep.dev/playground/r/w8TRoO6/scala.lang.security.audit.tainted-sql-string.tainted-sql-string
|
|
origin: community
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: $PARAM
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = $A {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = $A(...) {
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$SQLSTR" + ...
|
|
- pattern: |
|
|
"$SQLSTR".format(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$SB = new StringBuilder("$SQLSTR");
|
|
...
|
|
- pattern: $SB.append(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VAR = "$SQLSTR"
|
|
...
|
|
- pattern: $VAR += ...
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(select|delete|insert|create|update|alter|drop)\b
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: s"..."
|
|
- pattern: f"..."
|
|
- pattern-regex: |
|
|
.*\b(?i)(select|delete|insert|create|update|alter|drop)\b.*
|
|
- pattern-not-inside: println(...)
|
|
- pattern-not-inside: throw new $EXCEPTION(...)
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $LOGGER.$METHOD(...)
|
|
- pattern: $LOGGER(...)
|
|
- metavariable-regex:
|
|
metavariable: $LOGGER
|
|
regex: (i?)log.*
|
|
- patterns:
|
|
- pattern: $LOGGER.$METHOD(...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (i?)(trace|info|warn|warning|warnToError|error|debug)
|
|
- id: scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
languages:
|
|
- scala
|
|
severity: ERROR
|
|
mode: taint
|
|
message: User data flows into this manually-constructed SQL string. User data can
|
|
be safely inserted into SQL strings using prepared statements or an object-relational
|
|
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
|
|
injection, which could let an attacker steal or manipulate data from the database.
|
|
Instead, use prepared statements (`connection.PreparedStatement`) or a safe library.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html
|
|
category: security
|
|
technology:
|
|
- scala
|
|
- play
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
shortlink: https://sg.run/BeW9
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20051
|
|
rv_id: 1263688
|
|
rule_id: 0oUpon
|
|
version_id: ZRTKAoG
|
|
url: https://semgrep.dev/playground/r/ZRTKAoG/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request
|
|
origin: community
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: $REQ
|
|
- pattern-either:
|
|
- pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n"
|
|
- patterns:
|
|
- pattern: $PARAM
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) {
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$SQLSTR" + ...
|
|
- pattern: |
|
|
"$SQLSTR".format(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$SB = new StringBuilder("$SQLSTR");
|
|
...
|
|
- pattern: $SB.append(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VAR = "$SQLSTR"
|
|
...
|
|
- pattern: $VAR += ...
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(select|delete|insert|create|update|alter|drop)\b
|
|
- patterns:
|
|
- pattern: s"..."
|
|
- pattern-regex: |
|
|
.*\b(?i)(select|delete|insert|create|update|alter|drop)\b.*
|
|
- pattern-not-inside: println(...)
|
|
- id: yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file
|
|
patterns:
|
|
- pattern: |
|
|
$KEY: $VALUE
|
|
- pattern-inside: |
|
|
data: ...
|
|
- pattern-inside: |
|
|
kind: Secret
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $VALUE
|
|
regex: (?i)^[aA-zZ0-9+/]+={0,2}$
|
|
- metavariable-analysis:
|
|
analyzer: entropy
|
|
metavariable: $VALUE
|
|
message: 'Secrets ($VALUE) should not be stored in infrastructure as code files.
|
|
Use an alternative such as Bitnami Sealed Secrets or KSOPS to encrypt Kubernetes
|
|
Secrets. '
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
category: security
|
|
technology:
|
|
- kubernetes
|
|
references:
|
|
- https://kubernetes.io/docs/concepts/configuration/secret/
|
|
- https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/0/CTR_Kubernetes_Hardening_Guidance_1.1_20220315.PDF
|
|
- https://docs.gitlab.com/ee/user/clusters/agent/gitops/secrets_management.html
|
|
- https://www.cncf.io/blog/2021/04/22/revealing-the-secrets-of-kubernetes-secrets/
|
|
- https://github.com/bitnami-labs/sealed-secrets
|
|
- https://www.cncf.io/blog/2022/01/25/secrets-management-essential-when-using-kubernetes/
|
|
- https://blog.oddbit.com/post/2021-03-09-getting-started-with-ksops/
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file
|
|
shortlink: https://sg.run/KyL6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20055
|
|
rv_id: 1263942
|
|
rule_id: YGUYEb
|
|
version_id: xyTjz5B
|
|
url: https://semgrep.dev/playground/r/xyTjz5B/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file
|
|
origin: community
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
- id: dockerfile.security.last-user-is-root.last-user-is-root
|
|
patterns:
|
|
- pattern: USER root
|
|
- pattern-not-inside:
|
|
patterns:
|
|
- pattern: |
|
|
USER root
|
|
...
|
|
USER $X
|
|
- metavariable-pattern:
|
|
metavariable: $X
|
|
patterns:
|
|
- pattern-not: root
|
|
message: The last user in the container is 'root'. This is a security hazard because
|
|
if an attacker gains control of the container they will have root access. Switch
|
|
back to another user after running commands as 'root'.
|
|
severity: ERROR
|
|
languages:
|
|
- dockerfile
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-269: Improper Privilege Management'
|
|
source-rule-url: https://github.com/hadolint/hadolint/wiki/DL3002
|
|
references:
|
|
- https://github.com/hadolint/hadolint/wiki/DL3002
|
|
category: security
|
|
technology:
|
|
- dockerfile
|
|
confidence: MEDIUM
|
|
owasp:
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/dockerfile.security.last-user-is-root.last-user-is-root
|
|
shortlink: https://sg.run/5Z43
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20147
|
|
rv_id: 1262658
|
|
rule_id: ReU2n5
|
|
version_id: 6xT29Eg
|
|
url: https://semgrep.dev/playground/r/6xT29Eg/dockerfile.security.last-user-is-root.last-user-is-root
|
|
origin: community
|
|
- id: dockerfile.security.missing-user.missing-user
|
|
patterns:
|
|
- pattern: |
|
|
CMD $...VARS
|
|
- pattern-not-inside: |
|
|
USER $USER
|
|
...
|
|
- pattern-not-inside: |
|
|
HEALTHCHECK ... CMD ...
|
|
fix: |
|
|
USER non-root
|
|
CMD $...VARS
|
|
message: By not specifying a USER, a program in the container may run as 'root'.
|
|
This is a security hazard. If an attacker can control a process running as root,
|
|
they may have control over the container. Ensure that the last USER in a Dockerfile
|
|
is a USER other than 'root'.
|
|
severity: ERROR
|
|
languages:
|
|
- dockerfile
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-250: Execution with Unnecessary Privileges'
|
|
category: security
|
|
technology:
|
|
- dockerfile
|
|
confidence: MEDIUM
|
|
owasp:
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/dockerfile.security.missing-user.missing-user
|
|
shortlink: https://sg.run/Gbvn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20148
|
|
rv_id: 1262660
|
|
rule_id: AbUN06
|
|
version_id: zyTb2n2
|
|
url: https://semgrep.dev/playground/r/zyTb2n2/dockerfile.security.missing-user.missing-user
|
|
origin: community
|
|
- id: javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config
|
|
message: Prefer Argon2id where possible. Per RFC9016, section 4 IETF recommends
|
|
selecting Argon2id unless you can guarantee an adversary has no direct access
|
|
to the computing environment.
|
|
metadata:
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
|
|
- https://eprint.iacr.org/2016/759.pdf
|
|
- https://www.cs.tau.ac.il/~tromer/papers/cache-joc-20090619.pdf
|
|
- https://datatracker.ietf.org/doc/html/rfc9106#section-4
|
|
category: security
|
|
cwe:
|
|
- 'CWE-916: Use of Password Hash With Insufficient Computational Effort'
|
|
technology:
|
|
- argon2
|
|
- cryptography
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
impact: LOW
|
|
likelihood: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config
|
|
shortlink: https://sg.run/ALq4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20150
|
|
rv_id: 1263103
|
|
rule_id: DbU2X8
|
|
version_id: qkTR7Jk
|
|
url: https://semgrep.dev/playground/r/qkTR7Jk/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ARGON = require('argon2');
|
|
...
|
|
- pattern: |
|
|
{type: ...}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
$Y
|
|
- pattern-inside: |
|
|
$ARGON.hash(...,$Y)
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: '{type: $ARGON.argon2id}'
|
|
- id: ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
:$KEY => "$LITERAL"
|
|
- pattern-inside: |
|
|
ActionController::Base.session = {...}
|
|
- pattern: |
|
|
$RAILS::Application.config.$KEY = "$LITERAL"
|
|
- pattern: |
|
|
Rails.application.config.$KEY = "$LITERAL"
|
|
- metavariable-regex:
|
|
metavariable: $KEY
|
|
regex: ^secret(_(token|key_base))?$
|
|
message: Found a string literal assignment to a Rails session secret `$KEY`. Do
|
|
not commit secret values to source control! Any user in possession of this value
|
|
may falsify arbitrary session data in your application. Read this value from an
|
|
environment variable, KMS, or file on disk outside of source control.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_session_settings.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-540: Inclusion of Sensitive Information in Source Code'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/06-Session_Management_Testing/02-Testing_for_Cookies_Attributes
|
|
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails4_with_engines/config/initializers/secret_token.rb
|
|
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3/config/initializers/secret_token.rb
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling
|
|
shortlink: https://sg.run/KyJd
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20155
|
|
rv_id: 1263656
|
|
rule_id: lBUX1r
|
|
version_id: 5PTo1ZY
|
|
url: https://semgrep.dev/playground/r/5PTo1ZY/ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling
|
|
origin: community
|
|
- id: ruby.rails.security.brakeman.check-regex-dos.check-regex-dos
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
cookies[...]
|
|
- patterns:
|
|
- pattern: |
|
|
cookies. ... .$PROPERTY[...]
|
|
- metavariable-regex:
|
|
metavariable: $PROPERTY
|
|
regex: (?!signed|encrypted)
|
|
- pattern: |
|
|
params[...]
|
|
- pattern: |
|
|
request.env[...]
|
|
- patterns:
|
|
- pattern: $Y
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$RECORD.read_attribute($Y)
|
|
- pattern-inside: |
|
|
$RECORD[$Y]
|
|
- metavariable-regex:
|
|
metavariable: $RECORD
|
|
regex: '[A-Z][a-z]+'
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: $Y
|
|
- pattern-inside: |
|
|
/...#{...}.../
|
|
- patterns:
|
|
- pattern: $Y
|
|
- pattern-inside: |
|
|
Regexp.new(...)
|
|
message: Found a potentially user-controllable argument in the construction of a
|
|
regular expressions. This may result in excessive resource consumption when applied
|
|
to certain inputs, or when the user is allowed to control the match target. Avoid
|
|
allowing users to specify regular expressions processed by the server. If you
|
|
must support user-controllable input in a regular expression, use an allow-list
|
|
to restrict the expressions users may supply to limit catastrophic backtracking.
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_regex_dos.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-1333: Inefficient Regular Expression Complexity'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Denial-of-Service (DoS)
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos
|
|
shortlink: https://sg.run/qZwx
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20156
|
|
rv_id: 1409406
|
|
rule_id: YGUY4R
|
|
version_id: 0bTG0WO
|
|
url: https://semgrep.dev/playground/r/0bTG0WO/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos
|
|
origin: community
|
|
- id: ruby.rails.security.brakeman.check-before-filter.check-before-filter
|
|
mode: search
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
skip_filter ..., :except => $ARGS
|
|
- pattern: |
|
|
skip_before_filter ..., :except => $ARGS
|
|
- pattern: |
|
|
skip_before_action ..., :except => $ARGS
|
|
message: 'Disabled-by-default Rails controller checks make it much easier to introduce
|
|
access control mistakes. Prefer an allowlist approach with `:only => [...]` rather
|
|
than `except: => [...]`'
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_skip_before_filter.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-284: Improper Access Control'
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-before-filter.check-before-filter
|
|
shortlink: https://sg.run/O4Zn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20531
|
|
rv_id: 1263649
|
|
rule_id: wdUkBP
|
|
version_id: 8KT5rDy
|
|
url: https://semgrep.dev/playground/r/8KT5rDy/ruby.rails.security.brakeman.check-before-filter.check-before-filter
|
|
origin: community
|
|
- id: ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion
|
|
mode: search
|
|
patterns:
|
|
- pattern: |
|
|
if request.get?
|
|
...
|
|
else
|
|
...
|
|
end
|
|
- pattern-not-inside: |
|
|
if ...
|
|
elsif ...
|
|
...
|
|
end
|
|
message: Found an improperly constructed control flow block with `request.get?`.
|
|
Rails will route HEAD requests as GET requests but they will fail the `request.get?`
|
|
check, potentially causing unexpected behavior unless an `elif` condition is used.
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_verb_confusion.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-650: Trusting HTTP Permission Methods on the Server Side'
|
|
owasp:
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/accounts_controller.rb
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion
|
|
shortlink: https://sg.run/eJ6y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20532
|
|
rv_id: 1263652
|
|
rule_id: x8UdDE
|
|
version_id: 3ZT4X82
|
|
url: https://semgrep.dev/playground/r/3ZT4X82/ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion
|
|
origin: community
|
|
- id: ruby.rails.security.brakeman.check-sql.check-sql
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- pattern: |
|
|
cookies[...]
|
|
- patterns:
|
|
- pattern: |
|
|
cookies. ... .$PROPERTY[...]
|
|
- metavariable-regex:
|
|
metavariable: $PROPERTY
|
|
regex: (?!signed|encrypted)
|
|
- pattern: |
|
|
params[...]
|
|
- pattern: |
|
|
request.env[...]
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: $X
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
:$KEY => $X
|
|
- pattern-inside: |
|
|
["...",$X,...]
|
|
- pattern: |
|
|
params[...].to_i
|
|
- pattern: |
|
|
params[...].to_f
|
|
- patterns:
|
|
- pattern: |
|
|
params[...] ? $A : $B
|
|
- metavariable-pattern:
|
|
metavariable: $A
|
|
patterns:
|
|
- pattern-not: |
|
|
params[...]
|
|
- metavariable-pattern:
|
|
metavariable: $B
|
|
patterns:
|
|
- pattern-not: |
|
|
params[...]
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $X
|
|
- pattern-not-inside: |
|
|
$P.where("...",...)
|
|
- pattern-not-inside: |
|
|
$P.where(:$KEY => $VAL,...)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$P.$M(...)
|
|
- pattern-inside: |
|
|
$P.$M("...",...)
|
|
- pattern-inside: |
|
|
class $P < ActiveRecord::Base
|
|
...
|
|
end
|
|
- metavariable-regex:
|
|
metavariable: $M
|
|
regex: (where|find|first|last|select|minimum|maximum|calculate|sum|average)
|
|
message: Found potential SQL injection due to unsafe SQL query construction via
|
|
$X. Where possible, prefer parameterized queries.
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_sql.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://owasp.org/www-community/attacks/SQL_Injection
|
|
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/product.rb
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-sql.check-sql
|
|
shortlink: https://sg.run/vpgb
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20533
|
|
rv_id: 1263661
|
|
rule_id: OrUv2z
|
|
version_id: DkTRbE4
|
|
url: https://semgrep.dev/playground/r/DkTRbE4/ruby.rails.security.brakeman.check-sql.check-sql
|
|
origin: community
|
|
- id: ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- pattern: |
|
|
cookies[...]
|
|
- patterns:
|
|
- pattern: |
|
|
cookies. ... .$PROPERTY[...]
|
|
- metavariable-regex:
|
|
metavariable: $PROPERTY
|
|
regex: (?!signed|encrypted)
|
|
- pattern: |
|
|
params[...]
|
|
- pattern: |
|
|
request.env[...]
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $X
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$X. ... .to_proc
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$Y.method($Z)
|
|
- focus-metavariable: $Z
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$Y.tap($Z)
|
|
- focus-metavariable: $Z
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$Y.tap{ |$ANY| $Z }
|
|
- focus-metavariable: $Z
|
|
message: Found user-controllable input to a reflection method. This may allow a
|
|
user to alter program behavior and potentially execute arbitrary instructions
|
|
in the context of the process. Do not provide arbitrary user input to `tap`, `method`,
|
|
or `to_proc`
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection_methods.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/groups_controller.rb
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods
|
|
shortlink: https://sg.run/dPYd
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20534
|
|
rv_id: 1263662
|
|
rule_id: eqUZ2Q
|
|
version_id: WrTqKLA
|
|
url: https://semgrep.dev/playground/r/WrTqKLA/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods
|
|
origin: community
|
|
- id: ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase
|
|
message: Found the use of an hardcoded passphrase for RSA. The passphrase can be
|
|
easily discovered, and therefore should not be stored in source-code. It is recommended
|
|
to remove the passphrase from source-code, and use system environment variables
|
|
or a restricted configuration file.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
metadata:
|
|
technology:
|
|
- ruby
|
|
- secrets
|
|
category: security
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/522.html
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase
|
|
shortlink: https://sg.run/xPEe
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20730
|
|
rv_id: 1263607
|
|
rule_id: bwULyN
|
|
version_id: K3TKkEo
|
|
url: https://semgrep.dev/playground/r/K3TKkEo/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: OpenSSL::PKey::RSA.new(..., '...')
|
|
- pattern: OpenSSL::PKey::RSA.new(...).to_pem(..., '...')
|
|
- pattern: OpenSSL::PKey::RSA.new(...).export(..., '...')
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$OPENSSL = OpenSSL::PKey::RSA.new(...)
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
$OPENSSL.export(...,'...')
|
|
- pattern: |
|
|
$OPENSSL.to_pem(...,'...')
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ASSIGN = '...'
|
|
...
|
|
- pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $METHOD1(...)
|
|
...
|
|
$ASSIGN = '...'
|
|
...
|
|
end
|
|
...
|
|
def $METHOD2(...)
|
|
...
|
|
end
|
|
- pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ASSIGN = '...'
|
|
...
|
|
def $METHOD(...)
|
|
$OPENSSL = OpenSSL::PKey::RSA.new(...)
|
|
...
|
|
end
|
|
...
|
|
- pattern-either:
|
|
- pattern: $OPENSSL.export(...,$ASSIGN)
|
|
- pattern: $OPENSSL.to_pem(...,$ASSIGN)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $METHOD1(...)
|
|
...
|
|
$OPENSSL = OpenSSL::PKey::RSA.new(...)
|
|
...
|
|
$ASSIGN = '...'
|
|
...
|
|
end
|
|
...
|
|
- pattern-either:
|
|
- pattern: $OPENSSL.export(...,$ASSIGN)
|
|
- pattern: $OPENSSL.to_pem(...,$ASSIGN)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $METHOD1(...)
|
|
...
|
|
$ASSIGN = '...'
|
|
...
|
|
end
|
|
...
|
|
def $METHOD2(...)
|
|
...
|
|
$OPENSSL = OpenSSL::PKey::RSA.new(...)
|
|
...
|
|
end
|
|
...
|
|
- pattern-either:
|
|
- pattern: $OPENSSL.export(...,$ASSIGN)
|
|
- pattern: $OPENSSL.to_pem(...,$ASSIGN)
|
|
- id: ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
message: The RSA key size $SIZE is insufficent by NIST standards. It is recommended
|
|
to use a key length of 2048 or higher.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
metadata:
|
|
technology:
|
|
- ruby
|
|
category: security
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
shortlink: https://sg.run/O4Re
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20731
|
|
rv_id: 1263608
|
|
rule_id: NbUe4N
|
|
version_id: qkTR76v
|
|
url: https://semgrep.dev/playground/r/qkTR76v/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: OpenSSL::PKey::RSA.generate($SIZE,...)
|
|
- pattern: OpenSSL::PKey::RSA.new($SIZE, ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$ASSIGN = $SIZE
|
|
...
|
|
- pattern-either:
|
|
- pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...)
|
|
- pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $METHOD1(...)
|
|
...
|
|
$ASSIGN = $SIZE
|
|
...
|
|
end
|
|
...
|
|
- pattern-either:
|
|
- pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...)
|
|
- pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...)
|
|
- metavariable-comparison:
|
|
metavariable: $SIZE
|
|
comparison: $SIZE < 2048
|
|
- id: ruby.rails.security.brakeman.check-redirect-to.check-redirect-to
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: cookies
|
|
- pattern: request.env
|
|
- pattern: url_for(params[...],...,:only_path => false,...)
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
$F(...)
|
|
- metavariable-pattern:
|
|
metavariable: $F
|
|
patterns:
|
|
- pattern-not-regex: (params|url_for|cookies|request.env|permit|redirect_to)
|
|
- pattern: |
|
|
params.merge! :only_path => true
|
|
...
|
|
- pattern: |
|
|
params.slice(...)
|
|
...
|
|
- pattern: |
|
|
redirect_to [...]
|
|
- patterns:
|
|
- pattern: |
|
|
$MODEL. ... .$M(...)
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $MODEL
|
|
regex: '[A-Z]\w+'
|
|
- metavariable-regex:
|
|
metavariable: $M
|
|
regex: (all|create|find|find_by|find_by_sql|first|last|new|from|group|having|joins|lock|order|reorder|select|where|take)
|
|
- patterns:
|
|
- pattern: |
|
|
params.$UNSAFE_HASH.merge(...,:only_path => true,...)
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $UNSAFE_HASH
|
|
regex: to_unsafe_h(ash)?
|
|
- patterns:
|
|
- pattern: params.permit(...,$X,...)
|
|
- metavariable-pattern:
|
|
metavariable: $X
|
|
patterns:
|
|
- pattern-not-regex: (host|port|(sub)?domain)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $X
|
|
- pattern-inside: |
|
|
redirect_to $X, ...
|
|
- pattern-not-regex: params\.\w+(?<!permit)\(.*?\)
|
|
message: Found potentially unsafe handling of redirect behavior $X. Do not pass
|
|
`params` to `redirect_to` without the `:only_path => true` hash value.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_redirect.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Open Redirect
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to
|
|
shortlink: https://sg.run/eJNX
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20732
|
|
rv_id: 1263657
|
|
rule_id: kxUOJ6
|
|
version_id: GxTke14
|
|
url: https://semgrep.dev/playground/r/GxTke14/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to
|
|
origin: community
|
|
- id: ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- pattern: |
|
|
cookies[...]
|
|
- patterns:
|
|
- pattern: |
|
|
cookies. ... .$PROPERTY[...]
|
|
- metavariable-regex:
|
|
metavariable: $PROPERTY
|
|
regex: (?!signed|encrypted)
|
|
- pattern: |
|
|
params[...]
|
|
- pattern: |
|
|
request.env[...]
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $X
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$X.constantize
|
|
- pattern-inside: |
|
|
$X. ... .safe_constantize
|
|
- pattern-inside: |
|
|
const_get(...)
|
|
- pattern-inside: |
|
|
qualified_const_get(...)
|
|
message: Found user-controllable input to Ruby reflection functionality. This allows
|
|
a remote user to influence runtime behavior, up to and including arbitrary remote
|
|
code execution. Do not provide user-controllable input to reflection functionality.
|
|
Do not call symbol conversion on user-controllable input.
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails2/app/controllers/application_controller.rb
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection
|
|
shortlink: https://sg.run/vpEX
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20733
|
|
rv_id: 1263663
|
|
rule_id: wdUkYA
|
|
version_id: 0bTKzn8
|
|
url: https://semgrep.dev/playground/r/0bTKzn8/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection
|
|
origin: community
|
|
- id: ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- pattern: |
|
|
cookies[...]
|
|
- patterns:
|
|
- pattern: |
|
|
cookies. ... .$PROPERTY[...]
|
|
- metavariable-regex:
|
|
metavariable: $PROPERTY
|
|
regex: (?!signed|encrypted)
|
|
- pattern: |
|
|
params[...]
|
|
- pattern: |
|
|
request.env[...]
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $MODEL.find(...)
|
|
- pattern: $MODEL.find_by_id(...)
|
|
- pattern: $MODEL.find_by_id!(...)
|
|
- metavariable-regex:
|
|
metavariable: $MODEL
|
|
regex: '[A-Z]\S+'
|
|
message: Found an unscoped `find(...)` with user-controllable input. If the ActiveRecord
|
|
model being searched against is sensitive, this may lead to Insecure Direct Object
|
|
Reference (IDOR) behavior and allow users to read arbitrary records. Scope the
|
|
find to the current user, e.g. `current_user.accounts.find(params[:id])`.
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unscoped_find.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-639: Authorization Bypass Through User-Controlled Key'
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://brakemanscanner.org/docs/warning_types/unscoped_find/
|
|
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/controllers/users_controller.rb
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find
|
|
shortlink: https://sg.run/dPbP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20734
|
|
rv_id: 1263664
|
|
rule_id: x8Ud6d
|
|
version_id: K3TKkxZ
|
|
url: https://semgrep.dev/playground/r/K3TKkxZ/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find
|
|
origin: community
|
|
- id: ruby.rails.security.brakeman.check-validation-regex.check-validation-regex
|
|
mode: search
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
validates ..., :format => <... $V ...>,...
|
|
- pattern: |
|
|
validates_format_of ..., :with => <... $V ...>,...
|
|
- metavariable-regex:
|
|
metavariable: $V
|
|
regex: /(.{2}(?<!\\A)[^\/]+|[^\/]+(?<!\\[Zz]))\/
|
|
message: $V Found an incorrectly-bounded regex passed to `validates_format_of` or
|
|
`validate ... format => ...`. Ruby regex behavior is multiline by default and
|
|
lines should be terminated by `\A` for beginning of line and `\Z` for end of line,
|
|
respectively.
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
metadata:
|
|
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_validation_regex.rb
|
|
category: security
|
|
cwe:
|
|
- 'CWE-185: Incorrect Regular Expression'
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
technology:
|
|
- ruby
|
|
- rails
|
|
references:
|
|
- https://brakemanscanner.org/docs/warning_types/format_validation/
|
|
- https://github.com/presidentbeef/brakeman/blob/aef6253a8b7bcb97116f2af1ed2a561a6ae35bd5/test/apps/rails3/app/models/account.rb
|
|
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/account.rb
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-validation-regex.check-validation-regex
|
|
shortlink: https://sg.run/ZPo7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 20735
|
|
rv_id: 1263665
|
|
rule_id: OrUv1X
|
|
version_id: qkTR7DG
|
|
url: https://semgrep.dev/playground/r/qkTR7DG/ruby.rails.security.brakeman.check-validation-regex.check-validation-regex
|
|
origin: community
|
|
- id: go.lang.security.audit.net.fs-directory-listing.fs-directory-listing
|
|
message: 'Detected usage of ''http.FileServer'' as handler: this allows directory
|
|
listing and an attacker could navigate through directories looking for sensitive
|
|
files. Be sure to disable directory listing or restrict access to specific directories/files.'
|
|
severity: WARNING
|
|
languages:
|
|
- go
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$FS := http.FileServer(...)
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
http.ListenAndServe(..., $FS)
|
|
- pattern: |
|
|
http.ListenAndServeTLS(..., $FS)
|
|
- pattern: |
|
|
http.Handle(..., $FS)
|
|
- pattern: |
|
|
http.HandleFunc(..., $FS)
|
|
- patterns:
|
|
- pattern: |
|
|
http.$FN(..., http.FileServer(...))
|
|
- metavariable-regex:
|
|
metavariable: $FN
|
|
regex: (ListenAndServe|ListenAndServeTLS|Handle|HandleFunc)
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-548: Exposure of Information Through Directory Listing'
|
|
owasp:
|
|
- A06:2017 - Security Misconfiguration
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://github.com/OWASP/Go-SCP
|
|
- https://cwe.mitre.org/data/definitions/548.html
|
|
confidence: MEDIUM
|
|
technology:
|
|
- go
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing
|
|
shortlink: https://sg.run/4R8x
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21300
|
|
rv_id: 1262944
|
|
rule_id: 5rU9JO
|
|
version_id: QkTGqX0
|
|
url: https://semgrep.dev/playground/r/QkTGqX0/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing
|
|
origin: community
|
|
- id: javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object
|
|
message: Detected DynamoDB query params that are tainted by `$EVENT` object. This
|
|
could lead to NoSQL injection if the variable is user-controlled and not properly
|
|
sanitized. Explicitly assign query params instead of passing data from `$EVENT`
|
|
directly to DynamoDB client.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
category: security
|
|
technology:
|
|
- javascript
|
|
- aws-lambda
|
|
- dynamodb
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object
|
|
shortlink: https://sg.run/X1e4
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21320
|
|
rv_id: 945766
|
|
rule_id: 0oU1xk
|
|
version_id: GxTP7gN
|
|
url: https://semgrep.dev/playground/r/GxTP7gN/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: $EVENT
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
exports.handler = function ($EVENT, ...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function $FUNC ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
- pattern-inside: |
|
|
$FUNC = function ($EVENT, ...) {...}
|
|
...
|
|
exports.handler = $FUNC
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $SINK
|
|
- pattern: |
|
|
$DC.$METHOD($SINK, ...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (query|send|scan|delete|put|transactWrite|update|batchExecuteStatement|executeStatement|executeTransaction|transactWriteItems)
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$DC = new $AWS.DocumentClient(...);
|
|
...
|
|
- pattern-inside: |
|
|
$DC = new $AWS.DynamoDB(...);
|
|
...
|
|
- pattern-inside: |
|
|
$DC = new DynamoDBClient(...);
|
|
...
|
|
- pattern-inside: |
|
|
$DC = DynamoDBDocumentClient.from(...);
|
|
...
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: |
|
|
{...}
|
|
- id: python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection
|
|
mode: taint
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
category: security
|
|
technology:
|
|
- python
|
|
- boto3
|
|
- aws-lambda
|
|
- dynamodb
|
|
references:
|
|
- https://medium.com/appsecengineer/dynamodb-injection-1db99c2454ac
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection
|
|
shortlink: https://sg.run/jjrl
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21321
|
|
rv_id: 946088
|
|
rule_id: KxUJ2B
|
|
version_id: 9lTy1rQ
|
|
url: https://semgrep.dev/playground/r/9lTy1rQ/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection
|
|
origin: community
|
|
message: Detected DynamoDB query filter that is tainted by `$EVENT` object. This
|
|
could lead to NoSQL injection if the variable is user-controlled and not properly
|
|
sanitized. Explicitly assign query params instead of passing data from `$EVENT`
|
|
directly to DynamoDB client.
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: |
|
|
{...}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $SINK
|
|
- pattern-either:
|
|
- pattern: $TABLE.scan(..., ScanFilter = $SINK, ...)
|
|
- pattern: $TABLE.query(..., QueryFilter = $SINK, ...)
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$TABLE = $DB.Table(...)
|
|
...
|
|
- pattern-inside: |
|
|
$DB = boto3.resource('dynamodb', ...)
|
|
...
|
|
- pattern-inside: |
|
|
$TABLE = boto3.client('dynamodb', ...)
|
|
...
|
|
severity: ERROR
|
|
languages:
|
|
- python
|
|
- id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default
|
|
patterns:
|
|
- pattern: pyramid.authentication.$FUNC($...PARAMS)
|
|
- metavariable-pattern:
|
|
metavariable: $FUNC
|
|
pattern-either:
|
|
- pattern: AuthTktCookieHelper
|
|
- pattern: AuthTktAuthenticationPolicy
|
|
- pattern-not: pyramid.authentication.$FUNC(..., httponly=$HTTPONLY, ...)
|
|
- pattern-not: pyramid.authentication.$FUNC(..., **$PARAMS, ...)
|
|
- focus-metavariable: $...PARAMS
|
|
fix: |
|
|
$...PARAMS, httponly=True
|
|
message: Found a Pyramid Authentication Ticket cookie without the httponly option
|
|
correctly set. Pyramid cookies should be handled securely by setting httponly=True.
|
|
If this parameter is not properly set, your cookies are not properly protected
|
|
and are at risk of being stolen by an attacker.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default
|
|
shortlink: https://sg.run/EprB
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21437
|
|
rv_id: 1263557
|
|
rule_id: bwUXKB
|
|
version_id: RGT0L7K
|
|
url: https://semgrep.dev/playground/r/RGT0L7K/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS)
|
|
- pattern: pyramid.authentication.AuthTktCookieHelper(..., httponly=$HTTPONLY,
|
|
...)
|
|
- patterns:
|
|
- pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS)
|
|
- pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., httponly=$HTTPONLY,
|
|
...)
|
|
- pattern: $HTTPONLY
|
|
- metavariable-pattern:
|
|
metavariable: $HTTPONLY
|
|
pattern: |
|
|
False
|
|
fix: |
|
|
True
|
|
message: Found a Pyramid Authentication Ticket cookie without the httponly option
|
|
correctly set. Pyramid cookies should be handled securely by setting httponly=True.
|
|
If this parameter is not properly set, your cookies are not properly protected
|
|
and are at risk of being stolen by an attacker.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value
|
|
shortlink: https://sg.run/7DgQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21438
|
|
rv_id: 1263558
|
|
rule_id: NbUq9e
|
|
version_id: A8Tgd8N
|
|
url: https://semgrep.dev/playground/r/A8Tgd8N/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: pyramid.authentication.AuthTktCookieHelper(..., samesite=$SAMESITE,
|
|
...)
|
|
- pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., samesite=$SAMESITE,
|
|
...)
|
|
- pattern: $SAMESITE
|
|
- metavariable-regex:
|
|
metavariable: $SAMESITE
|
|
regex: (?!'Lax')
|
|
fix: |
|
|
'Lax'
|
|
message: Found a Pyramid Authentication Ticket without the samesite option correctly
|
|
set. Pyramid cookies should be handled securely by setting samesite='Lax'. If
|
|
this parameter is not properly set, your cookies are not properly protected and
|
|
are at risk of being stolen by an attacker.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite
|
|
shortlink: https://sg.run/LYrY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21439
|
|
rv_id: 1263559
|
|
rule_id: kxUYjY
|
|
version_id: BjTkZ51
|
|
url: https://semgrep.dev/playground/r/BjTkZ51/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-not: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE,
|
|
...)
|
|
- pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS)
|
|
- pattern: pyramid.authentication.AuthTktCookieHelper(...)
|
|
- patterns:
|
|
- pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE,
|
|
...)
|
|
- pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS)
|
|
- pattern: pyramid.authentication.AuthTktAuthenticationPolicy(...)
|
|
fix-regex:
|
|
regex: (.*)\)
|
|
replacement: \1, secure=True)
|
|
message: Found a Pyramid Authentication Ticket cookie using an unsafe default for
|
|
the secure option. Pyramid cookies should be handled securely by setting secure=True.
|
|
If this parameter is not properly set, your cookies are not properly protected
|
|
and are at risk of being stolen by an attacker.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default
|
|
shortlink: https://sg.run/8WxQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21440
|
|
rv_id: 1263560
|
|
rule_id: wdUKzn
|
|
version_id: DkTRbJn
|
|
url: https://semgrep.dev/playground/r/DkTRbJn/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS)
|
|
- pattern: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE, ...)
|
|
- patterns:
|
|
- pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS)
|
|
- pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE,
|
|
...)
|
|
- pattern: $SECURE
|
|
- metavariable-pattern:
|
|
metavariable: $SECURE
|
|
pattern: |
|
|
False
|
|
fix: |
|
|
True
|
|
message: Found a Pyramid Authentication Ticket cookie without the secure option
|
|
correctly set. Pyramid cookies should be handled securely by setting secure=True.
|
|
If this parameter is not properly set, your cookies are not properly protected
|
|
and are at risk of being stolen by an attacker.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value
|
|
shortlink: https://sg.run/gjp5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21441
|
|
rv_id: 1263561
|
|
rule_id: x8UqAp
|
|
version_id: WrTqK93
|
|
url: https://semgrep.dev/playground/r/WrTqK93/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally
|
|
patterns:
|
|
- pattern-inside: |
|
|
$CONFIG.set_default_csrf_options(..., check_origin=$CHECK_ORIGIN, ...)
|
|
- pattern: $CHECK_ORIGIN
|
|
- metavariable-comparison:
|
|
metavariable: $CHECK_ORIGIN
|
|
comparison: $CHECK_ORIGIN == False
|
|
message: Automatic check of the referrer for cross-site request forgery tokens has
|
|
been explicitly disabled globally, which might leave views unprotected when an
|
|
unsafe CSRF storage policy is used. Use 'pyramid.config.Configurator.set_default_csrf_options(check_origin=True)'
|
|
to turn the automatic check for all unsafe methods (per RFC2616).
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
fix: |
|
|
True
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-352: Cross-Site Request Forgery (CSRF)'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site Request Forgery (CSRF)
|
|
source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally
|
|
shortlink: https://sg.run/3GeW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21443
|
|
rv_id: 1263563
|
|
rule_id: eqU9Le
|
|
version_id: K3TKkeo
|
|
url: https://semgrep.dev/playground/r/K3TKkeo/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally
|
|
origin: community
|
|
- id: python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled
|
|
message: Origin check for the CSRF token is disabled for this view. This might represent
|
|
a security risk if the CSRF storage policy is not known to be secure.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-352: Cross-Site Request Forgery (CSRF)'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
asvs:
|
|
section: V4 Access Control
|
|
control_id: 4.2.2 CSRF
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V4-Access-Control.md#v42-operation-level-access-control
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site Request Forgery (CSRF)
|
|
source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled
|
|
shortlink: https://sg.run/4RB9
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21444
|
|
rv_id: 1263564
|
|
rule_id: v8UGpL
|
|
version_id: qkTR7Gv
|
|
url: https://semgrep.dev/playground/r/qkTR7Gv/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
patterns:
|
|
- pattern-inside: |
|
|
from pyramid.view import view_config
|
|
...
|
|
@view_config(..., check_origin=$CHECK_ORIGIN, ...)
|
|
def $VIEW(...):
|
|
...
|
|
- pattern: $CHECK_ORIGIN
|
|
- metavariable-comparison:
|
|
metavariable: $CHECK_ORIGIN
|
|
comparison: $CHECK_ORIGIN == False
|
|
fix: |
|
|
True
|
|
- id: python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config(...)
|
|
def $VIEW($REQUEST):
|
|
...
|
|
$RESPONSE = $REQUEST.response
|
|
...
|
|
- pattern-inside: |
|
|
def $VIEW(...):
|
|
...
|
|
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
|
|
...
|
|
- pattern-not: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...)
|
|
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
|
|
- pattern: $RESPONSE.set_cookie(...)
|
|
fix-regex:
|
|
regex: (.*)\)
|
|
replacement: \1, httponly=True)
|
|
message: Found a Pyramid cookie using an unsafe default for the httponly option.
|
|
Pyramid cookies should be handled securely by setting httponly=True in response.set_cookie(...).
|
|
If this parameter is not properly set, your cookies are not properly protected
|
|
and are at risk of being stolen by an attacker.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default
|
|
shortlink: https://sg.run/P19v
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21445
|
|
rv_id: 1263565
|
|
rule_id: d8UPQ7
|
|
version_id: l4TJRbo
|
|
url: https://semgrep.dev/playground/r/l4TJRbo/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config(...)
|
|
def $VIEW($REQUEST):
|
|
...
|
|
$RESPONSE = $REQUEST.response
|
|
...
|
|
- pattern-inside: |
|
|
def $VIEW(...):
|
|
...
|
|
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
|
|
...
|
|
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
|
|
- pattern: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...)
|
|
- pattern: $HTTPONLY
|
|
- metavariable-pattern:
|
|
metavariable: $HTTPONLY
|
|
pattern: |
|
|
False
|
|
fix: |
|
|
True
|
|
message: Found a Pyramid cookie without the httponly option correctly set. Pyramid
|
|
cookies should be handled securely by setting httponly=True in response.set_cookie(...).
|
|
If this parameter is not properly set, your cookies are not properly protected
|
|
and are at risk of being stolen by an attacker.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://owasp.org/www-community/controls/SecureCookieAttribute
|
|
- https://owasp.org/www-community/HttpOnly
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html#httponly-attribute
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value
|
|
shortlink: https://sg.run/JbqP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21446
|
|
rv_id: 1263566
|
|
rule_id: ZqU37W
|
|
version_id: YDTZe54
|
|
url: https://semgrep.dev/playground/r/YDTZe54/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config(...)
|
|
def $VIEW($REQUEST):
|
|
...
|
|
$RESPONSE = $REQUEST.response
|
|
...
|
|
- pattern-inside: |
|
|
def $VIEW(...):
|
|
...
|
|
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
|
|
...
|
|
- pattern-not: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...)
|
|
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
|
|
- pattern: $RESPONSE.set_cookie(...)
|
|
fix-regex:
|
|
regex: (.*)\)
|
|
replacement: \1, samesite='Lax')
|
|
message: Found a Pyramid cookie using an unsafe value for the samesite option. Pyramid
|
|
cookies should be handled securely by setting samesite='Lax' in response.set_cookie(...).
|
|
If this parameter is not properly set, your cookies are not properly protected
|
|
and are at risk of being stolen by an attacker.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default
|
|
shortlink: https://sg.run/5AWj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21447
|
|
rv_id: 1263567
|
|
rule_id: nJUp80
|
|
version_id: 6xT293z
|
|
url: https://semgrep.dev/playground/r/6xT293z/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config(...)
|
|
def $VIEW($REQUEST):
|
|
...
|
|
$RESPONSE = $REQUEST.response
|
|
...
|
|
- pattern-inside: |
|
|
def $VIEW(...):
|
|
...
|
|
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
|
|
...
|
|
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
|
|
- pattern: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...)
|
|
- pattern: $SAMESITE
|
|
- metavariable-regex:
|
|
metavariable: $SAMESITE
|
|
regex: (?!'Lax')
|
|
fix: |
|
|
'Lax'
|
|
message: Found a Pyramid cookie without the samesite option correctly set. Pyramid
|
|
cookies should be handled securely by setting samesite='Lax' in response.set_cookie(...).
|
|
If this parameter is not properly set, your cookies are not properly protected
|
|
and are at risk of being stolen by an attacker.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value
|
|
shortlink: https://sg.run/GXR6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21448
|
|
rv_id: 1263568
|
|
rule_id: EwUgpY
|
|
version_id: o5TbDv5
|
|
url: https://semgrep.dev/playground/r/o5TbDv5/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config(...)
|
|
def $VIEW($REQUEST):
|
|
...
|
|
$RESPONSE = $REQUEST.response
|
|
...
|
|
- pattern-inside: |
|
|
def $VIEW(...):
|
|
...
|
|
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
|
|
...
|
|
- pattern-not: $RESPONSE.set_cookie(..., secure=$SECURE, ...)
|
|
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
|
|
- pattern: $RESPONSE.set_cookie(...)
|
|
fix-regex:
|
|
regex: (.*)\)
|
|
replacement: \1, secure=True)
|
|
message: Found a Pyramid cookie using an unsafe default for the secure option. Pyramid
|
|
cookies should be handled securely by setting secure=True in response.set_cookie(...).
|
|
If this parameter is not properly set, your cookies are not properly protected
|
|
and are at risk of being stolen by an attacker.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default
|
|
shortlink: https://sg.run/RbrN
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21449
|
|
rv_id: 1263569
|
|
rule_id: 7KUr15
|
|
version_id: zyTb2dX
|
|
url: https://semgrep.dev/playground/r/zyTb2dX/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config(...)
|
|
def $VIEW($REQUEST):
|
|
...
|
|
$RESPONSE = $REQUEST.response
|
|
...
|
|
- pattern-inside: |
|
|
def $VIEW(...):
|
|
...
|
|
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
|
|
...
|
|
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
|
|
- pattern: $RESPONSE.set_cookie(..., secure=$SECURE, ...)
|
|
- pattern: $SECURE
|
|
- metavariable-pattern:
|
|
metavariable: $SECURE
|
|
pattern: |
|
|
False
|
|
fix: |
|
|
True
|
|
message: Found a Pyramid cookie without the secure option correctly set. Pyramid
|
|
cookies should be handled securely by setting secure=True in response.set_cookie(...).
|
|
If this parameter is not properly set, your cookies are not properly protected
|
|
and are at risk of being stolen by an attacker.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value
|
|
shortlink: https://sg.run/AzjB
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21450
|
|
rv_id: 1263570
|
|
rule_id: L1UX2J
|
|
version_id: pZT03oJ
|
|
url: https://semgrep.dev/playground/r/pZT03oJ/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally
|
|
patterns:
|
|
- pattern-inside: |
|
|
$CONFIG.set_default_csrf_options(..., require_csrf=$REQUIRE_CSRF, ...)
|
|
- pattern: $REQUIRE_CSRF
|
|
- metavariable-comparison:
|
|
metavariable: $REQUIRE_CSRF
|
|
comparison: $REQUIRE_CSRF == False
|
|
message: Automatic check of cross-site request forgery tokens has been explicitly
|
|
disabled globally, which might leave views unprotected. Use 'pyramid.config.Configurator.set_default_csrf_options(require_csrf=True)'
|
|
to turn the automatic check for all unsafe methods (per RFC2616).
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
fix: |
|
|
True
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-352: Cross-Site Request Forgery (CSRF)'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site Request Forgery (CSRF)
|
|
source: https://semgrep.dev/r/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally
|
|
shortlink: https://sg.run/Bx2R
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21451
|
|
rv_id: 1263571
|
|
rule_id: 8GUKqP
|
|
version_id: 2KTv2en
|
|
url: https://semgrep.dev/playground/r/2KTv2en/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally
|
|
origin: community
|
|
- id: python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response
|
|
message: Detected data rendered directly to the end user via 'Response'. This bypasses
|
|
Pyramid's built-in cross-site scripting (XSS) defenses and could result in an
|
|
XSS vulnerability. Use Pyramid's template engines to safely render HTML.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- pyramid
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response
|
|
shortlink: https://sg.run/DX8G
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21452
|
|
rv_id: 1263572
|
|
rule_id: gxUeA8
|
|
version_id: X0TzyEe
|
|
url: https://semgrep.dev/playground/r/X0TzyEe/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config( ... )
|
|
def $VIEW($REQ):
|
|
...
|
|
- pattern: $REQ.$ANYTHING
|
|
- pattern-not: $REQ.dbsession
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
pyramid.request.Response.text($SINK)
|
|
- pattern: |
|
|
pyramid.request.Response($SINK)
|
|
- pattern: |
|
|
$REQ.response.body = $SINK
|
|
- pattern: |
|
|
$REQ.response.text = $SINK
|
|
- pattern: |
|
|
$REQ.response.ubody = $SINK
|
|
- pattern: |
|
|
$REQ.response.unicode_body = $SINK
|
|
- pattern: $SINK
|
|
- id: python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection
|
|
message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause
|
|
sql injections if the developer inputs raw SQL into the before-mentioned clauses.
|
|
This pattern captures relevant cases in which the developer inputs raw SQL into
|
|
the distinct, having, group_by, order_by or filter clauses and injects user-input
|
|
into the raw SQL with any function besides "bindparams". Use bindParams to securely
|
|
bind user-input to SQL statements.
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.sqlalchemy.org/en/14/tutorial/data_select.html#tutorial-selecting-data
|
|
technology:
|
|
- pyramid
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection
|
|
shortlink: https://sg.run/W7eE
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21453
|
|
rv_id: 1263573
|
|
rule_id: QrUZ7l
|
|
version_id: jQTn5WA
|
|
url: https://semgrep.dev/playground/r/jQTn5WA/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
from pyramid.view import view_config
|
|
...
|
|
@view_config( ... )
|
|
def $VIEW($REQ):
|
|
...
|
|
- pattern: $REQ.$ANYTHING
|
|
- pattern-not: $REQ.dbsession
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$QUERY = $REQ.dbsession.query(...)
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
$QUERY.$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...))
|
|
- pattern: |
|
|
$QUERY.join(...).$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...))
|
|
- pattern: $SINK
|
|
- metavariable-regex:
|
|
metavariable: $SQLFUNC
|
|
regex: (group_by|order_by|distinct|having|filter)
|
|
- metavariable-regex:
|
|
metavariable: $FORMATFUNC
|
|
regex: (?!bindparams)
|
|
fix-regex:
|
|
regex: format
|
|
replacement: bindparams
|
|
- id: javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint
|
|
message: Use of angular.element can lead to XSS if user-input is treated as part
|
|
of the HTML element within `$SINK`. It is recommended to contextually output encode
|
|
user-input, before inserting into `$SINK`. If the HTML needs to be preserved it
|
|
is recommended to sanitize the input using $sce.getTrustedHTML or $sanitize.
|
|
metadata:
|
|
confidence: MEDIUM
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
references:
|
|
- https://docs.angularjs.org/api/ng/function/angular.element
|
|
- https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf
|
|
category: security
|
|
technology:
|
|
- angularjs
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint
|
|
shortlink: https://sg.run/5AQ0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21503
|
|
rv_id: 1263091
|
|
rule_id: GdUP71
|
|
version_id: 44TEj8L
|
|
url: https://semgrep.dev/playground/r/44TEj8L/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: window.location.search
|
|
- pattern: window.document.location.search
|
|
- pattern: document.location.search
|
|
- pattern: location.search
|
|
- pattern: $location.search(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $DECODE(<... location.hash ...>)
|
|
- pattern: $DECODE(<... window.location.hash ...>)
|
|
- pattern: $DECODE(<... document.location.hash ...>)
|
|
- pattern: $DECODE(<... location.href ...>)
|
|
- pattern: $DECODE(<... window.location.href ...>)
|
|
- pattern: $DECODE(<... document.location.href ...>)
|
|
- pattern: $DECODE(<... document.URL ...>)
|
|
- pattern: $DECODE(<... window.document.URL ...>)
|
|
- pattern: $DECODE(<... document.location.href ...>)
|
|
- pattern: $DECODE(<... document.location.href ...>)
|
|
- pattern: $DECODE(<... $location.absUrl() ...>)
|
|
- pattern: $DECODE(<... $location.url() ...>)
|
|
- pattern: $DECODE(<... $location.hash() ...>)
|
|
- metavariable-regex:
|
|
metavariable: $DECODE
|
|
regex: ^(unescape|decodeURI|decodeURIComponent)$
|
|
- patterns:
|
|
- pattern-inside: $http.$METHOD(...).$CONTINUE(function $FUNC($RES) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|delete|head|jsonp|post|put|patch)
|
|
- pattern: $RES.data
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
angular.element(...). ... .$SINK($QUERY)
|
|
- pattern-inside: |
|
|
$ANGULAR = angular.element(...)
|
|
...
|
|
$ANGULAR. ... .$SINK($QUERY)
|
|
- metavariable-regex:
|
|
metavariable: $SINK
|
|
regex: ^(after|append|html|prepend|replaceWith|wrap)$
|
|
- focus-metavariable: $QUERY
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $sce.getTrustedHtml(...)
|
|
- pattern: $sanitize(...)
|
|
- pattern: DOMPurify.sanitize(...)
|
|
- id: python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context):
|
|
...
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $SINK
|
|
- pattern-either:
|
|
- pattern: pickle.load($SINK,...)
|
|
- pattern: pickle.loads($SINK,...)
|
|
- pattern: _pickle.load($SINK,...)
|
|
- pattern: _pickle.loads($SINK,...)
|
|
- pattern: cPickle.load($SINK,...)
|
|
- pattern: cPickle.loads($SINK,...)
|
|
- pattern: dill.load($SINK,...)
|
|
- pattern: dill.loads($SINK,...)
|
|
- pattern: shelve.open($SINK,...)
|
|
message: Avoid using `pickle`, which is known to lead to code execution vulnerabilities.
|
|
When unpickling, the serialized data could be manipulated to run arbitrary code.
|
|
Instead, consider serializing the relevant data as JSON or a similar text-based
|
|
serialization format.
|
|
metadata:
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
references:
|
|
- https://docs.python.org/3/library/pickle.html
|
|
- https://davidhamann.de/2020/04/05/exploiting-python-pickle/
|
|
category: security
|
|
technology:
|
|
- python
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization
|
|
shortlink: https://sg.run/JbjW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21602
|
|
rv_id: 1263345
|
|
rule_id: JDUDQg
|
|
version_id: LjTkgd9
|
|
url: https://semgrep.dev/playground/r/LjTkgd9/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
- id: php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- focus-metavariable: $ARG
|
|
- pattern-inside: |
|
|
Route::$METHOD($ROUTE_NAME, function(...,$ARG,...){...})
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: |
|
|
DB::raw("...",[...])
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
DB::raw(...)
|
|
message: HTTP method [$METHOD] to Laravel route $ROUTE_NAME is vulnerable to SQL
|
|
injection via string concatenation or unsafe interpolation.
|
|
languages:
|
|
- php
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Laravel_Cheat_Sheet.md
|
|
technology:
|
|
- php
|
|
- laravel
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection
|
|
shortlink: https://sg.run/x94g
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21674
|
|
rv_id: 1263305
|
|
rule_id: zdUln0
|
|
version_id: qkTR7A9
|
|
url: https://semgrep.dev/playground/r/qkTR7A9/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection
|
|
origin: community
|
|
- id: php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: |
|
|
public function $F(...,Request $R,...){...}
|
|
- focus-metavariable: $R
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$this->$PROPERTY
|
|
- pattern: |
|
|
$this->$PROPERTY->$GET
|
|
- metavariable-pattern:
|
|
metavariable: $PROPERTY
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: query
|
|
- pattern: request
|
|
- pattern: headers
|
|
- pattern: cookies
|
|
- pattern: cookie
|
|
- pattern: files
|
|
- pattern: file
|
|
- pattern: allFiles
|
|
- pattern: input
|
|
- pattern: all
|
|
- pattern: post
|
|
- pattern: json
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $CL extends Illuminate\Http\Request {...}
|
|
- pattern-inside: |
|
|
class $CL extends Illuminate\Foundation\Http\FormRequest {...}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
Illuminate\Validation\Rule::unique(...)->ignore(...,$IGNORE,...)
|
|
- focus-metavariable: $IGNORE
|
|
message: Found a request argument passed to an `ignore()` definition in a Rule constraint.
|
|
This can lead to SQL injection.
|
|
languages:
|
|
- php
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
technology:
|
|
- php
|
|
- laravel
|
|
references:
|
|
- https://laravel.com/docs/9.x/validation#rule-unique
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator
|
|
shortlink: https://sg.run/vkeb
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 21677
|
|
rv_id: 1263314
|
|
rule_id: X5ULgE
|
|
version_id: DkTRbBl
|
|
url: https://semgrep.dev/playground/r/DkTRbBl/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator
|
|
origin: community
|
|
- id: java.spring.security.injection.tainted-file-path.tainted-file-path
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
message: Detected user input controlling a file path. An attacker could control
|
|
the location of this file, to include going backwards in the directory with '../'.
|
|
To address this, ensure that user-controlled variables in file paths are sanitized.
|
|
You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...)
|
|
to only retrieve the file name from the path.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-23: Relative Path Traversal'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://owasp.org/www-community/attacks/Path_Traversal
|
|
category: security
|
|
technology:
|
|
- java
|
|
- spring
|
|
subcategory:
|
|
- vuln
|
|
impact: HIGH
|
|
likelihood: MEDIUM
|
|
confidence: HIGH
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/java.spring.security.injection.tainted-file-path.tainted-file-path
|
|
shortlink: https://sg.run/x9o0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22074
|
|
rv_id: 1263084
|
|
rule_id: lBUxok
|
|
version_id: ExTEx6Y
|
|
url: https://semgrep.dev/playground/r/ExTEx6Y/java.spring.security.injection.tainted-file-path.tainted-file-path
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $TYPE
|
|
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
|
|
- metavariable-regex:
|
|
metavariable: $REQ
|
|
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute)
|
|
- focus-metavariable: $SOURCE
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: new File(...)
|
|
- pattern: new java.io.File(...)
|
|
- pattern: new FileReader(...)
|
|
- pattern: new java.io.FileReader(...)
|
|
- pattern: new FileInputStream(...)
|
|
- pattern: new java.io.FileInputStream(...)
|
|
- pattern: (Paths $PATHS).get(...)
|
|
- patterns:
|
|
- pattern: |
|
|
$CLASS.$FUNC(...)
|
|
- metavariable-regex:
|
|
metavariable: $FUNC
|
|
regex: ^(getResourceAsStream|getResource)$
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: new ClassPathResource($FILE, ...)
|
|
- pattern: ResourceUtils.getFile($FILE, ...)
|
|
- pattern: new FileOutputStream($FILE, ...)
|
|
- pattern: new java.io.FileOutputStream($FILE, ...)
|
|
- pattern: new StreamSource($FILE, ...)
|
|
- pattern: new javax.xml.transform.StreamSource($FILE, ...)
|
|
- pattern: FileUtils.openOutputStream($FILE, ...)
|
|
- focus-metavariable: $FILE
|
|
pattern-sanitizers:
|
|
- pattern: org.apache.commons.io.FilenameUtils.getName(...)
|
|
- id: java.spring.security.injection.tainted-html-string.tainted-html-string
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
message: Detected user input flowing into a manually constructed HTML string. You
|
|
may be accidentally bypassing secure methods of rendering HTML by manually constructing
|
|
HTML and this could create a cross-site scripting vulnerability, which could let
|
|
attackers steal sensitive user data. To be sure this is safe, check that the HTML
|
|
is rendered safely. You can use the OWASP ESAPI encoder if you must render user
|
|
data.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
- spring
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/java.spring.security.injection.tainted-html-string.tainted-html-string
|
|
shortlink: https://sg.run/ObdR
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22075
|
|
rv_id: 1409395
|
|
rule_id: YGUvkL
|
|
version_id: 3ZT2598
|
|
url: https://semgrep.dev/playground/r/3ZT2598/java.spring.security.injection.tainted-html-string.tainted-html-string
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- label: INPUT
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $TYPE
|
|
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
|
|
- metavariable-regex:
|
|
metavariable: $REQ
|
|
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute)
|
|
- focus-metavariable: $SOURCE
|
|
- label: CONCAT
|
|
by-side-effect: true
|
|
requires: INPUT
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$HTMLSTR" + ...
|
|
- pattern: |
|
|
"$HTMLSTR".concat(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
StringBuilder $SB = new StringBuilder("$HTMLSTR");
|
|
...
|
|
- pattern: $SB.append(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VAR = "$HTMLSTR";
|
|
...
|
|
- pattern: $VAR += ...
|
|
- pattern: String.format("$HTMLSTR", ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
String $VAR = "$HTMLSTR";
|
|
...
|
|
- pattern: String.format($VAR, ...)
|
|
- metavariable-regex:
|
|
metavariable: $HTMLSTR
|
|
regex: ^<\w+
|
|
pattern-propagators:
|
|
- pattern: (StringBuilder $SB).append($...TAINTED)
|
|
from: $...TAINTED
|
|
to: $SB
|
|
- pattern: $VAR += $...TAINTED
|
|
from: $...TAINTED
|
|
to: $VAR
|
|
pattern-sinks:
|
|
- requires: CONCAT
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: new ResponseEntity<>($PAYLOAD, ...)
|
|
- pattern: new ResponseEntity<$ERROR>($PAYLOAD, ...)
|
|
- pattern: ResponseEntity. ... .body($PAYLOAD)
|
|
- patterns:
|
|
- pattern: |
|
|
ResponseEntity.$RESPFUNC($PAYLOAD). ...
|
|
- metavariable-regex:
|
|
metavariable: $RESPFUNC
|
|
regex: ^(ok|of)$
|
|
- focus-metavariable: $PAYLOAD
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: Encode.forHtml(...)
|
|
- pattern: (PolicyFactory $POLICY).sanitize(...)
|
|
- pattern: (AntiSamy $AS).scan(...)
|
|
- pattern: JSoup.clean(...)
|
|
- id: java.spring.security.injection.tainted-system-command.tainted-system-command
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-propagators:
|
|
- pattern: (StringBuilder $STRB).append($INPUT)
|
|
from: $INPUT
|
|
to: $STRB
|
|
label: CONCAT
|
|
requires: INPUT
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $TYPE
|
|
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
|
|
- metavariable-regex:
|
|
metavariable: $REQ
|
|
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute)
|
|
- focus-metavariable: $SOURCE
|
|
label: INPUT
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $X + $SOURCE
|
|
- pattern: $SOURCE + $Y
|
|
- pattern: String.format("...", ..., $SOURCE, ...)
|
|
- pattern: String.join("...", ..., $SOURCE, ...)
|
|
- pattern: (String $STR).concat($SOURCE)
|
|
- pattern: $SOURCE.concat(...)
|
|
- pattern: $X += $SOURCE
|
|
- pattern: $SOURCE += $X
|
|
label: CONCAT
|
|
requires: INPUT
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(Process $P) = new Process(...);
|
|
- pattern: |
|
|
(ProcessBuilder $PB).command(...);
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(Runtime $R).$EXEC(...);
|
|
- pattern: |
|
|
Runtime.getRuntime(...).$EXEC(...);
|
|
- metavariable-regex:
|
|
metavariable: $EXEC
|
|
regex: (exec|loadLibrary|load)
|
|
- patterns:
|
|
- pattern: |
|
|
(ProcessBuilder $PB).command(...).$ADD(...);
|
|
- metavariable-regex:
|
|
metavariable: $ADD
|
|
regex: (add|addAll)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$BUILDER = new ProcessBuilder(...);
|
|
...
|
|
- pattern: $BUILDER.start(...)
|
|
- pattern: |
|
|
new ProcessBuilder(...). ... .start(...);
|
|
requires: CONCAT
|
|
message: 'Detected user input entering a method which executes a system command.
|
|
This could result in a command injection vulnerability, which allows an attacker
|
|
to inject an arbitrary system command onto the server. The attacker could download
|
|
malware onto or steal data from the server. Instead, use ProcessBuilder, separating
|
|
the command into individual arguments, like this: `new ProcessBuilder("ls", "-al",
|
|
targetDirectory)`. Further, make sure you hardcode or allowlist the actual command
|
|
so that attackers can''t run arbitrary commands.'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- java
|
|
- spring
|
|
confidence: HIGH
|
|
references:
|
|
- https://www.stackhawk.com/blog/command-injection-java/
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html
|
|
- https://github.com/github/codeql/blob/main/java/ql/src/Security/CWE/CWE-078/ExecUnescaped.java
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/java.spring.security.injection.tainted-system-command.tainted-system-command
|
|
shortlink: https://sg.run/epY0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22076
|
|
rv_id: 1263087
|
|
rule_id: 6JUxGN
|
|
version_id: 8KT5rnP
|
|
url: https://semgrep.dev/playground/r/8KT5rnP/java.spring.security.injection.tainted-system-command.tainted-system-command
|
|
origin: community
|
|
- id: java.spring.security.injection.tainted-url-host.tainted-url-host
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
message: User data flows into the host portion of this manually-constructed URL.
|
|
This could allow an attacker to send data to their own server, potentially exposing
|
|
sensitive data such as cookies or authorization information sent with this request.
|
|
They could also probe internal servers or other resources that the server running
|
|
this code can access. (This is called server-side request forgery, or SSRF.) Do
|
|
not allow arbitrary hosts. Instead, create an allowlist for approved hosts, hardcode
|
|
the correct host, or ensure that the user data can only affect the path or parameters.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
- spring
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/java.spring.security.injection.tainted-url-host.tainted-url-host
|
|
shortlink: https://sg.run/vkYn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22077
|
|
rv_id: 1263088
|
|
rule_id: oqUZo8
|
|
version_id: gETB708
|
|
url: https://semgrep.dev/playground/r/gETB708/java.spring.security.injection.tainted-url-host.tainted-url-host
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $TYPE
|
|
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
|
|
- metavariable-regex:
|
|
metavariable: $REQ
|
|
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute)
|
|
- focus-metavariable: $SOURCE
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- pattern: new URL($ONEARG)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$URLSTR" + ...
|
|
- pattern: |
|
|
"$URLSTR".concat(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
StringBuilder $SB = new StringBuilder("$URLSTR");
|
|
...
|
|
- pattern: $SB.append(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VAR = "$URLSTR";
|
|
...
|
|
- pattern: $VAR += ...
|
|
- patterns:
|
|
- pattern: String.format("$URLSTR", ...)
|
|
- pattern-not: String.format("$URLSTR", "...", ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
String $VAR = "$URLSTR";
|
|
...
|
|
- pattern: String.format($VAR, ...)
|
|
- metavariable-regex:
|
|
metavariable: $URLSTR
|
|
regex: http(s?)://%(v|s|q).*
|
|
- id: ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization
|
|
mode: taint
|
|
languages:
|
|
- ruby
|
|
message: Deserialization of a string tainted by `event` object found. Objects in
|
|
Ruby can be serialized into strings, then later loaded from strings. However,
|
|
uses of `load` can cause remote code execution. Loading user input with MARSHAL,
|
|
YAML or CSV can potentially be dangerous. If you need to deserialize untrusted
|
|
data, you should use JSON as it is only capable of returning 'primitive' types
|
|
such as strings, arrays, hashes, numbers and nil.
|
|
metadata:
|
|
references:
|
|
- https://ruby-doc.org/core-3.1.2/doc/security_rdoc.html
|
|
- https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ
|
|
- https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb
|
|
category: security
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
technology:
|
|
- ruby
|
|
- aws-lambda
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization
|
|
shortlink: https://sg.run/dplX
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22078
|
|
rv_id: 1263585
|
|
rule_id: zdUlNJ
|
|
version_id: vdT06gR
|
|
url: https://semgrep.dev/playground/r/vdT06gR/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization
|
|
origin: community
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $SINK
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
YAML.load($SINK,...)
|
|
- pattern-inside: |
|
|
CSV.load($SINK,...)
|
|
- pattern-inside: |
|
|
Marshal.load($SINK,...)
|
|
- pattern-inside: |
|
|
Marshal.restore($SINK,...)
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: event
|
|
- pattern-inside: |
|
|
def $HANDLER(event, context)
|
|
...
|
|
end
|
|
severity: WARNING
|
|
- id: javascript.express.security.audit.express-libxml-noent.express-libxml-noent
|
|
message: The libxml library processes user-input with the `noent` attribute is set
|
|
to `true` which can lead to being vulnerable to XML External Entities (XXE) type
|
|
attacks. It is recommended to set `noent` to `false` when using this feature to
|
|
ensure you are protected.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
|
|
technology:
|
|
- express
|
|
category: security
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-noent.express-libxml-noent
|
|
shortlink: https://sg.run/Z75x
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22079
|
|
rv_id: 1263138
|
|
rule_id: pKUNeD
|
|
version_id: d6TyxpX
|
|
url: https://semgrep.dev/playground/r/d6TyxpX/javascript.express.security.audit.express-libxml-noent.express-libxml-noent
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
|
|
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
- pattern: files.$ANYTHING.data.toString('utf8')
|
|
- pattern: files.$ANYTHING['data'].toString('utf8')
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$XML = require('$IMPORT')
|
|
...
|
|
- pattern-inside: |
|
|
import $XML from '$IMPORT'
|
|
...
|
|
- pattern-inside: |
|
|
import * as $XML from '$IMPORT'
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $IMPORT
|
|
regex: ^(libxmljs|libxmljs2)$
|
|
- pattern-inside: $XML.$FUNC($QUERY, {...,noent:true,...})
|
|
- metavariable-regex:
|
|
metavariable: $FUNC
|
|
regex: ^(parseXmlString|parseXml)$
|
|
- focus-metavariable: $QUERY
|
|
- id: javascript.express.security.audit.express-open-redirect.express-open-redirect
|
|
message: The application redirects to a URL specified by user-supplied input `$REQ`
|
|
that is not validated. This could redirect users to malicious locations. Consider
|
|
using an allow-list approach to validate URLs, or warn users they are being redirected
|
|
to a third-party website.
|
|
metadata:
|
|
technology:
|
|
- express
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html
|
|
cwe:
|
|
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
|
|
category: security
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Open Redirect
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-open-redirect.express-open-redirect
|
|
shortlink: https://sg.run/EpoP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22081
|
|
rv_id: 1263140
|
|
rule_id: X5ULkq
|
|
version_id: nWT2L0v
|
|
url: https://semgrep.dev/playground/r/nWT2L0v/javascript.express.security.audit.express-open-redirect.express-open-redirect
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
options:
|
|
taint_unify_mvars: true
|
|
symbolic_propagation: true
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE)
|
|
- pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE + $...A)
|
|
- pattern: $RES.redirect(`$HTTP${$REQ. ... .$VALUE}...`)
|
|
- pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...])
|
|
- pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...] + $...A)
|
|
- pattern: $RES.redirect(`$HTTP${$REQ.$VALUE[...]}...`)
|
|
- metavariable-regex:
|
|
metavariable: $HTTP
|
|
regex: ^https?:\/\/$
|
|
- pattern-either:
|
|
- pattern: $REQ. ... .$VALUE
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $RES.redirect($REQ. ... .$VALUE)
|
|
- pattern: $RES.redirect($REQ. ... .$VALUE + $...A)
|
|
- pattern: $RES.redirect(`${$REQ. ... .$VALUE}...`)
|
|
- pattern: $REQ. ... .$VALUE
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $RES.redirect($REQ.$VALUE['...'])
|
|
- pattern: $RES.redirect($REQ.$VALUE['...'] + $...A)
|
|
- pattern: $RES.redirect(`${$REQ.$VALUE['...']}...`)
|
|
- pattern: $REQ.$VALUE
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$ASSIGN = $REQ. ... .$VALUE
|
|
...
|
|
- pattern-inside: |
|
|
$ASSIGN = $REQ.$VALUE['...']
|
|
...
|
|
- pattern-inside: |
|
|
$ASSIGN = $REQ. ... .$VALUE + $...A
|
|
...
|
|
- pattern-inside: "$ASSIGN = $REQ.$VALUE['...'] + $...A\n... \n"
|
|
- pattern-inside: |
|
|
$ASSIGN = `${$REQ. ... .$VALUE}...`
|
|
...
|
|
- pattern-inside: "$ASSIGN = `${$REQ.$VALUE['...']}...`\n... \n"
|
|
- pattern-either:
|
|
- pattern: $RES.redirect($ASSIGN)
|
|
- pattern: $RES.redirect($ASSIGN + $...FOO)
|
|
- pattern: $RES.redirect(`${$ASSIGN}...`)
|
|
- focus-metavariable: $ASSIGN
|
|
- id: javascript.express.security.audit.express-res-sendfile.express-res-sendfile
|
|
message: The application processes user-input, this is passed to res.sendFile which
|
|
can allow an attacker to arbitrarily read files on the system through path traversal.
|
|
It is recommended to perform input validation in addition to canonicalizing the
|
|
path. This allows you to validate the path against the intended directory it should
|
|
be accessing.
|
|
metadata:
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html
|
|
technology:
|
|
- express
|
|
category: security
|
|
cwe:
|
|
- 'CWE-73: External Control of File Name or Path'
|
|
owasp:
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Path Traversal
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-res-sendfile.express-res-sendfile
|
|
shortlink: https://sg.run/7DJk
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22082
|
|
rv_id: 1263142
|
|
rule_id: j2UzDx
|
|
version_id: 7ZTE3X9
|
|
url: https://semgrep.dev/playground/r/7ZTE3X9/javascript.express.security.audit.express-res-sendfile.express-res-sendfile
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
function ... (...,$REQ: $TYPE, ...) {...}
|
|
- metavariable-regex:
|
|
metavariable: $TYPE
|
|
regex: ^(string|String)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $RES.$METH($QUERY,...)
|
|
- pattern-not-inside: $RES.$METH($QUERY,$OPTIONS)
|
|
- metavariable-regex:
|
|
metavariable: $METH
|
|
regex: ^(sendfile|sendFile)$
|
|
- focus-metavariable: $QUERY
|
|
- id: javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret
|
|
message: A hard-coded credential was detected. It is not recommended to store credentials
|
|
in source-code, as this risks secrets being leaked and used by either an internal
|
|
or external malicious adversary. It is recommended to use environment variables
|
|
to securely provide credentials or retrieve credentials from a secure vault or
|
|
HSM (Hardware Security Module).
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
category: security
|
|
technology:
|
|
- express
|
|
- secrets
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret
|
|
shortlink: https://sg.run/LYvG
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22083
|
|
rv_id: 1263143
|
|
rule_id: 10Uo39
|
|
version_id: LjTkgle
|
|
url: https://semgrep.dev/playground/r/LjTkgle/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$SESSION = require('express-session');
|
|
...
|
|
- pattern-inside: |
|
|
import $SESSION from 'express-session'
|
|
...
|
|
- pattern-inside: |
|
|
import {..., $SESSION, ...} from 'express-session'
|
|
...
|
|
- pattern-inside: |
|
|
import * as $SESSION from 'express-session'
|
|
...
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.use($SESSION({...}))
|
|
- pattern: |
|
|
$SECRET = $VALUE
|
|
...
|
|
$APP.use($SESSION($SECRET))
|
|
- pattern: |
|
|
secret: '$Y'
|
|
- id: javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization
|
|
message: The following function call $SER.$FUNC accepts user controlled data which
|
|
can result in Remote Code Execution (RCE) through Object Deserialization. It is
|
|
recommended to use secure data processing alternatives such as JSON.parse() and
|
|
Buffer.from().
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
technology:
|
|
- express
|
|
category: security
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Deserialization_Cheat_Sheet.html
|
|
source_rule_url:
|
|
- https://github.com/ajinabraham/njsscan/blob/75bfbeb9c8d72999e4d527dfa2548f7f0f3cc48a/njsscan/rules/semantic_grep/eval/eval_deserialize.yaml
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization
|
|
shortlink: https://sg.run/8W5j
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22084
|
|
rv_id: 1263145
|
|
rule_id: 9AUyqj
|
|
version_id: gETB7nD
|
|
url: https://semgrep.dev/playground/r/gETB7nD/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
|
|
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
- pattern: files.$ANYTHING.data.toString('utf8')
|
|
- pattern: files.$ANYTHING['data'].toString('utf8')
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$SER = require('$IMPORT')
|
|
...
|
|
- pattern-inside: |
|
|
import $SER from '$IMPORT'
|
|
...
|
|
- pattern-inside: |
|
|
import * as $SER from '$IMPORT'
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $IMPORT
|
|
regex: ^(node-serialize|serialize-to-js)$
|
|
- pattern: $SER.$FUNC(...)
|
|
- metavariable-regex:
|
|
metavariable: $FUNC
|
|
regex: ^(unserialize|deserialize)$
|
|
- id: javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection
|
|
message: Detected a sequelize statement that is tainted by user-input. This could
|
|
lead to SQL injection if the variable is user-controlled and is not properly sanitized.
|
|
In order to prevent SQL injection, it is recommended to use parameterized queries
|
|
or prepared statements.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
references:
|
|
- https://sequelize.org/docs/v6/core-concepts/raw-queries/#replacements
|
|
category: security
|
|
technology:
|
|
- express
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection
|
|
shortlink: https://sg.run/gjoe
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22085
|
|
rv_id: 1263241
|
|
rule_id: yyU0GX
|
|
version_id: nWT2Llx
|
|
url: https://semgrep.dev/playground/r/nWT2Llx/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, $RES) {...}
|
|
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
|
|
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|head|delete|options)$
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
|
|
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,$RES: Response) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
- pattern: files.$ANYTHING.data.toString('utf8')
|
|
- pattern: files.$ANYTHING['data'].toString('utf8')
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sequelize.query($QUERY,...)
|
|
- pattern: $DB.sequelize.query($QUERY,...)
|
|
- focus-metavariable: $QUERY
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: parseInt(...)
|
|
- pattern: $FUNC. ... .hash(...)
|
|
- id: javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing
|
|
message: Directory listing/indexing is enabled, which may lead to disclosure of
|
|
sensitive directories and files. It is recommended to disable directory listing
|
|
unless it is a public resource. If you need directory listing, ensure that sensitive
|
|
files are inaccessible when querying the resource.
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
interfile: true
|
|
cwe:
|
|
- 'CWE-548: Exposure of Information Through Directory Listing'
|
|
owasp:
|
|
- A06:2017 - Security Misconfiguration
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
category: security
|
|
technology:
|
|
- express
|
|
references:
|
|
- https://www.npmjs.com/package/serve-index
|
|
- https://www.acunetix.com/blog/articles/directory-listing-information-disclosure/
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing
|
|
shortlink: https://sg.run/DX2G
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22552
|
|
rv_id: 1263129
|
|
rule_id: x8UqEb
|
|
version_id: rxTAKGb
|
|
url: https://semgrep.dev/playground/r/rxTAKGb/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$APP.use(require('serve-index')(...))
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$SERVEINDEX = require('serve-index')
|
|
...
|
|
- pattern-inside: |
|
|
import $SERVEINDEX from 'serve-index'
|
|
...
|
|
- pattern-inside: |
|
|
import * as $SERVEINDEX from 'serve-index'
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VALUE = $SERVEINDEX(...)
|
|
...
|
|
- pattern: |
|
|
$VALUE(...)
|
|
- pattern: |
|
|
$APP.use(..., $SERVEINDEX(...), ...)
|
|
- id: javascript.express.security.audit.express-ssrf.express-ssrf
|
|
message: 'The following request $REQUEST.$METHOD() was found to be crafted from
|
|
user-input `$REQ` which can lead to Server-Side Request Forgery (SSRF) vulnerabilities.
|
|
It is recommended where possible to not allow user-input to craft the base request,
|
|
but to be treated as part of the path or query parameter. When user-input is necessary
|
|
to craft the request, it is recommeneded to follow OWASP best practices to prevent
|
|
abuse. '
|
|
metadata:
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
technology:
|
|
- express
|
|
category: security
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/javascript.express.security.audit.express-ssrf.express-ssrf
|
|
shortlink: https://sg.run/0PNw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 22554
|
|
rv_id: 1263144
|
|
rule_id: eqU9l2
|
|
version_id: 8KT5rBr
|
|
url: https://semgrep.dev/playground/r/8KT5rBr/javascript.express.security.audit.express-ssrf.express-ssrf
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: WARNING
|
|
mode: taint
|
|
options:
|
|
taint_unify_mvars: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: function ... ($REQ, ...) {...}
|
|
- pattern-either:
|
|
- pattern: $REQ.query
|
|
- pattern: $REQ.body
|
|
- pattern: $REQ.params
|
|
- pattern: $REQ.cookies
|
|
- pattern: $REQ.headers
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
({ $REQ }: Request,...) =>
|
|
{...}
|
|
- pattern-inside: |
|
|
({ $REQ }: $EXPRESS.Request,...) => {...}
|
|
- focus-metavariable: $REQ
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: query
|
|
- pattern: cookies
|
|
- pattern: headers
|
|
- pattern: body
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$REQUEST = require('request')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $REQUEST from 'request'
|
|
...
|
|
- pattern-inside: |
|
|
import $REQUEST from 'request'
|
|
...
|
|
- pattern-either:
|
|
- pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE)
|
|
- pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE + $...A)
|
|
- pattern: $REQUEST.$METHOD(`$HTTP${$REQ. ... .$VALUE}...`)
|
|
- pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...])
|
|
- pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...] + $...A)
|
|
- pattern: $REQUEST.$METHOD(`$HTTP${$REQ.$VALUE[...]}...`)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|patch|del|head|delete)$
|
|
- metavariable-regex:
|
|
metavariable: $HTTP
|
|
regex: ^(https?:\/\/|//)$
|
|
- pattern-either:
|
|
- pattern: $REQ. ... .$VALUE
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$REQUEST = require('request')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $REQUEST from 'request'
|
|
...
|
|
- pattern-inside: |
|
|
import $REQUEST from 'request'
|
|
...
|
|
- pattern-either:
|
|
- pattern: $REQUEST.$METHOD($REQ. ... .$VALUE,...)
|
|
- pattern: $REQUEST.$METHOD($REQ. ... .$VALUE + $...A,...)
|
|
- pattern: $REQUEST.$METHOD(`${$REQ. ... .$VALUE}...`,...)
|
|
- pattern: $REQ. ... .$VALUE
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|patch|del|head|delete)$
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$REQUEST = require('request')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $REQUEST from 'request'
|
|
...
|
|
- pattern-inside: |
|
|
import $REQUEST from 'request'
|
|
...
|
|
- pattern-either:
|
|
- pattern: $REQUEST.$METHOD($REQ.$VALUE['...'],...)
|
|
- pattern: $REQUEST.$METHOD($REQ.$VALUE['...'] + $...A,...)
|
|
- pattern: $REQUEST.$METHOD(`${$REQ.$VALUE['...']}...`,...)
|
|
- pattern: $REQ.$VALUE
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|patch|del|head|delete)$
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$REQUEST = require('request')
|
|
...
|
|
- pattern-inside: |
|
|
import * as $REQUEST from 'request'
|
|
...
|
|
- pattern-inside: |
|
|
import $REQUEST from 'request'
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$ASSIGN = $REQ. ... .$VALUE
|
|
...
|
|
- pattern-inside: |
|
|
$ASSIGN = $REQ. ... .$VALUE['...']
|
|
...
|
|
- pattern-inside: |
|
|
$ASSIGN = $REQ. ... .$VALUE + $...A
|
|
...
|
|
- pattern-inside: "$ASSIGN = $REQ. ... .$VALUE['...'] + $...A\n... \n"
|
|
- pattern-inside: |
|
|
$ASSIGN = `${$REQ. ... .$VALUE}...`
|
|
...
|
|
- pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE['...']}...`\n... \n"
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$ASSIGN = "$HTTP"+ $REQ. ... .$VALUE
|
|
...
|
|
- pattern-inside: |
|
|
$ASSIGN = "$HTTP"+$REQ. ... .$VALUE + $...A
|
|
...
|
|
- pattern-inside: |
|
|
$ASSIGN = "$HTTP"+$REQ.$VALUE[...]
|
|
...
|
|
- pattern-inside: |
|
|
$ASSIGN = "$HTTP"+$REQ.$VALUE[...] + $...A
|
|
...
|
|
- pattern-inside: |
|
|
$ASSIGN = `$HTTP${$REQ.$VALUE[...]}...`
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $HTTP
|
|
regex: ^(https?:\/\/|//)$
|
|
- pattern-either:
|
|
- pattern: $REQUEST.$METHOD($ASSIGN,...)
|
|
- pattern: $REQUEST.$METHOD($ASSIGN + $...FOO,...)
|
|
- pattern: $REQUEST.$METHOD(`${$ASSIGN}...`,...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN,...)
|
|
- pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN + $...A,...)
|
|
- pattern: $REQUEST.$METHOD(`$HTTP${$ASSIGN}...`,...)
|
|
- metavariable-regex:
|
|
metavariable: $HTTP
|
|
regex: ^(https?:\/\/|//)$
|
|
- pattern: $ASSIGN
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(get|post|put|patch|del|head|delete)$
|
|
- id: terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled
|
|
message: Ensure that App service enables detailed error messages
|
|
patterns:
|
|
- pattern: resource
|
|
- pattern-not-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
logs {
|
|
...
|
|
detailed_error_messages_enabled = true
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
}
|
|
metadata:
|
|
owasp:
|
|
- A10:2017 - Insufficient Logging & Monitoring
|
|
- A09:2021 - Security Logging and Monitoring Failures
|
|
- A09:2025 - Security Logging & Alerting Failures
|
|
cwe:
|
|
- 'CWE-778: Insufficient Logging'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insufficient Logging
|
|
source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled
|
|
shortlink: https://sg.run/pA1g
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 23962
|
|
rv_id: 1263762
|
|
rule_id: bwU1Eg
|
|
version_id: DkTRbr5
|
|
url: https://semgrep.dev/playground/r/DkTRbr5/terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only
|
|
message: Ensure web app redirects all HTTP traffic to HTTPS in Azure App Service
|
|
Slot
|
|
patterns:
|
|
- pattern: resource
|
|
- pattern-not-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
https_only = true
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
}
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only
|
|
shortlink: https://sg.run/1g9w
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 23966
|
|
rv_id: 1263766
|
|
rule_id: x8UZRP
|
|
version_id: qkTR78q
|
|
url: https://semgrep.dev/playground/r/qkTR78q/terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version
|
|
message: Ensure web app is using the latest version of TLS encryption
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"1.0"
|
|
- pattern: |
|
|
"1.1"
|
|
- pattern-inside: min_tls_version = ...
|
|
- pattern-inside: |
|
|
$RESOURCE "azurerm_app_service" "..." {
|
|
...
|
|
}
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version
|
|
shortlink: https://sg.run/rDwn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 23969
|
|
rv_id: 1263769
|
|
rule_id: v8UNL7
|
|
version_id: 6xT29gv
|
|
url: https://semgrep.dev/playground/r/6xT29gv/terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date
|
|
message: Ensure that the expiration date is set on all keys
|
|
patterns:
|
|
- pattern: resource
|
|
- pattern-not-inside: |
|
|
resource "azurerm_key_vault_key" "..." {
|
|
...
|
|
expiration_date = "..."
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "azurerm_key_vault_key" "..." {
|
|
...
|
|
}
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
cwe:
|
|
- 'CWE-320: CWE CATEGORY: Key Management Errors'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date
|
|
shortlink: https://sg.run/J1vw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 23990
|
|
rv_id: 946834
|
|
rule_id: 0oUlgp
|
|
version_id: pZTNGkl
|
|
url: https://semgrep.dev/playground/r/pZTNGkl/terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version
|
|
message: Ensure MSSQL is using the latest version of TLS encryption
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"1.0"
|
|
- pattern: |
|
|
"1.1"
|
|
- pattern-inside: minimum_tls_version = ...
|
|
- pattern-inside: |
|
|
$RESOURCE "azurerm_mssql_server" "..." {
|
|
...
|
|
}
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version
|
|
shortlink: https://sg.run/B1lW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 23995
|
|
rv_id: 1263784
|
|
rule_id: 6JUJG8
|
|
version_id: xyTjzeR
|
|
url: https://semgrep.dev/playground/r/xyTjzeR/terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled
|
|
message: Ensure that MySQL server enables infrastructure encryption
|
|
patterns:
|
|
- pattern: resource
|
|
- pattern-inside: |
|
|
resource "azurerm_mysql_server" "..." {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "azurerm_mysql_server" "..." {
|
|
...
|
|
infrastructure_encryption_enabled = true
|
|
...
|
|
}
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
cwe:
|
|
- 'CWE-320: CWE CATEGORY: Key Management Errors'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled
|
|
shortlink: https://sg.run/Dd6Y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 23996
|
|
rv_id: 946840
|
|
rule_id: oqUloL
|
|
version_id: yeT0vBn
|
|
url: https://semgrep.dev/playground/r/yeT0vBn/terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version
|
|
message: Ensure MySQL is using the latest version of TLS encryption
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"TLS1_0"
|
|
- pattern: |
|
|
"TLS1_1"
|
|
- pattern-inside: ssl_minimal_tls_version_enforced = ...
|
|
- pattern-inside: |
|
|
$RESOURCE "azurerm_mysql_server" "..." {
|
|
...
|
|
}
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version
|
|
shortlink: https://sg.run/WR44
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 23997
|
|
rv_id: 1263785
|
|
rule_id: zdU8NN
|
|
version_id: O9TpxWE
|
|
url: https://semgrep.dev/playground/r/O9TpxWE/terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage
|
|
message: Detected usage of dangerous method $METHOD which does not escape inputs
|
|
(see link in references). If the argument is user-controlled, this can lead to
|
|
SQL injection. When using $METHOD function, do not trust user-submitted data and
|
|
only allow approved list of input (possibly, use an allowlist approach).
|
|
severity: WARNING
|
|
languages:
|
|
- go
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
($REQUEST : http.Request).$ANYTHING
|
|
- pattern: |
|
|
($REQUEST : *http.Request).$ANYTHING
|
|
- metavariable-regex:
|
|
metavariable: $ANYTHING
|
|
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import ("gorm.io/gorm")
|
|
...
|
|
- patterns:
|
|
- pattern-inside: |
|
|
func $VAL(..., $GORM *gorm.DB,... ) {
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern: |
|
|
$GORM. ... .$METHOD($VALUE)
|
|
- pattern: |
|
|
$DB := $GORM. ... .$ANYTHING(...)
|
|
...
|
|
$DB. ... .$METHOD($VALUE)
|
|
- focus-metavariable: $VALUE
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: ^(Order|Exec|Raw|Group|Having|Distinct|Select|Pluck)$
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: strconv.Atoi(...)
|
|
- pattern: |
|
|
($X: bool)
|
|
options:
|
|
interfile: true
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- gorm
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://gorm.io/docs/security.html#SQL-injection-Methods
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage
|
|
shortlink: https://sg.run/R4qg
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 24693
|
|
rv_id: 1262915
|
|
rule_id: AbU5o3
|
|
version_id: l4TJRJK
|
|
url: https://semgrep.dev/playground/r/l4TJRJK/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage
|
|
origin: community
|
|
- id: yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
spec:
|
|
...
|
|
securityContext:
|
|
...
|
|
runAsNonRoot: $VALUE
|
|
- patterns:
|
|
- pattern-inside: |
|
|
containers:
|
|
...
|
|
- pattern: |
|
|
image: ...
|
|
...
|
|
securityContext:
|
|
...
|
|
runAsNonRoot: $VALUE
|
|
- metavariable-pattern:
|
|
metavariable: $VALUE
|
|
pattern: |
|
|
false
|
|
- focus-metavariable: $VALUE
|
|
fix: |
|
|
true
|
|
message: When running containers in Kubernetes, it's important to ensure that they are
|
|
properly secured to prevent privilege escalation attacks. One potential vulnerability
|
|
is when a container is allowed to run applications as the root user, which could
|
|
allow an attacker to gain access to sensitive resources. To mitigate this risk,
|
|
it's recommended to add a `securityContext` to the container, with the parameter
|
|
`runAsNonRoot` set to `true`. This will ensure that the container runs as a non-root
|
|
user, limiting the damage that could be caused by any potential attacks. By adding
|
|
a `securityContext` to the container in your Kubernetes pod, you can help to
|
|
ensure that your containerized applications are more secure and less vulnerable
|
|
to privilege escalation attacks.
|
|
metadata:
|
|
references:
|
|
- https://kubernetes.io/blog/2016/08/security-best-practices-kubernetes-deployment/
|
|
- https://kubernetes.io/docs/concepts/policy/pod-security-policy/
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-2-set-a-user
|
|
cwe:
|
|
- 'CWE-250: Execution with Unnecessary Privileges'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A06:2017 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
category: security
|
|
technology:
|
|
- kubernetes
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value
|
|
shortlink: https://sg.run/D9No
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 26096
|
|
rv_id: 1263939
|
|
rule_id: L1UAxy
|
|
version_id: NdTzyj8
|
|
url: https://semgrep.dev/playground/r/NdTzyj8/yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value
|
|
origin: community
|
|
languages:
|
|
- yaml
|
|
severity: INFO
|
|
- id: csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization
|
|
message: Anonymous access shouldn't be allowed unless explicit by design. Access
|
|
control checks are missing and potentially can be bypassed. This finding violates
|
|
the principle of least privilege or deny by default, where access should only
|
|
be permitted for a specific set of roles or conforms to a custom policy or users.
|
|
severity: INFO
|
|
metadata:
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe:
|
|
- 'CWE-862: Missing Authorization'
|
|
cwe2021-top25: true
|
|
cwe2022-top25: true
|
|
cwe2023-top25: true
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
- https://cwe.mitre.org/data/definitions/862.html
|
|
- https://docs.microsoft.com/en-us/aspnet/core/security/authorization/simple?view=aspnetcore-7.0
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
- mvc
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization
|
|
shortlink: https://sg.run/Z8GA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 26335
|
|
rv_id: 1262615
|
|
rule_id: eqU32Y
|
|
version_id: o5TbD41
|
|
url: https://semgrep.dev/playground/r/o5TbD41/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
patterns:
|
|
- pattern: |
|
|
public class $CLASS : Controller {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
using Microsoft.AspNetCore.Mvc;
|
|
...
|
|
- pattern-not: |
|
|
[AllowAnonymous]
|
|
public class $CLASS : Controller {
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
[Authorize]
|
|
public class $CLASS : Controller {
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
[Authorize(Roles = ...)]
|
|
public class $CLASS : Controller {
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
[Authorize(Policy = ...)]
|
|
public class $CLASS : Controller {
|
|
...
|
|
}
|
|
- id: csharp.dotnet.security.audit.open-directory-listing.open-directory-listing
|
|
message: An open directory listing is potentially exposed, potentially revealing
|
|
sensitive information to attackers.
|
|
severity: INFO
|
|
metadata:
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe:
|
|
- 'CWE-548: Exposure of Information Through Directory Listing'
|
|
owasp:
|
|
- A06:2017 - Security Misconfiguration
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/548.html
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration/
|
|
- https://docs.microsoft.com/en-us/aspnet/core/fundamentals/static-files?view=aspnetcore-7.0#directory-browsing
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
- mvc
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.audit.open-directory-listing.open-directory-listing
|
|
shortlink: https://sg.run/n0y1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 26336
|
|
rv_id: 1262616
|
|
rule_id: v8U8Ab
|
|
version_id: zyTb2Y2
|
|
url: https://semgrep.dev/playground/r/zyTb2Y2/csharp.dotnet.security.audit.open-directory-listing.open-directory-listing
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: (IApplicationBuilder $APP).UseDirectoryBrowser(...);
|
|
- pattern: $BUILDER.Services.AddDirectoryBrowser(...);
|
|
- pattern-inside: |
|
|
public void Configure(...) {
|
|
...
|
|
}
|
|
- id: csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token
|
|
patterns:
|
|
- pattern: RequireSignedTokens = false
|
|
- pattern-inside: |
|
|
new TokenValidationParameters {
|
|
...
|
|
}
|
|
fix: RequireSignedTokens = true
|
|
message: Accepting unsigned security tokens as valid security tokens allows an attacker
|
|
to remove its signature and potentially forge an identity. As a fix, set RequireSignedTokens
|
|
to be true.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- csharp
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-347: Improper Verification of Cryptographic Signature'
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures/
|
|
- https://cwe.mitre.org/data/definitions/347
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token
|
|
shortlink: https://sg.run/pqzN
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 26718
|
|
rv_id: 1262631
|
|
rule_id: KxUGLw
|
|
version_id: e1Tyjrz
|
|
url: https://semgrep.dev/playground/r/e1Tyjrz/csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
severity: ERROR
|
|
- id: csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure
|
|
patterns:
|
|
- pattern: $APP.UseDeveloperExceptionPage(...);
|
|
- pattern-not-inside: |
|
|
if ($ENV.IsDevelopment(...)) {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
if ($ENV.EnvironmentName == "Development") {
|
|
...
|
|
}
|
|
message: Stacktrace information is displayed in a non-Development environment. Accidentally
|
|
disclosing sensitive stack trace information in a production environment aids
|
|
an attacker in reconnaissance and information gathering.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- csharp
|
|
owasp:
|
|
- A06:2017 - Security Misconfiguration
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
cwe:
|
|
- 'CWE-209: Generation of Error Message Containing Sensitive Information'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/209.html
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design/
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure
|
|
shortlink: https://sg.run/XvkA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 26720
|
|
rv_id: 1262653
|
|
rule_id: lBU6Dv
|
|
version_id: 0bTKzrB
|
|
url: https://semgrep.dev/playground/r/0bTKzrB/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
severity: WARNING
|
|
- id: csharp.dotnet.security.audit.mass-assignment.mass-assignment
|
|
message: Mass assignment or Autobinding vulnerability in code allows an attacker
|
|
to execute over-posting attacks, which could create a new parameter in the binding
|
|
request and manipulate the underlying object in the application.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe:
|
|
- 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object
|
|
Attributes'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/915.html
|
|
- https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa6-mass-assignment.md
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mass Assignment
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.audit.mass-assignment.mass-assignment
|
|
shortlink: https://sg.run/7B3e
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 26838
|
|
rv_id: 1262613
|
|
rule_id: x8Up5B
|
|
version_id: YDTZeD9
|
|
url: https://semgrep.dev/playground/r/YDTZeD9/csharp.dotnet.security.audit.mass-assignment.mass-assignment
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
public IActionResult $METHOD(..., $TYPE $ARG, ...){
|
|
...
|
|
}
|
|
- pattern: |
|
|
public ActionResult $METHOD(..., $TYPE $ARG, ...){
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
using Microsoft.AspNetCore.Mvc;
|
|
...
|
|
- pattern-not: |
|
|
public IActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
public ActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){
|
|
...
|
|
}
|
|
- focus-metavariable: $ARG
|
|
pattern-sinks:
|
|
- pattern: View(...)
|
|
- id: python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: os.environ
|
|
- pattern: os.environ.get('$FOO', ...)
|
|
- pattern: os.environb
|
|
- pattern: os.environb.get('$FOO', ...)
|
|
- pattern: os.getenv('$ANYTHING', ...)
|
|
- pattern: os.getenvb('$ANYTHING', ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sys.argv
|
|
- pattern: sys.orig_argv
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = argparse.ArgumentParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = optparse.OptionParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.getopt(...)
|
|
...
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.gnu_getopt(...)
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
for $O, $A in $OPTS:
|
|
...
|
|
- pattern: $A
|
|
- pattern: $ARGS
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-not: $LOOP.subprocess_exec($PROTOCOL, "...", ...)
|
|
- pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["...",...], ...)
|
|
- pattern: $LOOP.subprocess_exec(...)
|
|
- patterns:
|
|
- pattern-not: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/",
|
|
"-c", "...", ...)
|
|
- pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/",
|
|
"-c",...)
|
|
- patterns:
|
|
- pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/",
|
|
"-c", "...", ...], ...)
|
|
- pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/",
|
|
"-c", ...], ...)
|
|
message: Detected subprocess function '$LOOP.subprocess_exec' with user controlled
|
|
data. You may consider using 'shlex.escape()'.
|
|
metadata:
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
references:
|
|
- https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec
|
|
- https://docs.python.org/3/library/shlex.html
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args
|
|
shortlink: https://sg.run/Apjp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27250
|
|
rv_id: 1263460
|
|
rule_id: 7KUE1E
|
|
version_id: WrTqKXz
|
|
url: https://semgrep.dev/playground/r/WrTqKXz/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: os.environ
|
|
- pattern: os.environ.get('$FOO', ...)
|
|
- pattern: os.environb
|
|
- pattern: os.environb.get('$FOO', ...)
|
|
- pattern: os.getenv('$ANYTHING', ...)
|
|
- pattern: os.getenvb('$ANYTHING', ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sys.argv
|
|
- pattern: sys.orig_argv
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = argparse.ArgumentParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = optparse.OptionParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.getopt(...)
|
|
...
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.gnu_getopt(...)
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
for $O, $A in $OPTS:
|
|
...
|
|
- pattern: $A
|
|
- pattern: $ARGS
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: $LOOP.subprocess_shell($PROTOCOL, $CMD)
|
|
- pattern-inside: asyncio.subprocess.create_subprocess_shell($CMD, ...)
|
|
- pattern-inside: asyncio.create_subprocess_shell($CMD, ...)
|
|
- focus-metavariable: $CMD
|
|
- pattern-not-inside: |
|
|
$CMD = "..."
|
|
...
|
|
- pattern-not: $LOOP.subprocess_shell($PROTOCOL, "...")
|
|
- pattern-not: asyncio.subprocess.create_subprocess_shell("...", ...)
|
|
- pattern-not: asyncio.create_subprocess_shell("...", ...)
|
|
message: Detected asyncio subprocess function with user controlled data. You may
|
|
consider using 'shlex.escape()'.
|
|
metadata:
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
references:
|
|
- https://docs.python.org/3/library/asyncio-subprocess.html
|
|
- https://docs.python.org/3/library/shlex.html
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args
|
|
shortlink: https://sg.run/Dx8Y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27252
|
|
rv_id: 1263462
|
|
rule_id: 8GU5q3
|
|
version_id: K3TKkDn
|
|
url: https://semgrep.dev/playground/r/K3TKkDn/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: os.environ
|
|
- pattern: os.environ.get('$FOO', ...)
|
|
- pattern: os.environb
|
|
- pattern: os.environb.get('$FOO', ...)
|
|
- pattern: os.getenv('$ANYTHING', ...)
|
|
- pattern: os.getenvb('$ANYTHING', ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sys.argv
|
|
- pattern: sys.orig_argv
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = argparse.ArgumentParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = optparse.OptionParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.getopt(...)
|
|
...
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.gnu_getopt(...)
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
for $O, $A in $OPTS:
|
|
...
|
|
- pattern: $A
|
|
- pattern: $ARGS
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$X = code.InteractiveConsole(...)
|
|
...
|
|
- pattern-inside: |
|
|
$X = code.InteractiveInterpreter(...)
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$X.push($PAYLOAD,...)
|
|
- pattern-inside: |
|
|
$X.runsource($PAYLOAD,...)
|
|
- pattern-inside: |
|
|
$X.runcode(code.compile_command($PAYLOAD),...)
|
|
- pattern-inside: |
|
|
$PL = code.compile_command($PAYLOAD,...)
|
|
...
|
|
$X.runcode($PL,...)
|
|
- pattern: $PAYLOAD
|
|
- pattern-not: |
|
|
$X.push("...",...)
|
|
- pattern-not: |
|
|
$X.runsource("...",...)
|
|
- pattern-not: |
|
|
$X.runcode(code.compile_command("..."),...)
|
|
- pattern-not: |
|
|
$PL = code.compile_command("...",...)
|
|
...
|
|
$X.runcode($PL,...)
|
|
message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter
|
|
method. This is dangerous if external data can reach this function call because
|
|
it allows a malicious actor to run arbitrary Python code.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args
|
|
shortlink: https://sg.run/0Bgv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27254
|
|
rv_id: 1263464
|
|
rule_id: QrUG72
|
|
version_id: l4TJRK9
|
|
url: https://semgrep.dev/playground/r/l4TJRK9/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
- id: python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: os.environ
|
|
- pattern: os.environ.get('$FOO', ...)
|
|
- pattern: os.environb
|
|
- pattern: os.environb.get('$FOO', ...)
|
|
- pattern: os.getenv('$ANYTHING', ...)
|
|
- pattern: os.getenvb('$ANYTHING', ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sys.argv
|
|
- pattern: sys.orig_argv
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = argparse.ArgumentParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = optparse.OptionParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.getopt(...)
|
|
...
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.gnu_getopt(...)
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
for $O, $A in $OPTS:
|
|
...
|
|
- pattern: $A
|
|
- pattern: $ARGS
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-not: os.$METHOD("...", ...)
|
|
- pattern: os.$METHOD(...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe)
|
|
- patterns:
|
|
- pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...)
|
|
- pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...)
|
|
- pattern: $CMD
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (execv|execve|execvp|execvpe)
|
|
- metavariable-regex:
|
|
metavariable: $BASH
|
|
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
|
|
- patterns:
|
|
- pattern-not: os.$METHOD("...", $PATH, "...", "...",...)
|
|
- pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...)
|
|
- pattern: $CMD
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (execl|execle|execlp|execlpe)
|
|
- metavariable-regex:
|
|
metavariable: $BASH
|
|
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
|
|
message: Found user controlled content when spawning a process. This is dangerous
|
|
because it allows a malicious actor to execute commands.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
confidence: MEDIUM
|
|
category: security
|
|
technology:
|
|
- python
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args
|
|
shortlink: https://sg.run/qL6z
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27256
|
|
rv_id: 1263466
|
|
rule_id: 4bUEAY
|
|
version_id: 6xT29l6
|
|
url: https://semgrep.dev/playground/r/6xT29l6/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: os.environ
|
|
- pattern: os.environ.get('$FOO', ...)
|
|
- pattern: os.environb
|
|
- pattern: os.environb.get('$FOO', ...)
|
|
- pattern: os.getenv('$ANYTHING', ...)
|
|
- pattern: os.getenvb('$ANYTHING', ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sys.argv
|
|
- pattern: sys.orig_argv
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = argparse.ArgumentParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = optparse.OptionParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.getopt(...)
|
|
...
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.gnu_getopt(...)
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
for $O, $A in $OPTS:
|
|
...
|
|
- pattern: $A
|
|
- pattern: $ARGS
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-not: os.$METHOD($MODE, "...", ...)
|
|
- pattern-inside: os.$METHOD($MODE, $CMD, ...)
|
|
- pattern: $CMD
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile)
|
|
- patterns:
|
|
- pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...)
|
|
- pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...)
|
|
- pattern: $CMD
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp)
|
|
- metavariable-regex:
|
|
metavariable: $BASH
|
|
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
|
|
- patterns:
|
|
- pattern-not: os.$METHOD($MODE, "...", "...", "...", ...)
|
|
- pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...)
|
|
- pattern: $CMD
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (spawnl|spawnle|spawnlp|spawnlpe)
|
|
- metavariable-regex:
|
|
metavariable: $BASH
|
|
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
|
|
message: Found user controlled content when spawning a process. This is dangerous
|
|
because it allows a malicious actor to execute commands.
|
|
metadata:
|
|
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args
|
|
shortlink: https://sg.run/Y3Ke
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27258
|
|
rv_id: 1263468
|
|
rule_id: JDUz34
|
|
version_id: zyTb2wn
|
|
url: https://semgrep.dev/playground/r/zyTb2wn/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: os.environ
|
|
- pattern: os.environ.get('$FOO', ...)
|
|
- pattern: os.environb
|
|
- pattern: os.environb.get('$FOO', ...)
|
|
- pattern: os.getenv('$ANYTHING', ...)
|
|
- pattern: os.getenvb('$ANYTHING', ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sys.argv
|
|
- pattern: sys.orig_argv
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = argparse.ArgumentParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = optparse.OptionParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.getopt(...)
|
|
...
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.gnu_getopt(...)
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
for $O, $A in $OPTS:
|
|
...
|
|
- pattern: $A
|
|
- pattern: $ARGS
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
_xxsubinterpreters.run_string($ID, $PAYLOAD, ...)
|
|
- pattern-not: |
|
|
_xxsubinterpreters.run_string($ID, "...", ...)
|
|
- pattern: $PAYLOAD
|
|
message: Found user controlled content in `run_string`. This is dangerous because
|
|
it allows a malicious actor to run arbitrary Python code.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://bugs.python.org/issue43472
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args
|
|
shortlink: https://sg.run/oLl9
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27260
|
|
rv_id: 1409404
|
|
rule_id: GdUkxO
|
|
version_id: DkTwBzO
|
|
url: https://semgrep.dev/playground/r/DkTwBzO/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
- id: python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sanitizers:
|
|
- pattern: shlex.quote(...)
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: os.environ
|
|
- pattern: os.environ.get('$FOO', ...)
|
|
- pattern: os.environb
|
|
- pattern: os.environb.get('$FOO', ...)
|
|
- pattern: os.getenv('$ANYTHING', ...)
|
|
- pattern: os.getenvb('$ANYTHING', ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sys.argv
|
|
- pattern: sys.orig_argv
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = argparse.ArgumentParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = optparse.OptionParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.getopt(...)
|
|
...
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.gnu_getopt(...)
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
for $O, $A in $OPTS:
|
|
...
|
|
- pattern: $A
|
|
- pattern: $ARGS
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-not: subprocess.$FUNC("...", ...)
|
|
- pattern-not: subprocess.$FUNC(["...",...], ...)
|
|
- pattern-not: subprocess.$FUNC(("...",...), ...)
|
|
- pattern-not: subprocess.CalledProcessError(...)
|
|
- pattern-not: subprocess.SubprocessError(...)
|
|
- pattern: subprocess.$FUNC($CMD, ...)
|
|
- patterns:
|
|
- pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...)
|
|
- pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD)
|
|
- patterns:
|
|
- pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...)
|
|
- pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...)
|
|
- pattern-either:
|
|
- pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD],
|
|
...)
|
|
- pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD),
|
|
...)
|
|
- patterns:
|
|
- pattern-not: subprocess.$FUNC("=~/(python)/","...",...)
|
|
- pattern: subprocess.$FUNC("=~/(python)/", $CMD)
|
|
- patterns:
|
|
- pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...)
|
|
- pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...)
|
|
- pattern-either:
|
|
- pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...)
|
|
- pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...)
|
|
- focus-metavariable: $CMD
|
|
message: Detected subprocess function '$FUNC' with user controlled data. A malicious
|
|
actor could leverage this to perform command injection. You may consider using
|
|
'shlex.quote()'.
|
|
metadata:
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
references:
|
|
- https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess
|
|
- https://docs.python.org/3/library/subprocess.html
|
|
- https://docs.python.org/3/library/shlex.html
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args
|
|
shortlink: https://sg.run/pLGg
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27262
|
|
rv_id: 1263472
|
|
rule_id: AbUgrZ
|
|
version_id: jQTn54Y
|
|
url: https://semgrep.dev/playground/r/jQTn54Y/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: os.environ
|
|
- pattern: os.environ.get('$FOO', ...)
|
|
- pattern: os.environb
|
|
- pattern: os.environb.get('$FOO', ...)
|
|
- pattern: os.getenv('$ANYTHING', ...)
|
|
- pattern: os.getenvb('$ANYTHING', ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sys.argv
|
|
- pattern: sys.orig_argv
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = argparse.ArgumentParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = optparse.OptionParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.getopt(...)
|
|
...
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.gnu_getopt(...)
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
for $O, $A in $OPTS:
|
|
...
|
|
- pattern: $A
|
|
- pattern: $ARGS
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-not: os.$W("...", ...)
|
|
- pattern-either:
|
|
- pattern: os.system(...)
|
|
- pattern: |
|
|
$X = __import__("os")
|
|
...
|
|
$X.system(...)
|
|
- pattern: |
|
|
$X = __import__("os")
|
|
...
|
|
getattr($X, "system")(...)
|
|
- pattern: |
|
|
$X = getattr(os, "system")
|
|
...
|
|
$X(...)
|
|
- pattern: |
|
|
$X = __import__("os")
|
|
...
|
|
$Y = getattr($X, "system")
|
|
...
|
|
$Y(...)
|
|
- pattern: os.popen(...)
|
|
- pattern: os.popen2(...)
|
|
- pattern: os.popen3(...)
|
|
- pattern: os.popen4(...)
|
|
message: Found user-controlled data used in a system call. This could allow a malicious
|
|
actor to execute commands. Use the 'subprocess' module instead, which is easier
|
|
to use without accidentally exposing a command injection vulnerability.
|
|
metadata:
|
|
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.2.4 Dyanmic Code Execution Features
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args
|
|
shortlink: https://sg.run/XR2K
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27264
|
|
rv_id: 1263474
|
|
rule_id: DbUR9g
|
|
version_id: 9lT4bG4
|
|
url: https://semgrep.dev/playground/r/9lT4bG4/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: os.environ
|
|
- pattern: os.environ.get('$FOO', ...)
|
|
- pattern: os.environb
|
|
- pattern: os.environb.get('$FOO', ...)
|
|
- pattern: os.getenv('$ANYTHING', ...)
|
|
- pattern: os.getenvb('$ANYTHING', ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sys.argv
|
|
- pattern: sys.orig_argv
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = argparse.ArgumentParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = optparse.OptionParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.getopt(...)
|
|
...
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.gnu_getopt(...)
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
for $O, $A in $OPTS:
|
|
...
|
|
- pattern: $A
|
|
- pattern: $ARGS
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
_testcapi.run_in_subinterp($PAYLOAD, ...)
|
|
- pattern-inside: |
|
|
test.support.run_in_subinterp($PAYLOAD, ...)
|
|
- pattern: $PAYLOAD
|
|
- pattern-not: |
|
|
_testcapi.run_in_subinterp("...", ...)
|
|
- pattern-not: |
|
|
test.support.run_in_subinterp("...", ...)
|
|
message: Found user controlled content in `run_in_subinterp`. This is dangerous
|
|
because it allows a malicious actor to run arbitrary Python code.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args
|
|
shortlink: https://sg.run/1DLw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27266
|
|
rv_id: 1263476
|
|
rule_id: 0oUK7N
|
|
version_id: rxTAKpn
|
|
url: https://semgrep.dev/playground/r/rxTAKpn/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
- id: python.lang.security.dangerous-code-run.dangerous-interactive-code-run
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.form.get(...)
|
|
- pattern: flask.request.form[...]
|
|
- pattern: flask.request.args.get(...)
|
|
- pattern: flask.request.args[...]
|
|
- pattern: flask.request.values.get(...)
|
|
- pattern: flask.request.values[...]
|
|
- pattern: flask.request.cookies.get(...)
|
|
- pattern: flask.request.cookies[...]
|
|
- pattern: flask.request.stream
|
|
- pattern: flask.request.headers.get(...)
|
|
- pattern: flask.request.headers[...]
|
|
- pattern: flask.request.data
|
|
- pattern: flask.request.full_path
|
|
- pattern: flask.request.url
|
|
- pattern: flask.request.json
|
|
- pattern: flask.request.get_json()
|
|
- pattern: flask.request.view_args.get(...)
|
|
- pattern: flask.request.view_args[...]
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route(...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- focus-metavariable: $ROUTEVAR
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(request, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: request.$PROPERTY.get(...)
|
|
- pattern: request.$PROPERTY[...]
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@rest_framework.decorators.api_view(...)
|
|
def $FUNC($REQ, ...):
|
|
...
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $VIEW(..., rest_framework.views.APIView, ...):
|
|
...
|
|
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
|
|
...):\n ... \n"
|
|
- pattern-inside: |
|
|
def $METHOD(self, $REQ, ...):
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (get|post|put|patch|delete|head)
|
|
- pattern-either:
|
|
- pattern: $REQ.POST.get(...)
|
|
- pattern: $REQ.POST[...]
|
|
- pattern: $REQ.FILES.get(...)
|
|
- pattern: $REQ.FILES[...]
|
|
- pattern: $REQ.DATA.get(...)
|
|
- pattern: $REQ.DATA[...]
|
|
- pattern: $REQ.QUERY_PARAMS.get(...)
|
|
- pattern: $REQ.QUERY_PARAMS[...]
|
|
- pattern: $REQ.data.get(...)
|
|
- pattern: $REQ.data[...]
|
|
- pattern: $REQ.query_params.get(...)
|
|
- pattern: $REQ.query_params[...]
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.stream
|
|
- pattern: $REQ.stream
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.StreamRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.DatagramRequestHandler, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: self.requestline
|
|
- pattern: self.path
|
|
- pattern: self.headers[...]
|
|
- pattern: self.headers.get(...)
|
|
- pattern: self.rfile
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config( ... )
|
|
def $VIEW($REQ):
|
|
...
|
|
- pattern: $REQ.$ANYTHING
|
|
- pattern-not: $REQ.dbsession
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$X = code.InteractiveConsole(...)
|
|
...
|
|
- pattern-inside: |
|
|
$X = code.InteractiveInterpreter(...)
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
$X.push($PAYLOAD,...)
|
|
- pattern: |
|
|
$X.runsource($PAYLOAD,...)
|
|
- pattern: |
|
|
$X.runcode(code.compile_command($PAYLOAD),...)
|
|
- pattern: |
|
|
$PL = code.compile_command($PAYLOAD,...)
|
|
...
|
|
$X.runcode($PL,...)
|
|
- focus-metavariable: $PAYLOAD
|
|
- pattern-not: |
|
|
$X.push("...",...)
|
|
- pattern-not: |
|
|
$X.runsource("...",...)
|
|
- pattern-not: |
|
|
$X.runcode(code.compile_command("..."),...)
|
|
- pattern-not: |
|
|
$PL = code.compile_command("...",...)
|
|
...
|
|
$X.runcode($PL,...)
|
|
message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter
|
|
method. This is dangerous if external data can reach this function call because
|
|
it allows a malicious actor to run arbitrary Python code.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.lang.security.dangerous-code-run.dangerous-interactive-code-run
|
|
shortlink: https://sg.run/9pRY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27267
|
|
rv_id: 1263521
|
|
rule_id: KxUKzx
|
|
version_id: l4TJRgo
|
|
url: https://semgrep.dev/playground/r/l4TJRgo/python.lang.security.dangerous-code-run.dangerous-interactive-code-run
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
- id: python.lang.security.dangerous-os-exec.dangerous-os-exec
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.form.get(...)
|
|
- pattern: flask.request.form[...]
|
|
- pattern: flask.request.args.get(...)
|
|
- pattern: flask.request.args[...]
|
|
- pattern: flask.request.values.get(...)
|
|
- pattern: flask.request.values[...]
|
|
- pattern: flask.request.cookies.get(...)
|
|
- pattern: flask.request.cookies[...]
|
|
- pattern: flask.request.stream
|
|
- pattern: flask.request.headers.get(...)
|
|
- pattern: flask.request.headers[...]
|
|
- pattern: flask.request.data
|
|
- pattern: flask.request.full_path
|
|
- pattern: flask.request.url
|
|
- pattern: flask.request.json
|
|
- pattern: flask.request.get_json()
|
|
- pattern: flask.request.view_args.get(...)
|
|
- pattern: flask.request.view_args[...]
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route(...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- focus-metavariable: $ROUTEVAR
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(request, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: request.$PROPERTY.get(...)
|
|
- pattern: request.$PROPERTY[...]
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@rest_framework.decorators.api_view(...)
|
|
def $FUNC($REQ, ...):
|
|
...
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $VIEW(..., rest_framework.views.APIView, ...):
|
|
...
|
|
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
|
|
...):\n ... \n"
|
|
- pattern-inside: |
|
|
def $METHOD(self, $REQ, ...):
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (get|post|put|patch|delete|head)
|
|
- pattern-either:
|
|
- pattern: $REQ.POST.get(...)
|
|
- pattern: $REQ.POST[...]
|
|
- pattern: $REQ.FILES.get(...)
|
|
- pattern: $REQ.FILES[...]
|
|
- pattern: $REQ.DATA.get(...)
|
|
- pattern: $REQ.DATA[...]
|
|
- pattern: $REQ.QUERY_PARAMS.get(...)
|
|
- pattern: $REQ.QUERY_PARAMS[...]
|
|
- pattern: $REQ.data.get(...)
|
|
- pattern: $REQ.data[...]
|
|
- pattern: $REQ.query_params.get(...)
|
|
- pattern: $REQ.query_params[...]
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.stream
|
|
- pattern: $REQ.stream
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.StreamRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.DatagramRequestHandler, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: self.requestline
|
|
- pattern: self.path
|
|
- pattern: self.headers[...]
|
|
- pattern: self.headers.get(...)
|
|
- pattern: self.rfile
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config( ... )
|
|
def $VIEW($REQ):
|
|
...
|
|
- pattern: $REQ.$ANYTHING
|
|
- pattern-not: $REQ.dbsession
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-not: os.$METHOD("...", ...)
|
|
- pattern: os.$METHOD(...)
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe)
|
|
- patterns:
|
|
- pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...)
|
|
- pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...)
|
|
- pattern: $CMD
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (execv|execve|execvp|execvpe)
|
|
- metavariable-regex:
|
|
metavariable: $BASH
|
|
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
|
|
- patterns:
|
|
- pattern-not: os.$METHOD("...", $PATH, "...", "...",...)
|
|
- pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...)
|
|
- pattern: $CMD
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (execl|execle|execlp|execlpe)
|
|
- metavariable-regex:
|
|
metavariable: $BASH
|
|
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
|
|
message: Found user controlled content when spawning a process. This is dangerous
|
|
because it allows a malicious actor to execute commands.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
confidence: MEDIUM
|
|
category: security
|
|
technology:
|
|
- python
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.lang.security.dangerous-os-exec.dangerous-os-exec
|
|
shortlink: https://sg.run/yL9x
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27268
|
|
rv_id: 1263523
|
|
rule_id: qNUR13
|
|
version_id: 6xT29rz
|
|
url: https://semgrep.dev/playground/r/6xT29rz/python.lang.security.dangerous-os-exec.dangerous-os-exec
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.dangerous-spawn-process.dangerous-spawn-process
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.form.get(...)
|
|
- pattern: flask.request.form[...]
|
|
- pattern: flask.request.args.get(...)
|
|
- pattern: flask.request.args[...]
|
|
- pattern: flask.request.values.get(...)
|
|
- pattern: flask.request.values[...]
|
|
- pattern: flask.request.cookies.get(...)
|
|
- pattern: flask.request.cookies[...]
|
|
- pattern: flask.request.stream
|
|
- pattern: flask.request.headers.get(...)
|
|
- pattern: flask.request.headers[...]
|
|
- pattern: flask.request.data
|
|
- pattern: flask.request.full_path
|
|
- pattern: flask.request.url
|
|
- pattern: flask.request.json
|
|
- pattern: flask.request.get_json()
|
|
- pattern: flask.request.view_args.get(...)
|
|
- pattern: flask.request.view_args[...]
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route(...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- pattern: $ROUTEVAR
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(request, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: request.$PROPERTY.get(...)
|
|
- pattern: request.$PROPERTY[...]
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@rest_framework.decorators.api_view(...)
|
|
def $FUNC($REQ, ...):
|
|
...
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $VIEW(..., rest_framework.views.APIView, ...):
|
|
...
|
|
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
|
|
...):\n ... \n"
|
|
- pattern-inside: |
|
|
def $METHOD(self, $REQ, ...):
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (get|post|put|patch|delete|head)
|
|
- pattern-either:
|
|
- pattern: $REQ.POST.get(...)
|
|
- pattern: $REQ.POST[...]
|
|
- pattern: $REQ.FILES.get(...)
|
|
- pattern: $REQ.FILES[...]
|
|
- pattern: $REQ.DATA.get(...)
|
|
- pattern: $REQ.DATA[...]
|
|
- pattern: $REQ.QUERY_PARAMS.get(...)
|
|
- pattern: $REQ.QUERY_PARAMS[...]
|
|
- pattern: $REQ.data.get(...)
|
|
- pattern: $REQ.data[...]
|
|
- pattern: $REQ.query_params.get(...)
|
|
- pattern: $REQ.query_params[...]
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.stream
|
|
- pattern: $REQ.stream
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.StreamRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.DatagramRequestHandler, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: self.requestline
|
|
- pattern: self.path
|
|
- pattern: self.headers[...]
|
|
- pattern: self.headers.get(...)
|
|
- pattern: self.rfile
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config( ... )
|
|
def $VIEW($REQ):
|
|
...
|
|
- pattern: $REQ.$ANYTHING
|
|
- pattern-not: $REQ.dbsession
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: os.environ['$ANYTHING']
|
|
- pattern: os.environ.get('$FOO', ...)
|
|
- pattern: os.environb['$ANYTHING']
|
|
- pattern: os.environb.get('$FOO', ...)
|
|
- pattern: os.getenv('$ANYTHING', ...)
|
|
- pattern: os.getenvb('$ANYTHING', ...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: sys.argv[...]
|
|
- pattern: sys.orig_argv[...]
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = argparse.ArgumentParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$PARSER = optparse.OptionParser(...)
|
|
...
|
|
- pattern-inside: |
|
|
$ARGS = $PARSER.parse_args()
|
|
- pattern: <... $ARGS ...>
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.getopt(...)
|
|
...
|
|
- pattern-inside: |
|
|
$OPTS, $ARGS = getopt.gnu_getopt(...)
|
|
...
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
for $O, $A in $OPTS:
|
|
...
|
|
- pattern: $A
|
|
- pattern: $ARGS
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-not: os.$METHOD($MODE, "...", ...)
|
|
- pattern-inside: os.$METHOD($MODE, $CMD, ...)
|
|
- pattern: $CMD
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile)
|
|
- patterns:
|
|
- pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...)
|
|
- pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...)
|
|
- pattern: $CMD
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp)
|
|
- metavariable-regex:
|
|
metavariable: $BASH
|
|
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
|
|
- patterns:
|
|
- pattern-not: os.$METHOD($MODE, "...", "...", "...", ...)
|
|
- pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...)
|
|
- pattern: $CMD
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (spawnl|spawnle|spawnlp|spawnlpe)
|
|
- metavariable-regex:
|
|
metavariable: $BASH
|
|
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
|
|
message: Found user controlled content when spawning a process. This is dangerous
|
|
because it allows a malicious actor to execute commands.
|
|
metadata:
|
|
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.lang.security.dangerous-spawn-process.dangerous-spawn-process
|
|
shortlink: https://sg.run/r8Zn
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27269
|
|
rv_id: 1263524
|
|
rule_id: lBUJrn
|
|
version_id: o5TbDO5
|
|
url: https://semgrep.dev/playground/r/o5TbDO5/python.lang.security.dangerous-spawn-process.dangerous-spawn-process
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.form.get(...)
|
|
- pattern: flask.request.form[...]
|
|
- pattern: flask.request.args.get(...)
|
|
- pattern: flask.request.args[...]
|
|
- pattern: flask.request.values.get(...)
|
|
- pattern: flask.request.values[...]
|
|
- pattern: flask.request.cookies.get(...)
|
|
- pattern: flask.request.cookies[...]
|
|
- pattern: flask.request.stream
|
|
- pattern: flask.request.headers.get(...)
|
|
- pattern: flask.request.headers[...]
|
|
- pattern: flask.request.data
|
|
- pattern: flask.request.full_path
|
|
- pattern: flask.request.url
|
|
- pattern: flask.request.json
|
|
- pattern: flask.request.get_json()
|
|
- pattern: flask.request.view_args.get(...)
|
|
- pattern: flask.request.view_args[...]
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route(...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- focus-metavariable: $ROUTEVAR
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(request, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: request.$PROPERTY.get(...)
|
|
- pattern: request.$PROPERTY[...]
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@rest_framework.decorators.api_view(...)
|
|
def $FUNC($REQ, ...):
|
|
...
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $VIEW(..., rest_framework.views.APIView, ...):
|
|
...
|
|
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
|
|
...):\n ... \n"
|
|
- pattern-inside: |
|
|
def $METHOD(self, $REQ, ...):
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (get|post|put|patch|delete|head)
|
|
- pattern-either:
|
|
- pattern: $REQ.POST.get(...)
|
|
- pattern: $REQ.POST[...]
|
|
- pattern: $REQ.FILES.get(...)
|
|
- pattern: $REQ.FILES[...]
|
|
- pattern: $REQ.DATA.get(...)
|
|
- pattern: $REQ.DATA[...]
|
|
- pattern: $REQ.QUERY_PARAMS.get(...)
|
|
- pattern: $REQ.QUERY_PARAMS[...]
|
|
- pattern: $REQ.data.get(...)
|
|
- pattern: $REQ.data[...]
|
|
- pattern: $REQ.query_params.get(...)
|
|
- pattern: $REQ.query_params[...]
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.stream
|
|
- pattern: $REQ.stream
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.StreamRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.DatagramRequestHandler, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: self.requestline
|
|
- pattern: self.path
|
|
- pattern: self.headers[...]
|
|
- pattern: self.headers.get(...)
|
|
- pattern: self.rfile
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config( ... )
|
|
def $VIEW($REQ):
|
|
...
|
|
- pattern: $REQ.$ANYTHING
|
|
- pattern-not: $REQ.dbsession
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
_xxsubinterpreters.run_string($ID, $PAYLOAD, ...)
|
|
- pattern-not: |
|
|
_xxsubinterpreters.run_string($ID, "...", ...)
|
|
- focus-metavariable: $PAYLOAD
|
|
message: Found user controlled content in `run_string`. This is dangerous because
|
|
it allows a malicious actor to run arbitrary Python code.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://bugs.python.org/issue43472
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string
|
|
shortlink: https://sg.run/bPop
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27270
|
|
rv_id: 1263525
|
|
rule_id: PeURWr
|
|
version_id: zyTb2OX
|
|
url: https://semgrep.dev/playground/r/zyTb2OX/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
- id: python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.form.get(...)
|
|
- pattern: flask.request.form[...]
|
|
- pattern: flask.request.args.get(...)
|
|
- pattern: flask.request.args[...]
|
|
- pattern: flask.request.values.get(...)
|
|
- pattern: flask.request.values[...]
|
|
- pattern: flask.request.cookies.get(...)
|
|
- pattern: flask.request.cookies[...]
|
|
- pattern: flask.request.stream
|
|
- pattern: flask.request.headers.get(...)
|
|
- pattern: flask.request.headers[...]
|
|
- pattern: flask.request.data
|
|
- pattern: flask.request.full_path
|
|
- pattern: flask.request.url
|
|
- pattern: flask.request.json
|
|
- pattern: flask.request.get_json()
|
|
- pattern: flask.request.view_args.get(...)
|
|
- pattern: flask.request.view_args[...]
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route(...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- focus-metavariable: $ROUTEVAR
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(request, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: request.$PROPERTY.get(...)
|
|
- pattern: request.$PROPERTY[...]
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@rest_framework.decorators.api_view(...)
|
|
def $FUNC($REQ, ...):
|
|
...
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $VIEW(..., rest_framework.views.APIView, ...):
|
|
...
|
|
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
|
|
...):\n ... \n"
|
|
- pattern-inside: |
|
|
def $METHOD(self, $REQ, ...):
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (get|post|put|patch|delete|head)
|
|
- pattern-either:
|
|
- pattern: $REQ.POST.get(...)
|
|
- pattern: $REQ.POST[...]
|
|
- pattern: $REQ.FILES.get(...)
|
|
- pattern: $REQ.FILES[...]
|
|
- pattern: $REQ.DATA.get(...)
|
|
- pattern: $REQ.DATA[...]
|
|
- pattern: $REQ.QUERY_PARAMS.get(...)
|
|
- pattern: $REQ.QUERY_PARAMS[...]
|
|
- pattern: $REQ.data.get(...)
|
|
- pattern: $REQ.data[...]
|
|
- pattern: $REQ.query_params.get(...)
|
|
- pattern: $REQ.query_params[...]
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.stream
|
|
- pattern: $REQ.stream
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.StreamRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.DatagramRequestHandler, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: self.requestline
|
|
- pattern: self.path
|
|
- pattern: self.headers[...]
|
|
- pattern: self.headers.get(...)
|
|
- pattern: self.rfile
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config( ... )
|
|
def $VIEW($REQ):
|
|
...
|
|
- pattern: $REQ.$ANYTHING
|
|
- pattern-not: $REQ.dbsession
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-not: subprocess.$FUNC("...", ...)
|
|
- pattern-not: subprocess.$FUNC(["...",...], ...)
|
|
- pattern-not: subprocess.$FUNC(("...",...), ...)
|
|
- pattern-not: subprocess.CalledProcessError(...)
|
|
- pattern-not: subprocess.SubprocessError(...)
|
|
- pattern: subprocess.$FUNC($CMD, ...)
|
|
- patterns:
|
|
- pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...)
|
|
- pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD)
|
|
- patterns:
|
|
- pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...)
|
|
- pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...)
|
|
- pattern-either:
|
|
- pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD],
|
|
...)
|
|
- pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD),
|
|
...)
|
|
- patterns:
|
|
- pattern-not: subprocess.$FUNC("=~/(python)/","...",...)
|
|
- pattern: subprocess.$FUNC("=~/(python)/", $CMD)
|
|
- patterns:
|
|
- pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...)
|
|
- pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...)
|
|
- pattern-either:
|
|
- pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...)
|
|
- pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...)
|
|
- focus-metavariable: $CMD
|
|
message: Detected subprocess function '$FUNC' with user controlled data. A malicious
|
|
actor could leverage this to perform command injection. You may consider using
|
|
'shlex.escape()'.
|
|
metadata:
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.3.8 OS Command Injection
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
|
|
version: '4'
|
|
references:
|
|
- https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess
|
|
- https://docs.python.org/3/library/subprocess.html
|
|
- https://docs.python.org/3/library/shlex.html
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use
|
|
shortlink: https://sg.run/NWxp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27271
|
|
rv_id: 1263526
|
|
rule_id: JDUz3R
|
|
version_id: pZT038J
|
|
url: https://semgrep.dev/playground/r/pZT038J/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.dangerous-system-call.dangerous-system-call
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.form.get(...)
|
|
- pattern: flask.request.form[...]
|
|
- pattern: flask.request.args.get(...)
|
|
- pattern: flask.request.args[...]
|
|
- pattern: flask.request.values.get(...)
|
|
- pattern: flask.request.values[...]
|
|
- pattern: flask.request.cookies.get(...)
|
|
- pattern: flask.request.cookies[...]
|
|
- pattern: flask.request.stream
|
|
- pattern: flask.request.headers.get(...)
|
|
- pattern: flask.request.headers[...]
|
|
- pattern: flask.request.data
|
|
- pattern: flask.request.full_path
|
|
- pattern: flask.request.url
|
|
- pattern: flask.request.json
|
|
- pattern: flask.request.get_json()
|
|
- pattern: flask.request.view_args.get(...)
|
|
- pattern: flask.request.view_args[...]
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route(...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- focus-metavariable: $ROUTEVAR
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(request, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: request.$PROPERTY.get(...)
|
|
- pattern: request.$PROPERTY[...]
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@rest_framework.decorators.api_view(...)
|
|
def $FUNC($REQ, ...):
|
|
...
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $VIEW(..., rest_framework.views.APIView, ...):
|
|
...
|
|
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
|
|
...):\n ... \n"
|
|
- pattern-inside: |
|
|
def $METHOD(self, $REQ, ...):
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (get|post|put|patch|delete|head)
|
|
- pattern-either:
|
|
- pattern: $REQ.POST.get(...)
|
|
- pattern: $REQ.POST[...]
|
|
- pattern: $REQ.FILES.get(...)
|
|
- pattern: $REQ.FILES[...]
|
|
- pattern: $REQ.DATA.get(...)
|
|
- pattern: $REQ.DATA[...]
|
|
- pattern: $REQ.QUERY_PARAMS.get(...)
|
|
- pattern: $REQ.QUERY_PARAMS[...]
|
|
- pattern: $REQ.data.get(...)
|
|
- pattern: $REQ.data[...]
|
|
- pattern: $REQ.query_params.get(...)
|
|
- pattern: $REQ.query_params[...]
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.stream
|
|
- pattern: $REQ.stream
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.StreamRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.DatagramRequestHandler, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: self.requestline
|
|
- pattern: self.path
|
|
- pattern: self.headers[...]
|
|
- pattern: self.headers.get(...)
|
|
- pattern: self.rfile
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config( ... )
|
|
def $VIEW($REQ):
|
|
...
|
|
- pattern: $REQ.$ANYTHING
|
|
- pattern-not: $REQ.dbsession
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-not: os.$W("...", ...)
|
|
- pattern-either:
|
|
- pattern: os.system(...)
|
|
- pattern: getattr(os, "system")(...)
|
|
- pattern: __import__("os").system(...)
|
|
- pattern: getattr(__import__("os"), "system")(...)
|
|
- pattern: |
|
|
$X = __import__("os")
|
|
...
|
|
$X.system(...)
|
|
- pattern: |
|
|
$X = __import__("os")
|
|
...
|
|
getattr($X, "system")(...)
|
|
- pattern: |
|
|
$X = getattr(os, "system")
|
|
...
|
|
$X(...)
|
|
- pattern: |
|
|
$X = __import__("os")
|
|
...
|
|
$Y = getattr($X, "system")
|
|
...
|
|
$Y(...)
|
|
- pattern: os.popen(...)
|
|
- pattern: os.popen2(...)
|
|
- pattern: os.popen3(...)
|
|
- pattern: os.popen4(...)
|
|
message: Found user-controlled data used in a system call. This could allow a malicious
|
|
actor to execute commands. Use the 'subprocess' module instead, which is easier
|
|
to use without accidentally exposing a command injection vulnerability.
|
|
metadata:
|
|
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
asvs:
|
|
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
|
|
control_id: 5.2.4 Dyanmic Code Execution Features
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.lang.security.dangerous-system-call.dangerous-system-call
|
|
shortlink: https://sg.run/k0W7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27272
|
|
rv_id: 1263527
|
|
rule_id: 5rUoP1
|
|
version_id: 2KTv2Zn
|
|
url: https://semgrep.dev/playground/r/2KTv2Zn/python.lang.security.dangerous-system-call.dangerous-system-call
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
- id: python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.form.get(...)
|
|
- pattern: flask.request.form[...]
|
|
- pattern: flask.request.args.get(...)
|
|
- pattern: flask.request.args[...]
|
|
- pattern: flask.request.values.get(...)
|
|
- pattern: flask.request.values[...]
|
|
- pattern: flask.request.cookies.get(...)
|
|
- pattern: flask.request.cookies[...]
|
|
- pattern: flask.request.stream
|
|
- pattern: flask.request.headers.get(...)
|
|
- pattern: flask.request.headers[...]
|
|
- pattern: flask.request.data
|
|
- pattern: flask.request.full_path
|
|
- pattern: flask.request.url
|
|
- pattern: flask.request.json
|
|
- pattern: flask.request.get_json()
|
|
- pattern: flask.request.view_args.get(...)
|
|
- pattern: flask.request.view_args[...]
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route(...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- focus-metavariable: $ROUTEVAR
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(request, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: request.$PROPERTY.get(...)
|
|
- pattern: request.$PROPERTY[...]
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
@rest_framework.decorators.api_view(...)
|
|
def $FUNC($REQ, ...):
|
|
...
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $VIEW(..., rest_framework.views.APIView, ...):
|
|
...
|
|
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
|
|
...):\n ... \n"
|
|
- pattern-inside: |
|
|
def $METHOD(self, $REQ, ...):
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $METHOD
|
|
regex: (get|post|put|patch|delete|head)
|
|
- pattern-either:
|
|
- pattern: $REQ.POST.get(...)
|
|
- pattern: $REQ.POST[...]
|
|
- pattern: $REQ.FILES.get(...)
|
|
- pattern: $REQ.FILES[...]
|
|
- pattern: $REQ.DATA.get(...)
|
|
- pattern: $REQ.DATA[...]
|
|
- pattern: $REQ.QUERY_PARAMS.get(...)
|
|
- pattern: $REQ.QUERY_PARAMS[...]
|
|
- pattern: $REQ.data.get(...)
|
|
- pattern: $REQ.data[...]
|
|
- pattern: $REQ.query_params.get(...)
|
|
- pattern: $REQ.query_params[...]
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.content_type
|
|
- pattern: $REQ.stream
|
|
- pattern: $REQ.stream
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.StreamRequestHandler, ...):
|
|
...
|
|
- pattern-inside: |
|
|
class $SERVER(..., http.server.DatagramRequestHandler, ...):
|
|
...
|
|
- pattern-either:
|
|
- pattern: self.requestline
|
|
- pattern: self.path
|
|
- pattern: self.headers[...]
|
|
- pattern: self.headers.get(...)
|
|
- pattern: self.rfile
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@pyramid.view.view_config( ... )
|
|
def $VIEW($REQ):
|
|
...
|
|
- pattern: $REQ.$ANYTHING
|
|
- pattern-not: $REQ.dbsession
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
_testcapi.run_in_subinterp($PAYLOAD, ...)
|
|
- pattern: |
|
|
test.support.run_in_subinterp($PAYLOAD, ...)
|
|
- focus-metavariable: $PAYLOAD
|
|
- pattern-not: |
|
|
_testcapi.run_in_subinterp("...", ...)
|
|
- pattern-not: |
|
|
test.support.run_in_subinterp("...", ...)
|
|
message: Found user controlled content in `run_in_subinterp`. This is dangerous
|
|
because it allows a malicious actor to run arbitrary Python code.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
|
|
(''Eval Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
category: security
|
|
technology:
|
|
- python
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp
|
|
shortlink: https://sg.run/wLpY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27273
|
|
rv_id: 1263528
|
|
rule_id: GdUkxR
|
|
version_id: X0Tzy1e
|
|
url: https://semgrep.dev/playground/r/X0Tzy1e/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
- id: csharp.dotnet.security.audit.xpath-injection.xpath-injection
|
|
message: XPath queries are constructed dynamically on user-controlled input. This
|
|
vulnerability in code could lead to an XPath Injection exploitation.
|
|
severity: ERROR
|
|
metadata:
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe:
|
|
- 'CWE-643: Improper Neutralization of Data within XPath Expressions (''XPath
|
|
Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection/
|
|
- https://cwe.mitre.org/data/definitions/643.html
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XPath Injection
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.audit.xpath-injection.xpath-injection
|
|
shortlink: https://sg.run/4KP7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27400
|
|
rv_id: 1262618
|
|
rule_id: x8Uj2k
|
|
version_id: 2KTv2Pq
|
|
url: https://semgrep.dev/playground/r/2KTv2Pq/csharp.dotnet.security.audit.xpath-injection.xpath-injection
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- pattern: $T $M($INPUT,...) {...}
|
|
- pattern: |
|
|
$T $M(...) {
|
|
...
|
|
string $INPUT;
|
|
}
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- pattern: XPathExpression $EXPR = $NAV.Compile("..." + $INPUT + "...");
|
|
- pattern: var $EXPR = $NAV.Compile("..." + $INPUT + "...");
|
|
- pattern: XPathNodeIterator $NODE = $NAV.Select("..." + $INPUT + "...");
|
|
- pattern: var $NODE = $NAV.Select("..." + $INPUT + "...");
|
|
- pattern: Object $OBJ = $NAV.Evaluate("..." + $INPUT + "...");
|
|
- pattern: var $OBJ = $NAV.Evaluate("..." + $INPUT + "...");
|
|
- id: csharp.dotnet.security.audit.ldap-injection.ldap-injection
|
|
message: LDAP queries are constructed dynamically on user-controlled input. This
|
|
vulnerability in code could lead to an arbitrary LDAP query execution.
|
|
severity: ERROR
|
|
metadata:
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe:
|
|
- 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP
|
|
Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection/
|
|
- https://cwe.mitre.org/data/definitions/90
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/LDAP_Injection_Prevention_Cheat_Sheet.html#safe-c-sharp-net-tba-example
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- LDAP Injection
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.audit.ldap-injection.ldap-injection
|
|
shortlink: https://sg.run/GJ9z
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 27692
|
|
rv_id: 1262612
|
|
rule_id: 2ZUv3R
|
|
version_id: l4TJR8G
|
|
url: https://semgrep.dev/playground/r/l4TJR8G/csharp.dotnet.security.audit.ldap-injection.ldap-injection
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
mode: taint
|
|
options:
|
|
taint_unify_mvars: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- focus-metavariable: $INPUT
|
|
- pattern-inside: $T $M(...,$INPUT,...) {...}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $S.Filter = ... + $INPUT + ...
|
|
- pattern: $S.Filter = String.Format(...,$INPUT)
|
|
- pattern: $S.Filter = String.Concat(...,$INPUT)
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: Regex.Replace($INPUT, ...)
|
|
- pattern: $ENCODER.LdapFilterEncode($INPUT)
|
|
- pattern: $ENCODER.LdapDistinguishedNameEncode($INPUT)
|
|
- id: csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: $LIFETIME = $FALSE
|
|
- pattern-inside: new TokenValidationParameters {...}
|
|
- patterns:
|
|
- pattern: |
|
|
(TokenValidationParameters $OPTS). ... .$LIFETIME = $FALSE
|
|
- metavariable-regex:
|
|
metavariable: $LIFETIME
|
|
regex: (RequireExpirationTime|ValidateLifetime)
|
|
- metavariable-regex:
|
|
metavariable: $FALSE
|
|
regex: (false)
|
|
- focus-metavariable: $FALSE
|
|
fix: |
|
|
true
|
|
message: The TokenValidationParameters.$LIFETIME is set to $FALSE, this means the
|
|
JWT tokens lifetime is not validated. This can lead to an JWT token being used
|
|
after it has expired, which has security implications. It is recommended to validate
|
|
the JWT lifetime to ensure only valid tokens are used.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- csharp
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe:
|
|
- 'CWE-613: Insufficient Session Expiration'
|
|
references:
|
|
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/
|
|
- https://cwe.mitre.org/data/definitions/613.html
|
|
- https://docs.microsoft.com/en-us/dotnet/api/microsoft.identitymodel.tokens.tokenvalidationparameters?view=azure-dotnet
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation
|
|
shortlink: https://sg.run/KA0d
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 28955
|
|
rv_id: 1262628
|
|
rule_id: bwU5kK
|
|
version_id: w8TRolJ
|
|
url: https://semgrep.dev/playground/r/w8TRolJ/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
severity: WARNING
|
|
- id: java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml
|
|
patterns:
|
|
- pattern-inside: |
|
|
management:
|
|
...
|
|
endpoints:
|
|
...
|
|
web:
|
|
...
|
|
exposure:
|
|
...
|
|
- pattern: |
|
|
include: "*"
|
|
message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints
|
|
such as /actuator/env, /actuator/logfile, /actuator/heapdump and others. Unless
|
|
you have Spring Security enabled or another means to protect these endpoints,
|
|
this functionality is available without authentication, causing a severe security
|
|
risk.
|
|
severity: WARNING
|
|
languages:
|
|
- yaml
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints
|
|
- https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785
|
|
- https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators
|
|
category: security
|
|
technology:
|
|
- spring
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml
|
|
shortlink: https://sg.run/1Bzw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 29422
|
|
rv_id: 1263076
|
|
rule_id: eqUerQ
|
|
version_id: w8TRo5n
|
|
url: https://semgrep.dev/playground/r/w8TRo5n/java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml
|
|
origin: community
|
|
- id: python.django.security.injection.command.subprocess-injection.subprocess-injection
|
|
languages:
|
|
- python
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(..., $REQUEST, ...):
|
|
...
|
|
- focus-metavariable: $REQUEST
|
|
- metavariable-pattern:
|
|
metavariable: $REQUEST
|
|
patterns:
|
|
- pattern: request
|
|
- pattern-not-inside: request.build_absolute_uri
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(...)
|
|
- pattern-not: subprocess.$FUNC("...", ...)
|
|
- pattern-not: subprocess.$FUNC(["...", ...], ...)
|
|
- pattern-not-inside: |
|
|
$CMD = ["...", ...]
|
|
...
|
|
subprocess.$FUNC($CMD, ...)
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...)
|
|
- metavariable-regex:
|
|
metavariable: $SHELL
|
|
regex: ^(sh|bash|ksh|csh|tcsh|zsh)$
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...)
|
|
- metavariable-regex:
|
|
metavariable: $INTERPRETER
|
|
regex: ^(python|python\d)$
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: $DICT[$KEY]
|
|
- focus-metavariable: $KEY
|
|
severity: ERROR
|
|
message: Detected user input entering a `subprocess` call unsafely. This could result
|
|
in a command injection vulnerability. An attacker could use this vulnerability
|
|
to execute arbitrary commands on the host, which allows them to download malware,
|
|
scan sensitive data, or run any command they wish on the server. Do not let users
|
|
choose the command to run. In general, prefer to use Python API versions of system
|
|
commands. If you must use subprocess, use a dictionary to allowlist a set of commands.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- flask
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.django.security.injection.command.subprocess-injection.subprocess-injection
|
|
shortlink: https://sg.run/49BE
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 31144
|
|
rv_id: 1263388
|
|
rule_id: EwUepx
|
|
version_id: 7ZTE3qK
|
|
url: https://semgrep.dev/playground/r/7ZTE3qK/python.django.security.injection.command.subprocess-injection.subprocess-injection
|
|
origin: community
|
|
- id: python.django.security.injection.csv-writer-injection.csv-writer-injection
|
|
languages:
|
|
- python
|
|
message: Detected user input into a generated CSV file using the built-in `csv`
|
|
module. If user data is used to generate the data in this file, it is possible
|
|
that an attacker could inject a formula when the CSV is imported into a spreadsheet
|
|
application that runs an attacker script, which could steal data from the importing
|
|
user or, at worst, install malware on the user's computer. `defusedcsv` is a drop-in
|
|
replacement with the same API that will attempt to mitigate formula injection
|
|
attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs.
|
|
metadata:
|
|
category: security
|
|
confidence: MEDIUM
|
|
cwe:
|
|
- 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://github.com/raphaelm/defusedcsv
|
|
- https://owasp.org/www-community/attacks/CSV_Injection
|
|
- https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities
|
|
technology:
|
|
- django
|
|
- python
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/python.django.security.injection.csv-writer-injection.csv-writer-injection
|
|
shortlink: https://sg.run/Pw9q
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 31145
|
|
rv_id: 1263389
|
|
rule_id: 7KUK1y
|
|
version_id: LjTkgD9
|
|
url: https://semgrep.dev/playground/r/LjTkgD9/python.django.security.injection.csv-writer-injection.csv-writer-injection
|
|
origin: community
|
|
mode: taint
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$WRITER = csv.writer(...)
|
|
|
|
...
|
|
|
|
$WRITER.$WRITE(...)
|
|
- pattern: $WRITER.$WRITE(...)
|
|
- metavariable-regex:
|
|
metavariable: $WRITE
|
|
regex: ^(writerow|writerows|writeheader)$
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
def $FUNC(..., $REQUEST, ...):
|
|
...
|
|
- focus-metavariable: $REQUEST
|
|
- metavariable-pattern:
|
|
metavariable: $REQUEST
|
|
patterns:
|
|
- pattern: request
|
|
- pattern-not-inside: request.build_absolute_uri
|
|
severity: ERROR
|
|
- id: python.flask.security.injection.csv-writer-injection.csv-writer-injection
|
|
languages:
|
|
- python
|
|
message: Detected user input into a generated CSV file using the built-in `csv`
|
|
module. If user data is used to generate the data in this file, it is possible
|
|
that an attacker could inject a formula when the CSV is imported into a spreadsheet
|
|
application that runs an attacker script, which could steal data from the importing
|
|
user or, at worst, install malware on the user's computer. `defusedcsv` is a drop-in
|
|
replacement with the same API that will attempt to mitigate formula injection
|
|
attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs.
|
|
metadata:
|
|
category: security
|
|
confidence: MEDIUM
|
|
cwe:
|
|
- 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://github.com/raphaelm/defusedcsv
|
|
- https://owasp.org/www-community/attacks/CSV_Injection
|
|
- https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities
|
|
technology:
|
|
- python
|
|
- flask
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/python.flask.security.injection.csv-writer-injection.csv-writer-injection
|
|
shortlink: https://sg.run/JzqQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 31146
|
|
rv_id: 1263428
|
|
rule_id: L1UR2K
|
|
version_id: jQTn50Y
|
|
url: https://semgrep.dev/playground/r/jQTn50Y/python.flask.security.injection.csv-writer-injection.csv-writer-injection
|
|
origin: community
|
|
mode: taint
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$WRITER = csv.writer(...)
|
|
|
|
...
|
|
|
|
$WRITER.$WRITE(...)
|
|
- pattern: $WRITER.$WRITE(...)
|
|
- metavariable-regex:
|
|
metavariable: $WRITE
|
|
regex: ^(writerow|writerows|writeheader)$
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.form.get(...)
|
|
- pattern: flask.request.form[...]
|
|
- pattern: flask.request.args.get(...)
|
|
- pattern: flask.request.args[...]
|
|
- pattern: flask.request.values.get(...)
|
|
- pattern: flask.request.values[...]
|
|
- pattern: flask.request.cookies.get(...)
|
|
- pattern: flask.request.cookies[...]
|
|
- pattern: flask.request.stream
|
|
- pattern: flask.request.headers.get(...)
|
|
- pattern: flask.request.headers[...]
|
|
- pattern: flask.request.data
|
|
- pattern: flask.request.full_path
|
|
- pattern: flask.request.url
|
|
- pattern: flask.request.json
|
|
- pattern: flask.request.get_json()
|
|
- pattern: flask.request.view_args.get(...)
|
|
- pattern: flask.request.view_args[...]
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- focus-metavariable: $ROUTEVAR
|
|
severity: ERROR
|
|
- id: python.flask.security.injection.subprocess-injection.subprocess-injection
|
|
languages:
|
|
- python
|
|
mode: taint
|
|
options:
|
|
symbolic_propagation: true
|
|
pattern-sources:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: flask.request.form.get(...)
|
|
- pattern: flask.request.form[...]
|
|
- pattern: flask.request.args.get(...)
|
|
- pattern: flask.request.args[...]
|
|
- pattern: flask.request.values.get(...)
|
|
- pattern: flask.request.values[...]
|
|
- pattern: flask.request.cookies.get(...)
|
|
- pattern: flask.request.cookies[...]
|
|
- pattern: flask.request.stream
|
|
- pattern: flask.request.headers.get(...)
|
|
- pattern: flask.request.headers[...]
|
|
- pattern: flask.request.data
|
|
- pattern: flask.request.full_path
|
|
- pattern: flask.request.url
|
|
- pattern: flask.request.json
|
|
- pattern: flask.request.get_json()
|
|
- pattern: flask.request.view_args.get(...)
|
|
- pattern: flask.request.view_args[...]
|
|
- patterns:
|
|
- pattern-inside: |
|
|
@$APP.route($ROUTE, ...)
|
|
def $FUNC(..., $ROUTEVAR, ...):
|
|
...
|
|
- focus-metavariable: $ROUTEVAR
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(...)
|
|
- pattern-not: subprocess.$FUNC("...", ...)
|
|
- pattern-not: subprocess.$FUNC(["...", ...], ...)
|
|
- pattern-not-inside: |
|
|
$CMD = ["...", ...]
|
|
...
|
|
subprocess.$FUNC($CMD, ...)
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...)
|
|
- metavariable-regex:
|
|
metavariable: $SHELL
|
|
regex: ^(sh|bash|ksh|csh|tcsh|zsh)$
|
|
- patterns:
|
|
- pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...)
|
|
- metavariable-regex:
|
|
metavariable: $INTERPRETER
|
|
regex: ^(python|python\d)$
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern: $DICT[$KEY]
|
|
- focus-metavariable: $KEY
|
|
severity: ERROR
|
|
message: Detected user input entering a `subprocess` call unsafely. This could result
|
|
in a command injection vulnerability. An attacker could use this vulnerability
|
|
to execute arbitrary commands on the host, which allows them to download malware,
|
|
scan sensitive data, or run any command they wish on the server. Do not let users
|
|
choose the command to run. In general, prefer to use Python API versions of system
|
|
commands. If you must use subprocess, use a dictionary to allowlist a set of commands.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- flask
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
references:
|
|
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
|
|
confidence: HIGH
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/python.flask.security.injection.subprocess-injection.subprocess-injection
|
|
shortlink: https://sg.run/5gW3
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 31147
|
|
rv_id: 1263433
|
|
rule_id: 8GU3qp
|
|
version_id: bZT53gQ
|
|
url: https://semgrep.dev/playground/r/bZT53gQ/python.flask.security.injection.subprocess-injection.subprocess-injection
|
|
origin: community
|
|
- id: yaml.github-actions.security.github-script-injection.github-script-injection
|
|
languages:
|
|
- yaml
|
|
message: 'Using variable interpolation `${{...}}` with `github` context data in
|
|
a `actions/github-script`''s `script:` step could allow an attacker to inject
|
|
their own code into the runner. This would allow them to steal secrets and code.
|
|
`github` context data can have arbitrary user input and should be treated as untrusted.
|
|
Instead, use an intermediate environment variable with `env:` to store the data
|
|
and use the environment variable in the `run:` script. Be sure to use double-quotes
|
|
the environment variable, like this: "$ENVVAR".'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections
|
|
- https://securitylab.github.com/research/github-actions-untrusted-input/
|
|
- https://github.com/actions/github-script
|
|
technology:
|
|
- github-actions
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.github-script-injection.github-script-injection
|
|
shortlink: https://sg.run/g1G0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 31441
|
|
rv_id: 1423394
|
|
rule_id: OrUQvK
|
|
version_id: 5PT7Zyw
|
|
url: https://semgrep.dev/playground/r/5PT7Zyw/yaml.github-actions.security.github-script-injection.github-script-injection
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: 'steps: [...]'
|
|
- pattern-inside: |
|
|
uses: $ACTION
|
|
...
|
|
- pattern-inside: |
|
|
with:
|
|
...
|
|
script: ...
|
|
...
|
|
- pattern: 'script: $SHELL'
|
|
- metavariable-regex:
|
|
metavariable: $ACTION
|
|
regex: actions/github-script@.*
|
|
- metavariable-pattern:
|
|
language: generic
|
|
metavariable: $SHELL
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: ${{ ... github.event.issue.title ... }}
|
|
- pattern: ${{ ... github.event.issue.body ... }}
|
|
- pattern: ${{ ... github.event.pull_request.title ... }}
|
|
- pattern: ${{ ... github.event.pull_request.body ... }}
|
|
- pattern: ${{ ... github.event.comment.body ... }}
|
|
- pattern: ${{ ... github.event.review.body ... }}
|
|
- pattern: ${{ ... github.event.review_comment.body ... }}
|
|
- pattern: ${{ ... github.event.pages ... .page_name ... }}
|
|
- pattern: ${{ ... github.event.head_commit.message ... }}
|
|
- pattern: ${{ ... github.event.head_commit.author.email ... }}
|
|
- pattern: ${{ ... github.event.head_commit.author.name ... }}
|
|
- pattern: ${{ ... github.event.commits ... .author.email ... }}
|
|
- pattern: ${{ ... github.event.commits ... .author.name ... }}
|
|
- pattern: ${{ ... github.event.commits ... .message ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.ref ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.label ... }}
|
|
- pattern: ${{ ... github.event.pull_request.head.repo.default_branch ...
|
|
}}
|
|
- pattern: ${{ ... github.ref ... }}
|
|
- pattern: ${{ ... github.base_ref ... }}
|
|
- pattern: ${{ ... github.head_ref ... }}
|
|
- pattern: ${{ ... github.ref_name ... }}
|
|
- pattern: ${{ ... github.workflow ... }}
|
|
- pattern: ${{ ... github.event.inputs ... }}
|
|
- pattern: ${{ ... github.event.discussion.title ... }}
|
|
- pattern: ${{ ... github.event.discussion.body ... }}
|
|
- pattern: ${{ ... github.event.workflow_run.head_branch ... }}
|
|
- pattern: ${{ ... github.event.workflow_run.head_commit.message ... }}
|
|
- pattern: ${{ ... github.event.milestone.title ... }}
|
|
- pattern: ${{ ... github.event.milestone.description ... }}
|
|
- pattern: ${{ ... github.event.project_card.note ... }}
|
|
- pattern: ${{ ... github.event.project.name ... }}
|
|
- pattern: ${{ ... github.event.project_column.name ... }}
|
|
- pattern: ${{ ... github.event.release.name ... }}
|
|
- pattern: ${{ ... github.event.release.body ... }}
|
|
- pattern: ${{ ... github.event.deployment.ref ... }}
|
|
- pattern: ${{ ... inputs ... }}
|
|
- pattern-not: ${{ ... github.event.issue.title && ... }}
|
|
- pattern-not: ${{ ... github.event.issue.body && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.title && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.body && ... }}
|
|
- pattern-not: ${{ ... github.event.comment.body && ... }}
|
|
- pattern-not: ${{ ... github.event.review.body && ... }}
|
|
- pattern-not: ${{ ... github.event.review_comment.body && ... }}
|
|
- pattern-not: ${{ ... github.event.pages ... .page_name && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.message && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.author.email && ... }}
|
|
- pattern-not: ${{ ... github.event.head_commit.author.name && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .author.email && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .author.name && ... }}
|
|
- pattern-not: ${{ ... github.event.commits ... .message && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.ref && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.label && ... }}
|
|
- pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch &&
|
|
... }}
|
|
- pattern-not: ${{ ... github.ref && ... }}
|
|
- pattern-not: ${{ ... github.base_ref && ... }}
|
|
- pattern-not: ${{ ... github.head_ref && ... }}
|
|
- pattern-not: ${{ ... github.ref_name && ... }}
|
|
- pattern-not: ${{ ... github.workflow && ... }}
|
|
- pattern-not: ${{ ... github.event.inputs && ... }}
|
|
- pattern-not: ${{ ... github.event.discussion.title && ... }}
|
|
- pattern-not: ${{ ... github.event.discussion.body && ... }}
|
|
- pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }}
|
|
- pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ...
|
|
}}
|
|
- pattern-not: ${{ ... github.event.milestone.title && ... }}
|
|
- pattern-not: ${{ ... github.event.milestone.description && ... }}
|
|
- pattern-not: ${{ ... github.event.project_card.note && ... }}
|
|
- pattern-not: ${{ ... github.event.project.name && ... }}
|
|
- pattern-not: ${{ ... github.event.project_column.name && ... }}
|
|
- pattern-not: ${{ ... github.event.release.name && ... }}
|
|
- pattern-not: ${{ ... github.event.release.body && ... }}
|
|
- pattern-not: ${{ ... github.event.deployment.ref && ... }}
|
|
severity: ERROR
|
|
- id: php.lang.security.injection.echoed-request.echoed-request
|
|
mode: taint
|
|
message: '`Echo`ing user input risks cross-site scripting vulnerability. You should
|
|
use `htmlentities()` when showing data to users.'
|
|
languages:
|
|
- php
|
|
severity: ERROR
|
|
pattern-sources:
|
|
- pattern: $_REQUEST
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
pattern-sinks:
|
|
- pattern: echo $...VARS;
|
|
pattern-sanitizers:
|
|
- pattern: htmlentities(...)
|
|
- pattern: htmlspecialchars(...)
|
|
- pattern: strip_tags(...)
|
|
- pattern: isset(...)
|
|
- pattern: empty(...)
|
|
- pattern: esc_html(...)
|
|
- pattern: esc_attr(...)
|
|
- pattern: wp_kses(...)
|
|
- pattern: e(...)
|
|
- pattern: twig_escape_filter(...)
|
|
- pattern: xss_clean(...)
|
|
- pattern: html_escape(...)
|
|
- pattern: Html::escape(...)
|
|
- pattern: Xss::filter(...)
|
|
- pattern: escapeHtml(...)
|
|
- pattern: escapeHtml(...)
|
|
- pattern: escapeHtmlAttr(...)
|
|
fix: echo htmlentities($...VARS);
|
|
metadata:
|
|
technology:
|
|
- php
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
references:
|
|
- https://www.php.net/manual/en/function.htmlentities.php
|
|
- https://www.php.net/manual/en/reserved.variables.request.php
|
|
- https://www.php.net/manual/en/reserved.variables.post.php
|
|
- https://www.php.net/manual/en/reserved.variables.get.php
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/php.lang.security.injection.echoed-request.echoed-request
|
|
shortlink: https://sg.run/Bqqb
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 31707
|
|
rv_id: 1263283
|
|
rule_id: BYUyyg
|
|
version_id: d6TyxE9
|
|
url: https://semgrep.dev/playground/r/d6TyxE9/php.lang.security.injection.echoed-request.echoed-request
|
|
origin: community
|
|
- id: python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication
|
|
message: 'An encryption mode of operation is being used without proper message authentication.
|
|
This can potentially result in the encrypted content to be decrypted by an attacker.
|
|
Consider instead use an AEAD mode of operation like GCM. '
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- cryptography
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication
|
|
shortlink: https://sg.run/N9JL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 31871
|
|
rv_id: 1263357
|
|
rule_id: lBUpNZ
|
|
version_id: BjTkZj5
|
|
url: https://semgrep.dev/playground/r/BjTkZj5/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
Cipher(..., $HAZMAT_MODE(...),...)
|
|
- pattern-not-inside: |
|
|
Cipher(..., $HAZMAT_MODE(...),...)
|
|
...
|
|
HMAC(...)
|
|
- pattern-not-inside: |
|
|
Cipher(..., $HAZMAT_MODE(...),...)
|
|
...
|
|
hmac.HMAC(...)
|
|
- metavariable-pattern:
|
|
metavariable: $HAZMAT_MODE
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: modes.CTR
|
|
- pattern: modes.CBC
|
|
- pattern: modes.CFB
|
|
- pattern: modes.OFB
|
|
- id: python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication
|
|
message: 'An encryption mode of operation is being used without proper message authentication.
|
|
This can potentially result in the encrypted content to be decrypted by an attacker.
|
|
Consider instead use an AEAD mode of operation like GCM. '
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- cryptography
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication
|
|
shortlink: https://sg.run/k1K1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 31872
|
|
rv_id: 1263556
|
|
rule_id: YGUw8w
|
|
version_id: GxTkeyz
|
|
url: https://semgrep.dev/playground/r/GxTkeyz/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
AES.new(..., $PYCRYPTODOME_MODE)
|
|
- pattern-not-inside: |
|
|
AES.new(..., $PYCRYPTODOME_MODE)
|
|
...
|
|
HMAC.new
|
|
- metavariable-pattern:
|
|
metavariable: $PYCRYPTODOME_MODE
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: AES.MODE_CBC
|
|
- pattern: AES.MODE_CTR
|
|
- pattern: AES.MODE_CFB
|
|
- pattern: AES.MODE_OFB
|
|
- id: java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml
|
|
patterns:
|
|
- pattern-inside: |
|
|
management:
|
|
...
|
|
endpoints:
|
|
...
|
|
web:
|
|
...
|
|
exposure:
|
|
...
|
|
include:
|
|
...
|
|
- pattern: |
|
|
include: [..., $ACTUATOR, ...]
|
|
- metavariable-comparison:
|
|
metavariable: $ACTUATOR
|
|
comparison: not str($ACTUATOR) in ["health","*"]
|
|
message: Spring Boot Actuator "$ACTUATOR" is enabled. Depending on the actuator,
|
|
this can pose a significant security risk. Please double-check if the actuator
|
|
is needed and properly secured.
|
|
severity: WARNING
|
|
languages:
|
|
- yaml
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints
|
|
- https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785
|
|
- https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators
|
|
category: security
|
|
technology:
|
|
- spring
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml
|
|
shortlink: https://sg.run/JzKQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 32290
|
|
rv_id: 1263078
|
|
rule_id: kxUWpX
|
|
version_id: O9TpxBp
|
|
url: https://semgrep.dev/playground/r/O9TpxBp/java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml
|
|
origin: community
|
|
- id: java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled
|
|
patterns:
|
|
- pattern: management.endpoints.web.exposure.include=$...ACTUATORS
|
|
- metavariable-comparison:
|
|
metavariable: $...ACTUATORS
|
|
comparison: not str($...ACTUATORS) in ["health","*"]
|
|
message: Spring Boot Actuators "$...ACTUATORS" are enabled. Depending on the actuators,
|
|
this can pose a significant security risk. Please double-check if the actuators
|
|
are needed and properly secured.
|
|
severity: WARNING
|
|
languages:
|
|
- generic
|
|
options:
|
|
generic_ellipsis_max_span: 0
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints
|
|
- https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785
|
|
- https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators
|
|
category: security
|
|
technology:
|
|
- spring
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled
|
|
shortlink: https://sg.run/5g23
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 32291
|
|
rv_id: 1263079
|
|
rule_id: wdUWrZ
|
|
version_id: e1Tyjqe
|
|
url: https://semgrep.dev/playground/r/e1Tyjqe/java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled
|
|
origin: community
|
|
- id: terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging
|
|
patterns:
|
|
- pattern: |
|
|
resource "google_storage_bucket" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not-inside: "resource \"google_storage_bucket\" $ANYTHING {\n ...\n logging
|
|
{\n log_bucket = ...\n } \n ...\n}\n"
|
|
message: Ensure bucket logs access.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A10:2017 - Insufficient Logging & Monitoring
|
|
- A09:2021 - Security Logging and Monitoring Failures
|
|
- A09:2025 - Security Logging & Alerting Failures
|
|
cwe:
|
|
- 'CWE-778: Insufficient Logging'
|
|
technology:
|
|
- terraform
|
|
- gcp
|
|
category: security
|
|
references:
|
|
- https://docs.bridgecrew.io/docs/google-cloud-policy-index
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insufficient Logging
|
|
source: https://semgrep.dev/r/terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging
|
|
shortlink: https://sg.run/5g5D
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 32303
|
|
rv_id: 1263813
|
|
rule_id: gxUrdg
|
|
version_id: JdTzxRN
|
|
url: https://semgrep.dev/playground/r/JdTzxRN/terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging
|
|
origin: community
|
|
- id: python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4
|
|
message: ARC4 (Alleged RC4) is a stream cipher with serious weaknesses in its initial
|
|
stream output. Its use is strongly discouraged. ARC4 does not use mode constructions.
|
|
Use a strong symmetric cipher such as EAS instead. With the `cryptography` package
|
|
it is recommended to use the `Fernet` which is a secure implementation of AES
|
|
in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class
|
|
from the hazmat primitives but use the AES algorithm instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers
|
|
category: security
|
|
technology:
|
|
- cryptography
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::cryptography
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4
|
|
shortlink: https://sg.run/xoZL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33630
|
|
rv_id: 1263348
|
|
rule_id: KxU8gK
|
|
version_id: QkTGq3Q
|
|
url: https://semgrep.dev/playground/r/QkTGq3Q/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
patterns:
|
|
- pattern: cryptography.hazmat.primitives.ciphers.algorithms.$ARC4($KEY)
|
|
- pattern-inside: cryptography.hazmat.primitives.ciphers.Cipher(...)
|
|
- metavariable-regex:
|
|
metavariable: $ARC4
|
|
regex: ^(ARC4)$
|
|
- focus-metavariable: $ARC4
|
|
fix: AES
|
|
- id: python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish
|
|
message: Blowfish is a block cipher developed by Bruce Schneier. It is known to
|
|
be susceptible to attacks when using weak keys. The author has recommended that
|
|
users of Blowfish move to newer algorithms such as AES. With the `cryptography`
|
|
package it is recommended to use `Fernet` which is a secure implementation of
|
|
AES in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class
|
|
from the hazmat primitives but use the AES algorithm instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers
|
|
- https://tools.ietf.org/html/rfc5469
|
|
category: security
|
|
technology:
|
|
- cryptography
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::cryptography
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish
|
|
shortlink: https://sg.run/OdzL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33631
|
|
rv_id: 1263349
|
|
rule_id: qNULvO
|
|
version_id: 3ZT4XK7
|
|
url: https://semgrep.dev/playground/r/3ZT4XK7/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
patterns:
|
|
- pattern: cryptography.hazmat.primitives.ciphers.algorithms.$BLOWFISH($KEY)
|
|
- metavariable-regex:
|
|
metavariable: $BLOWFISH
|
|
regex: ^(Blowfish)$
|
|
- focus-metavariable: $BLOWFISH
|
|
fix: AES
|
|
- id: python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
|
|
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use SHA256
|
|
or SHA3 instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B303
|
|
references:
|
|
- https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#md5
|
|
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
|
|
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
|
|
- http://2012.sharcs.org/slides/stevens.pdf
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- cryptography
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::cryptography
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
|
|
shortlink: https://sg.run/eY88
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33632
|
|
rv_id: 1263352
|
|
rule_id: lBUopp
|
|
version_id: JdTzxww
|
|
url: https://semgrep.dev/playground/r/JdTzxww/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
patterns:
|
|
- pattern: cryptography.hazmat.primitives.hashes.$MD5()
|
|
- metavariable-regex:
|
|
metavariable: $MD5
|
|
regex: ^(MD5)$
|
|
- focus-metavariable: $MD5
|
|
fix: SHA256
|
|
- id: python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
|
|
patterns:
|
|
- pattern: hashlib.md5(...)
|
|
- pattern-not: hashlib.md5(..., usedforsecurity=False, ...)
|
|
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use SHA256
|
|
or SHA3 instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B303
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.2 Insecure Custom Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
references:
|
|
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
|
|
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
|
|
- http://2012.sharcs.org/slides/stevens.pdf
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- python
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
|
|
shortlink: https://sg.run/vYrY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33633
|
|
rv_id: 1263536
|
|
rule_id: PeU2e2
|
|
version_id: kbTzGE1
|
|
url: https://semgrep.dev/playground/r/kbTzGE1/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
- id: python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish
|
|
message: Detected Blowfish cipher algorithm which is considered insecure. This algorithm
|
|
is not cryptographically secure and can be reversed easily. Use secure stream
|
|
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
|
|
with a block size of 128 bits. When using a block cipher, use a modern mode of
|
|
operation that also provides authentication, such as GCM.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption
|
|
- https://www.pycryptodome.org/src/cipher/cipher
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::pycryptodome
|
|
- crypto::search::symmetric-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish
|
|
shortlink: https://sg.run/dlOE
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33634
|
|
rv_id: 1263545
|
|
rule_id: JDUGnK
|
|
version_id: ExTExln
|
|
url: https://semgrep.dev/playground/r/ExTExln/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Cryptodome.Cipher.Blowfish.new(...)
|
|
- pattern: Crypto.Cipher.Blowfish.new(...)
|
|
- id: python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des
|
|
message: Detected DES cipher or Triple DES algorithm which is considered insecure.
|
|
This algorithm is not cryptographically secure and can be reversed easily. Use
|
|
a secure symmetric cipher from the cryptodome package instead. Use secure stream
|
|
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
|
|
with a block size of 128 bits. When using a block cipher, use a modern mode of
|
|
operation that also provides authentication, such as GCM.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/326.html
|
|
- https://www.pycryptodome.org/src/cipher/cipher
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::pycryptodome
|
|
- crypto::search::symmetric-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des
|
|
shortlink: https://sg.run/Z5bw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33635
|
|
rv_id: 1263546
|
|
rule_id: 5rUr73
|
|
version_id: 7ZTE3G7
|
|
url: https://semgrep.dev/playground/r/7ZTE3G7/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Cryptodome.Cipher.DES.new(...)
|
|
- pattern: Crypto.Cipher.DES.new(...)
|
|
- pattern: Cryptodome.Cipher.DES3.new(...)
|
|
- pattern: Crypto.Cipher.DES3.new(...)
|
|
- id: python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2
|
|
message: Detected RC2 cipher algorithm which is considered insecure. This algorithm
|
|
is not cryptographically secure and can be reversed easily. Use secure stream
|
|
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
|
|
with a block size of 128 bits. When using a block cipher, use a modern mode of
|
|
operation that also provides authentication, such as GCM.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/326.html
|
|
- https://www.pycryptodome.org/src/cipher/cipher
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::pycryptodome
|
|
- crypto::search::symmetric-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2
|
|
shortlink: https://sg.run/nAbY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33636
|
|
rv_id: 1263547
|
|
rule_id: GdUYlW
|
|
version_id: LjTkgn6
|
|
url: https://semgrep.dev/playground/r/LjTkgn6/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Cryptodome.Cipher.ARC2.new(...)
|
|
- pattern: Crypto.Cipher.ARC2.new(...)
|
|
- id: python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4
|
|
message: Detected ARC4 cipher algorithm which is considered insecure. This algorithm
|
|
is not cryptographically secure and can be reversed easily. Use secure stream
|
|
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
|
|
with a block size of 128 bits. When using a block cipher, use a modern mode of
|
|
operation that also provides authentication, such as GCM.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
bandit-code: B304
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/326.html
|
|
- https://www.pycryptodome.org/src/cipher/cipher
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::pycryptodome
|
|
- crypto::search::symmetric-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4
|
|
shortlink: https://sg.run/Eo6N
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33637
|
|
rv_id: 1263548
|
|
rule_id: ReUnEB
|
|
version_id: 8KT5rXY
|
|
url: https://semgrep.dev/playground/r/8KT5rXY/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Cryptodome.Cipher.ARC4.new(...)
|
|
- pattern: Crypto.Cipher.ARC4.new(...)
|
|
- id: python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2
|
|
message: Detected MD2 hash algorithm which is considered insecure. MD2 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use a modern
|
|
hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms
|
|
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
|
|
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
|
|
- http://2012.sharcs.org/slides/stevens.pdf
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::pycryptodome
|
|
- crypto::search::hash-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2
|
|
shortlink: https://sg.run/7JP2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33638
|
|
rv_id: 1263550
|
|
rule_id: AbU0Ex
|
|
version_id: QkTGqD8
|
|
url: https://semgrep.dev/playground/r/QkTGqD8/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Crypto.Hash.MD2.new(...)
|
|
- pattern: Cryptodome.Hash.MD2.new (...)
|
|
- id: python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4
|
|
message: Detected MD4 hash algorithm which is considered insecure. MD4 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use a modern
|
|
hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms
|
|
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
|
|
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
|
|
- http://2012.sharcs.org/slides/stevens.pdf
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::pycryptodome
|
|
- crypto::search::hash-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4
|
|
shortlink: https://sg.run/Lve6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33639
|
|
rv_id: 1263551
|
|
rule_id: BYUJy4
|
|
version_id: 3ZT4Xnp
|
|
url: https://semgrep.dev/playground/r/3ZT4Xnp/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Crypto.Hash.MD4.new(...)
|
|
- pattern: Cryptodome.Hash.MD4.new (...)
|
|
- id: python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5
|
|
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use a modern
|
|
hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead.
|
|
metadata:
|
|
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms
|
|
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
|
|
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
|
|
- http://2012.sharcs.org/slides/stevens.pdf
|
|
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
|
|
category: security
|
|
technology:
|
|
- pycryptodome
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::pycryptodome
|
|
- crypto::search::hash-algorithm::pycryptodomex
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5
|
|
shortlink: https://sg.run/85JN
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33640
|
|
rv_id: 1263552
|
|
rule_id: DbUXwo
|
|
version_id: 44TEjpk
|
|
url: https://semgrep.dev/playground/r/44TEjpk/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5
|
|
origin: community
|
|
options:
|
|
symbolic_propagation: true
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: Crypto.Hash.MD5.new(...)
|
|
- pattern: Cryptodome.Hash.MD5.new (...)
|
|
- id: terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1
|
|
patterns:
|
|
- pattern: resource
|
|
- pattern-inside: |
|
|
resource "google_dns_managed_zone" "..." {
|
|
...
|
|
dnssec_config {
|
|
...
|
|
default_key_specs {
|
|
...
|
|
algorithm = "rsasha1"
|
|
key_type = "zoneSigning"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "google_dns_managed_zone" "..." {
|
|
...
|
|
dnssec_config {
|
|
...
|
|
default_key_specs {
|
|
...
|
|
algorithm = "rsasha1"
|
|
key_type = "keySigning"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
...
|
|
}
|
|
message: "Ensure that RSASHA1 is not used for the zone-signing and key-signing keys
|
|
in Cloud DNS DNSSEC\t"
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- gcp
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1
|
|
shortlink: https://sg.run/bKKW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33670
|
|
rv_id: 1263837
|
|
rule_id: 7KUZZb
|
|
version_id: bZT53oD
|
|
url: https://semgrep.dev/playground/r/bZT53oD/terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl
|
|
patterns:
|
|
- pattern: resource
|
|
- pattern-inside: |
|
|
resource "google_sql_database_instance" "..." {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "google_sql_database_instance" "..." {
|
|
...
|
|
ip_configuration {
|
|
...
|
|
require_ssl = true
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "google_sql_database_instance" "..." {
|
|
...
|
|
ip_configuration {
|
|
...
|
|
ssl_mode = ...
|
|
...
|
|
}
|
|
...
|
|
}
|
|
message: Ensure all Cloud SQL database instance requires all incoming connections
|
|
to use SSL
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- gcp
|
|
references:
|
|
- https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl
|
|
shortlink: https://sg.run/W4Yg
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33709
|
|
rv_id: 1263873
|
|
rule_id: v8Uod5
|
|
version_id: pZT033e
|
|
url: https://semgrep.dev/playground/r/pZT033e/terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database
|
|
patterns:
|
|
- pattern: resource
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
resource "google_sql_database_instance" "..." {
|
|
...
|
|
ip_configuration {
|
|
...
|
|
authorized_networks {
|
|
...
|
|
value = "0.0.0.0/0"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "google_sql_database_instance" "..." {
|
|
...
|
|
ip_configuration {
|
|
...
|
|
dynamic "authorized_networks" {
|
|
...
|
|
content {
|
|
...
|
|
value = "0.0.0.0/0"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
...
|
|
}
|
|
...
|
|
}
|
|
message: Ensure that Cloud SQL database Instances are not open to the world
|
|
metadata:
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-1220: Insufficient Granularity of Access Control'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- gcp
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database
|
|
shortlink: https://sg.run/0Xv5
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 33710
|
|
rv_id: 1263876
|
|
rule_id: d8U7Ll
|
|
version_id: jQTn559
|
|
url: https://semgrep.dev/playground/r/jQTn559/terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding
|
|
message: You are using the outdated PKCS#1 v1.5 encryption padding for your RSA
|
|
key. Use the OAEP padding instead.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe:
|
|
- 'CWE-780: Use of RSA Algorithm without OAEP'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsapkcs1keyexchangeformatter
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsaoaepkeyexchangeformatter
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsapkcs1keyexchangedeformatter
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsaoaepkeyexchangedeformatter
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding
|
|
shortlink: https://sg.run/GoJ1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 35492
|
|
rv_id: 1262625
|
|
rule_id: QrU2G5
|
|
version_id: bZT53zb
|
|
url: https://semgrep.dev/playground/r/bZT53zb/csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
pattern-either:
|
|
- pattern: (RSAPKCS1KeyExchangeFormatter $FORMATER).CreateKeyExchange(...);
|
|
- pattern: (RSAPKCS1KeyExchangeDeformatter $DEFORMATER).DecryptKeyExchange(...);
|
|
- id: php.lang.security.redirect-to-request-uri.redirect-to-request-uri
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
header('$LOCATION' . $_SERVER['REQUEST_URI']);
|
|
- pattern: |
|
|
header('$LOCATION' . $_SERVER['REQUEST_URI'] . $MORE);
|
|
- metavariable-regex:
|
|
metavariable: $LOCATION
|
|
regex: ^(?i)location:\s*$
|
|
message: Redirecting to the current request URL may redirect to another domain,
|
|
if the current path starts with two slashes. E.g. in https://www.example.com//attacker.com,
|
|
the value of REQUEST_URI is //attacker.com, and redirecting to it will redirect
|
|
to that domain.
|
|
metadata:
|
|
references:
|
|
- https://www.php.net/manual/en/reserved.variables.server.php
|
|
- https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html
|
|
category: security
|
|
technology:
|
|
- php
|
|
owasp:
|
|
- A05:2017 - Broken Access Control
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
|
|
likelihood: MEDIUM
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Open Redirect
|
|
source: https://semgrep.dev/r/php.lang.security.redirect-to-request-uri.redirect-to-request-uri
|
|
shortlink: https://sg.run/RWl2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 35493
|
|
rv_id: 1263299
|
|
rule_id: 3qUb4n
|
|
version_id: A8Tgdvq
|
|
url: https://semgrep.dev/playground/r/A8Tgdvq/php.lang.security.redirect-to-request-uri.redirect-to-request-uri
|
|
origin: community
|
|
languages:
|
|
- php
|
|
severity: WARNING
|
|
- id: yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout
|
|
languages:
|
|
- yaml
|
|
message: This GitHub Actions workflow file uses `workflow_run` and checks out code
|
|
from the incoming pull request. When using `workflow_run`, the Action runs in
|
|
the context of the target repository, which includes access to all repository
|
|
secrets. Normally, this is safe because the Action only runs code from the target
|
|
repository, not the incoming PR. However, by checking out the incoming PR code,
|
|
you're now using the incoming code for the rest of the action. You may be inadvertently
|
|
executing arbitrary code from the incoming PR with access to repository secrets,
|
|
which would let an attacker steal repository secrets. This normally happens by
|
|
running build scripts (e.g., `npm build` and `make`) or dependency installation
|
|
scripts (e.g., `python setup.py install`). Audit your workflow file to make sure
|
|
no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
|
|
for additional mitigations.
|
|
metadata:
|
|
category: security
|
|
owasp: A01:2017 - Injection
|
|
cwe: 'CWE-913: Improper Control of Dynamically-Managed Code Resources'
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
|
|
- https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md
|
|
- https://www.legitsecurity.com/blog/github-privilege-escalation-vulnerability
|
|
technology:
|
|
- github-actions
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout
|
|
shortlink: https://sg.run/A0p6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 35494
|
|
rv_id: 947046
|
|
rule_id: 4bU8E4
|
|
version_id: kbTYRwl
|
|
url: https://semgrep.dev/playground/r/kbTYRwl/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
on:
|
|
...
|
|
workflow_run: ...
|
|
...
|
|
...
|
|
- pattern-inside: |
|
|
jobs:
|
|
...
|
|
$JOBNAME:
|
|
...
|
|
steps:
|
|
...
|
|
- pattern: |
|
|
...
|
|
uses: "$ACTION"
|
|
with:
|
|
...
|
|
ref: $EXPR
|
|
- metavariable-regex:
|
|
metavariable: $ACTION
|
|
regex: actions/checkout@.*
|
|
- metavariable-pattern:
|
|
language: generic
|
|
metavariable: $EXPR
|
|
patterns:
|
|
- pattern: ${{ github.event.workflow_run ... }}
|
|
severity: WARNING
|
|
- id: csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm
|
|
message: Usage of deprecated cipher algorithm detected. Use Aes or ChaCha20Poly1305
|
|
instead.
|
|
severity: ERROR
|
|
metadata:
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.des?view=net-6.0#remarks
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rc2?view=net-6.0#remarks
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aes?view=net-6.0
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm
|
|
shortlink: https://sg.run/k8Qo
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 36772
|
|
rv_id: 1262622
|
|
rule_id: WAUJr0
|
|
version_id: 9lT4bRK
|
|
url: https://semgrep.dev/playground/r/9lT4bRK/csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
patterns:
|
|
- pattern: $KEYTYPE.Create(...);
|
|
- metavariable-pattern:
|
|
metavariable: $KEYTYPE
|
|
pattern-either:
|
|
- pattern: DES
|
|
- pattern: RC2
|
|
- id: csharp.dotnet.security.use_ecb_mode.use_ecb_mode
|
|
message: Usage of the insecure ECB mode detected. You should use an authenticated
|
|
encryption mode instead, which is implemented by the classes AesGcm or ChaCha20Poly1305.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
category: security
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0
|
|
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.ciphermode?view=net-6.0
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.use_ecb_mode.use_ecb_mode
|
|
shortlink: https://sg.run/wj9n
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 36773
|
|
rv_id: 1262623
|
|
rule_id: 0oUqWP
|
|
version_id: yeTxpPw
|
|
url: https://semgrep.dev/playground/r/yeTxpPw/csharp.dotnet.security.use_ecb_mode.use_ecb_mode
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: ($KEYTYPE $KEY).EncryptEcb(...);
|
|
- pattern: ($KEYTYPE $KEY).DecryptEcb(...);
|
|
- pattern: ($KEYTYPE $KEY).Mode = CipherMode.ECB;
|
|
- metavariable-pattern:
|
|
metavariable: $KEYTYPE
|
|
pattern-either:
|
|
- pattern: SymmetricAlgorithm
|
|
- pattern: Aes
|
|
- pattern: Rijndael
|
|
- pattern: DES
|
|
- pattern: TripleDES
|
|
- pattern: RC2
|
|
- id: csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration
|
|
message: You are using an insecure random number generator (RNG) to create a cryptographic
|
|
key. System.Random must never be used for cryptographic purposes. Use System.Security.Cryptography.RandomNumberGenerator
|
|
instead.
|
|
severity: ERROR
|
|
metadata:
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
category: security
|
|
cwe:
|
|
- 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://learn.microsoft.com/en-us/dotnet/api/system.random?view=net-6.0#remarks
|
|
- https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.randomnumbergenerator?view=net-6.0
|
|
- https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0#constructors
|
|
- https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.symmetricalgorithm.key?view=net-6.0#system-security-cryptography-symmetricalgorithm-key
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- .net
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration
|
|
shortlink: https://sg.run/xjrA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 36774
|
|
rv_id: 1262624
|
|
rule_id: KxU3Nq
|
|
version_id: rxTAK2O
|
|
url: https://semgrep.dev/playground/r/rxTAK2O/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-inside: (System.Random $RNG).NextBytes($KEY); ...
|
|
- pattern: $KEY
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: ($KEYTYPE $CIPHER).Key = $SINK;
|
|
- focus-metavariable: $SINK
|
|
- metavariable-pattern:
|
|
metavariable: $KEYTYPE
|
|
pattern-either:
|
|
- pattern: SymmetricAlgorithm
|
|
- pattern: Aes
|
|
- pattern: Rijndael
|
|
- pattern: DES
|
|
- pattern: TripleDES
|
|
- pattern: RC2
|
|
- pattern: new AesGcm(...)
|
|
- pattern: new AesCcm(...)
|
|
- pattern: new ChaCha20Poly1305(...)
|
|
- id: html.security.plaintext-http-link.plaintext-http-link
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- html
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
confidence: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/319.html
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/html.security.plaintext-http-link.plaintext-http-link
|
|
shortlink: https://sg.run/RA5q
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 39193
|
|
rv_id: 1262976
|
|
rule_id: AbUnNo
|
|
version_id: xyTjzRL
|
|
url: https://semgrep.dev/playground/r/xyTjzRL/html.security.plaintext-http-link.plaintext-http-link
|
|
origin: community
|
|
patterns:
|
|
- pattern: <a href="$URL">...</a>
|
|
- metavariable-regex:
|
|
metavariable: $URL
|
|
regex: ^(?i)http://
|
|
message: This link points to a plaintext HTTP URL. Prefer an encrypted HTTPS URL
|
|
if possible.
|
|
severity: WARNING
|
|
languages:
|
|
- html
|
|
- id: java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils
|
|
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
|
|
resistant and is therefore not suitable as a cryptographic signature. Use HMAC
|
|
instead.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::org.apache.commons
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils
|
|
shortlink: https://sg.run/AWL2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 39194
|
|
rv_id: 1263012
|
|
rule_id: BYUGK0
|
|
version_id: WrTqK7K
|
|
url: https://semgrep.dev/playground/r/WrTqK7K/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils
|
|
origin: community
|
|
patterns:
|
|
- pattern: |
|
|
$DU.$GET_ALGO().digest(...)
|
|
- metavariable-pattern:
|
|
metavariable: $GET_ALGO
|
|
pattern: getMd5Digest
|
|
- metavariable-pattern:
|
|
metavariable: $DU
|
|
pattern: DigestUtils
|
|
- focus-metavariable: $GET_ALGO
|
|
fix: |
|
|
getSha512Digest
|
|
- id: yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection
|
|
message: Using input or workflow parameters in here-scripts can lead to command
|
|
injection or code injection. Convert the parameters to env variables instead.
|
|
languages:
|
|
- yaml
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
owasp:
|
|
- "A03:2021 \u2013 Injection"
|
|
confidence: MEDIUM
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://github.com/argoproj/argo-workflows/issues/5061
|
|
- https://github.com/argoproj/argo-workflows/issues/5114#issue-808865370
|
|
technology:
|
|
- ci
|
|
- argo
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection
|
|
shortlink: https://sg.run/yqeZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 40768
|
|
rv_id: 1151472
|
|
rule_id: 10U0zW
|
|
version_id: xyTp17z
|
|
url: https://semgrep.dev/playground/r/xyTp17z/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection
|
|
origin: community
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-inside: |
|
|
apiVersion: $VERSION
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $VERSION
|
|
regex: (argoproj.io.*)
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
command:
|
|
...
|
|
- $LANG
|
|
...
|
|
...
|
|
source:
|
|
$SCRIPT
|
|
- metavariable-regex:
|
|
metavariable: $LANG
|
|
regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).*
|
|
- metavariable-pattern:
|
|
metavariable: $SCRIPT
|
|
pattern-either:
|
|
- pattern-regex: (.*{{.*inputs.parameters.*}}.*)
|
|
- pattern-regex: (.*{{.*workflow.parameters.*}}.*)
|
|
- focus-metavariable: $SCRIPT
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
container:
|
|
...
|
|
command: $LANG
|
|
...
|
|
args: $PARAM
|
|
- pattern-inside: |
|
|
containerSet:
|
|
...
|
|
containers:
|
|
- ...
|
|
command: $LANG
|
|
...
|
|
args: $PARAM
|
|
- metavariable-regex:
|
|
metavariable: $LANG
|
|
regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).*
|
|
- metavariable-pattern:
|
|
metavariable: $PARAM
|
|
pattern-either:
|
|
- pattern-regex: (.*{{.*inputs.parameters.*}}.*)
|
|
- pattern-regex: (.*{{.*workflow.parameters.*}}.*)
|
|
- focus-metavariable: $PARAM
|
|
- id: python.cryptography.security.empty-aes-key.empty-aes-key
|
|
message: Potential empty AES encryption key. Using an empty key in AES encryption
|
|
can result in weak encryption and may allow attackers to easily decrypt sensitive
|
|
data. Ensure that a strong, non-empty key is used for AES encryption.
|
|
patterns:
|
|
- pattern: AES.new("",...)
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
- 'CWE-310: Cryptographic Issues'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/327.html
|
|
- https://cwe.mitre.org/data/definitions/310.html
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
owasp: A6:2017 misconfiguration
|
|
functional-categories:
|
|
- crypto::search::key-length::pycrypto
|
|
- crypto::search::key-length::pycryptodome
|
|
technology:
|
|
- python
|
|
- pycrypto
|
|
- pycryptodome
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.cryptography.security.empty-aes-key.empty-aes-key
|
|
shortlink: https://sg.run/zQ9G
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 44817
|
|
rv_id: 946105
|
|
rule_id: OrUADK
|
|
version_id: 8KTKjRg
|
|
url: https://semgrep.dev/playground/r/8KTKjRg/python.cryptography.security.empty-aes-key.empty-aes-key
|
|
origin: community
|
|
- id: dockerfile.security.missing-user-entrypoint.missing-user-entrypoint
|
|
patterns:
|
|
- pattern: |
|
|
ENTRYPOINT $...VARS
|
|
- pattern-not-inside: |
|
|
USER $USER
|
|
...
|
|
fix: |
|
|
USER non-root
|
|
ENTRYPOINT $...VARS
|
|
message: By not specifying a USER, a program in the container may run as 'root'.
|
|
This is a security hazard. If an attacker can control a process running as root,
|
|
they may have control over the container. Ensure that the last USER in a Dockerfile
|
|
is a USER other than 'root'.
|
|
severity: ERROR
|
|
languages:
|
|
- dockerfile
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-269: Improper Privilege Management'
|
|
category: security
|
|
technology:
|
|
- dockerfile
|
|
confidence: MEDIUM
|
|
owasp:
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint
|
|
shortlink: https://sg.run/k281
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 47272
|
|
rv_id: 1262659
|
|
rule_id: ReUW9E
|
|
version_id: o5TbD21
|
|
url: https://semgrep.dev/playground/r/o5TbD21/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint
|
|
origin: community
|
|
- id: terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions
|
|
pattern-either:
|
|
- pattern: |
|
|
resource "aws_config_configuration_aggregator" $ANYTHING {
|
|
...
|
|
account_aggregation_source {
|
|
...
|
|
regions = ...
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: |
|
|
resource "aws_config_configuration_aggregator" $ANYTHING {
|
|
...
|
|
organization_aggregation_source {
|
|
...
|
|
regions = ...
|
|
...
|
|
}
|
|
...
|
|
}
|
|
message: The AWS configuration aggregator does not aggregate all AWS Config region.
|
|
This may result in unmonitored configuration in regions that are thought to be
|
|
unused. Configure the aggregator with all_regions for the source.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A09:2021 - Security Logging and Monitoring Failures
|
|
- A09:2025 - Security Logging & Alerting Failures
|
|
cwe:
|
|
- 'CWE-778: Insufficient Logging'
|
|
references:
|
|
- https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insufficient Logging
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions
|
|
shortlink: https://sg.run/O6A7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 47275
|
|
rv_id: 1263703
|
|
rule_id: DbUo7v
|
|
version_id: A8Tgdwv
|
|
url: https://semgrep.dev/playground/r/A8Tgdwv/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions
|
|
origin: community
|
|
- id: yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext
|
|
patterns:
|
|
- pattern-inside: |
|
|
containers:
|
|
...
|
|
- pattern-inside: |
|
|
- $NAME: $CONTAINER
|
|
...
|
|
- pattern: |
|
|
image: ...
|
|
...
|
|
- pattern-not: |
|
|
image: ...
|
|
...
|
|
securityContext:
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $NAME
|
|
regex: name
|
|
- focus-metavariable: $NAME
|
|
fix: |
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
$NAME
|
|
message: In Kubernetes, each pod runs in its own isolated environment with its own
|
|
set of security policies. However, certain container images may contain `setuid`
|
|
or `setgid` binaries that could allow an attacker to perform privilege escalation
|
|
and gain access to sensitive resources. To mitigate this risk, it's recommended
|
|
to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation`
|
|
set to `false`. This will prevent the container from running any privileged processes
|
|
and limit the impact of any potential attacks. By adding a `securityContext` to
|
|
your Kubernetes pod, you can help to ensure that your containerized applications
|
|
are more secure and less vulnerable to privilege escalation attacks.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A06:2017 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation
|
|
- https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
|
|
- https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag
|
|
category: security
|
|
technology:
|
|
- kubernetes
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext
|
|
shortlink: https://sg.run/eleR
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 47276
|
|
rv_id: 1263931
|
|
rule_id: WAU5J6
|
|
version_id: 2KTv2j8
|
|
url: https://semgrep.dev/playground/r/2KTv2j8/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext
|
|
origin: community
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
- id: yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true
|
|
patterns:
|
|
- pattern-inside: |
|
|
containers:
|
|
...
|
|
- pattern-inside: |
|
|
- name: $CONTAINER
|
|
...
|
|
- pattern-inside: |
|
|
image: ...
|
|
...
|
|
- pattern-inside: |
|
|
securityContext:
|
|
...
|
|
- pattern: |
|
|
allowPrivilegeEscalation: $TRUE
|
|
- metavariable-pattern:
|
|
metavariable: $TRUE
|
|
pattern: |
|
|
true
|
|
- focus-metavariable: $TRUE
|
|
fix: |
|
|
false
|
|
message: In Kubernetes, each pod runs in its own isolated environment with its own set
|
|
of security policies. However, certain container images may contain `setuid`
|
|
or `setgid` binaries that could allow an attacker to perform privilege escalation
|
|
and gain access to sensitive resources. To mitigate this risk, it's recommended
|
|
to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation`
|
|
set to `false`. This will prevent the container from running any privileged processes
|
|
and limit the impact of any potential attacks. In the container `$CONTAINER`
|
|
this parameter is set to `true` which makes this container much more vulnerable
|
|
to privelege escalation attacks.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A06:2017 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation
|
|
- https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
|
|
- https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag
|
|
category: security
|
|
technology:
|
|
- kubernetes
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true
|
|
shortlink: https://sg.run/vw3W
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 47277
|
|
rv_id: 1263932
|
|
rule_id: 0oUkqQ
|
|
version_id: X0Tzyqr
|
|
url: https://semgrep.dev/playground/r/X0Tzyqr/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true
|
|
origin: community
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
- id: terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_docdb_cluster" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_docdb_cluster" $ANYTHING {
|
|
...
|
|
enabled_cloudwatch_logs_exports = [..., "audit", ...]
|
|
...
|
|
}
|
|
message: Auditing is not enabled for DocumentDB. To ensure that you are able to
|
|
accurately audit the usage of your DocumentDB cluster, you should enable auditing
|
|
and export logs to CloudWatch.
|
|
languages:
|
|
- hcl
|
|
severity: INFO
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A09:2021 - Security Logging and Monitoring Failures
|
|
- A09:2025 - Security Logging & Alerting Failures
|
|
cwe:
|
|
- 'CWE-778: Insufficient Logging'
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/docdb_cluster#enabled_cloudwatch_logs_exports
|
|
- https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insufficient Logging
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled
|
|
shortlink: https://sg.run/xJYP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48630
|
|
rv_id: 1263705
|
|
rule_id: AbU1WN
|
|
version_id: DkTRbA4
|
|
url: https://semgrep.dev/playground/r/DkTRbA4/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled
|
|
origin: community
|
|
- id: terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_ecr_repository" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_ecr_repository" $ANYTHING {
|
|
...
|
|
image_tag_mutability = "IMMUTABLE"
|
|
...
|
|
}
|
|
message: The ECR repository allows tag mutability. Image tags could be overwritten
|
|
with compromised images. ECR images should be set to IMMUTABLE to prevent code
|
|
injection through image mutation. This can be done by setting `image_tag_mutability`
|
|
to IMMUTABLE.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software or Data Integrity Failures
|
|
cwe:
|
|
- 'CWE-345: Insufficient Verification of Data Authenticity'
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository#image_tag_mutability
|
|
- https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures/
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags
|
|
shortlink: https://sg.run/ZEeL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48635
|
|
rv_id: 1263716
|
|
rule_id: KxUB4o
|
|
version_id: A8Tgdwd
|
|
url: https://semgrep.dev/playground/r/A8Tgdwd/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags
|
|
origin: community
|
|
- id: terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal
|
|
patterns:
|
|
- pattern-inside: |
|
|
resource "aws_ecr_repository_policy" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: policy = "$JSONPOLICY"
|
|
- metavariable-pattern:
|
|
metavariable: $JSONPOLICY
|
|
language: json
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
{..., "Effect": "Deny", ...}
|
|
- pattern-either:
|
|
- pattern: |
|
|
{..., "Principal": "*", ...}
|
|
- pattern: |
|
|
{..., "Principal": [..., "*", ...], ...}
|
|
- pattern: |
|
|
{..., "Principal": { "AWS": "*" }, ...}
|
|
- pattern: |
|
|
{..., "Principal": { "AWS": [..., "*", ...] }, ...}
|
|
- patterns:
|
|
- pattern-inside: policy = jsonencode(...)
|
|
- pattern-not-inside: |
|
|
{..., Effect = "Deny", ...}
|
|
- pattern-either:
|
|
- pattern: |
|
|
{..., Principal = "*", ...}
|
|
- pattern: |
|
|
{..., Principal = [..., "*", ...], ...}
|
|
- pattern: |
|
|
{..., Principal = { AWS = "*" }, ...}
|
|
- pattern: |
|
|
{..., Principal = { AWS = [..., "*", ...] }, ...}
|
|
message: Detected wildcard access granted in your ECR repository policy principal.
|
|
This grants access to all users, including anonymous users (public access). Instead,
|
|
limit principals, actions and resources to what you need according to least privilege.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository_policy
|
|
- https://docs.aws.amazon.com/lambda/latest/operatorguide/wildcard-permissions-iam.html
|
|
- https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/monitor-amazon-ecr-repositories-for-wildcard-permissions-using-aws-cloudformation-and-aws-config.html
|
|
- https://cwe.mitre.org/data/definitions/732.html
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal
|
|
shortlink: https://sg.run/nzqb
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48636
|
|
rv_id: 1263717
|
|
rule_id: qNUzov
|
|
version_id: BjTkZ6A
|
|
url: https://semgrep.dev/playground/r/BjTkZ6A/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb
|
|
pattern: $CIPHER.getInstance("=~/AES/ECB.*/")
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::mode::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb
|
|
shortlink: https://sg.run/dB2Y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48734
|
|
rv_id: 1263009
|
|
rule_id: WAU2yA
|
|
version_id: A8TgdEo
|
|
url: https://semgrep.dev/playground/r/A8TgdEo/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb
|
|
origin: community
|
|
message: 'Use of AES with ECB mode detected. ECB doesn''t provide message confidentiality
|
|
and is not semantically secure so should not be used. Instead, use a strong,
|
|
secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions
|
|
for more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish
|
|
pattern: $CIPHER.getInstance("Blowfish")
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish
|
|
shortlink: https://sg.run/ZE4n
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48735
|
|
rv_id: 1263010
|
|
rule_id: 0oUR28
|
|
version_id: BjTkZy0
|
|
url: https://semgrep.dev/playground/r/BjTkZy0/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish
|
|
origin: community
|
|
message: 'Use of Blowfish was detected. Blowfish uses a 64-bit block size that makes
|
|
it vulnerable to birthday attacks, and is therefore considered non-compliant. Instead,
|
|
use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions
|
|
for more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import javax;
|
|
...
|
|
- pattern-either:
|
|
- pattern: javax.crypto.Cipher.getInstance("AES")
|
|
- pattern: (javax.crypto.Cipher $CIPHER).getInstance("AES")
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import javax.*;
|
|
...
|
|
- pattern-inside: |
|
|
import javax.crypto;
|
|
...
|
|
- pattern-either:
|
|
- pattern: crypto.Cipher.getInstance("AES")
|
|
- pattern: (crypto.Cipher $CIPHER).getInstance("AES")
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
import javax.crypto.*;
|
|
...
|
|
- pattern-inside: |
|
|
import javax.crypto.Cipher;
|
|
...
|
|
- pattern-either:
|
|
- pattern: Cipher.getInstance("AES")
|
|
- pattern: (Cipher $CIPHER).getInstance("AES")
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::mode::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes
|
|
shortlink: https://sg.run/nzKO
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48736
|
|
rv_id: 1263011
|
|
rule_id: KxUB7Z
|
|
version_id: DkTRbwy
|
|
url: https://semgrep.dev/playground/r/DkTRbwy/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes
|
|
origin: community
|
|
message: 'Use of AES with no settings detected. By default, java.crypto.Cipher uses
|
|
ECB mode. ECB doesn''t provide message confidentiality and is not semantically
|
|
secure so should not be used. Instead, use a strong, secure cipher: java.crypto.Cipher.getInstance("AES/CBC/PKCS7PADDING").
|
|
See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for
|
|
more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.crypto.use-of-rc2.use-of-rc2
|
|
pattern: $CIPHER.getInstance("RC2")
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2
|
|
shortlink: https://sg.run/EEvA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48737
|
|
rv_id: 1263014
|
|
rule_id: qNUzXG
|
|
version_id: K3TKkg0
|
|
url: https://semgrep.dev/playground/r/K3TKkg0/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2
|
|
origin: community
|
|
message: 'Use of RC2 was detected. RC2 is vulnerable to related-key attacks, and
|
|
is therefore considered non-compliant. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING").
|
|
See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for
|
|
more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.crypto.use-of-rc4.use-of-rc4
|
|
pattern: $CIPHER.getInstance("RC4")
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::symmetric-algorithm::javax.crypto
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4
|
|
shortlink: https://sg.run/7OYR
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48738
|
|
rv_id: 1263015
|
|
rule_id: lBUw8k
|
|
version_id: qkTR7vk
|
|
url: https://semgrep.dev/playground/r/qkTR7vk/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4
|
|
origin: community
|
|
message: 'Use of RC4 was detected. RC4 is vulnerable to several attacks, including
|
|
stream cipher attacks and bit flipping attacks. Instead, use a strong, secure
|
|
cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions
|
|
for more information.'
|
|
severity: WARNING
|
|
languages:
|
|
- java
|
|
- id: problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request
|
|
message: Detected an HTTP request sent via HttpGet. This could lead to sensitive
|
|
information being sent over an insecure channel. Instead, it is recommended to
|
|
send requests over HTTPS.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe: 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
owasp: A03:2017 - Sensitive Data Exposure
|
|
references:
|
|
- https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URLConnection.html
|
|
- https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URL.html#openConnection()
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- java
|
|
vulnerability: Insecure Transport
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request
|
|
shortlink: https://sg.run/QE2q
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 48942
|
|
rv_id: 946061
|
|
rule_id: 6JUOJ2
|
|
version_id: WrTEo9G
|
|
url: https://semgrep.dev/playground/r/WrTEo9G/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request
|
|
origin: community
|
|
languages:
|
|
- java
|
|
fix-regex:
|
|
regex: '[Hh][Tt][Tt][Pp]://'
|
|
replacement: https://
|
|
count: 1
|
|
patterns:
|
|
- pattern: |
|
|
"=~/[Hh][Tt][Tt][Pp]://.*/"
|
|
- pattern-inside: |
|
|
$R = new HttpGet("=~/[Hh][Tt][Tt][Pp]://.*/");
|
|
...
|
|
$CLIENT. ... .execute($R, ...);
|
|
- id: terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_ebs_volume" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
resource "aws_ebs_volume" $ANYTHING {
|
|
...
|
|
encrypted = true
|
|
...
|
|
}
|
|
message: The AWS EBS volume is unencrypted. The volume, the disk I/O and any derived
|
|
snapshots could be read if compromised. Volumes should be encrypted to ensure
|
|
sensitive data is stored securely.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
cwe:
|
|
- 'CWE-311: Missing Encryption of Sensitive Data'
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ebs_volume#encrypted
|
|
- https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted
|
|
shortlink: https://sg.run/6ZbY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 50759
|
|
rv_id: 1263708
|
|
rule_id: YGUKl1
|
|
version_id: K3TKk1Z
|
|
url: https://semgrep.dev/playground/r/K3TKk1Z/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted
|
|
origin: community
|
|
- id: terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_launch_template" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_launch_template" $ANYTHING {
|
|
...
|
|
metadata_options {
|
|
...
|
|
http_endpoint = "disabled"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "aws_launch_template" $ANYTHING {
|
|
...
|
|
metadata_options {
|
|
...
|
|
http_tokens = "required"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
message: The EC2 launch template has Instance Metadata Service Version 1 (IMDSv1)
|
|
enabled. IMDSv2 introduced session authentication tokens which improve security
|
|
when talking to IMDS. You should either disable IMDS or require the use of IMDSv2.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe:
|
|
- 'CWE-1390: Weak Authentication'
|
|
references:
|
|
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_configuration#metadata_options
|
|
- https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled
|
|
shortlink: https://sg.run/pg9J
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 50762
|
|
rv_id: 1263712
|
|
rule_id: zdU0Wo
|
|
version_id: JdTzx88
|
|
url: https://semgrep.dev/playground/r/JdTzx88/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled
|
|
origin: community
|
|
- id: terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
resource "aws_subnet" $ANYTHING {
|
|
...
|
|
map_public_ip_on_launch = true
|
|
...
|
|
}
|
|
- pattern: |
|
|
resource "aws_default_subnet" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
resource "aws_default_subnet" $ANYTHING {
|
|
...
|
|
map_public_ip_on_launch = false
|
|
...
|
|
}
|
|
message: Resources in the AWS subnet are assigned a public IP address. Resources
|
|
should not be exposed on the public internet, but should have access limited to
|
|
consumers required for the function of your application. Set `map_public_ip_on_launch`
|
|
to false so that resources are not publicly-accessible.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-1220: Insufficient Granularity of Access Control'
|
|
references:
|
|
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/subnet#map_public_ip_on_launch
|
|
- https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-instance-addressing.html#concepts-public-addresses
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address
|
|
shortlink: https://sg.run/XJZw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 50764
|
|
rv_id: 1263744
|
|
rule_id: 2ZUo79
|
|
version_id: d6Tyxdb
|
|
url: https://semgrep.dev/playground/r/d6Tyxdb/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address
|
|
origin: community
|
|
- id: clojure.lang.security.use-of-md5.use-of-md5
|
|
languages:
|
|
- clojure
|
|
severity: WARNING
|
|
message: MD5 hash algorithm detected. This is not collision resistant and leads
|
|
to easily-cracked password hashes. Replace with current recommended hashing algorithms.
|
|
metadata:
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
|
|
technology:
|
|
- clojure
|
|
source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/weak-hash-function-md5.yml
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
author: Gabriel Marquet <gab.marquet@gmail.com>
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/clojure.lang.security.use-of-md5.use-of-md5
|
|
shortlink: https://sg.run/BgPx
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 52195
|
|
rv_id: 1262609
|
|
rule_id: nJU1ep
|
|
version_id: 0bTKz2B
|
|
url: https://semgrep.dev/playground/r/0bTKz2B/clojure.lang.security.use-of-md5.use-of-md5
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: (MessageDigest/getInstance "MD5")
|
|
- pattern: (MessageDigest/getInstance MessageDigestAlgorithms/MD5)
|
|
- pattern: (MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5)
|
|
- pattern: (java.security.MessageDigest/getInstance "MD5")
|
|
- pattern: (java.security.MessageDigest/getInstance MessageDigestAlgorithms/MD5)
|
|
- pattern: (java.security.MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5)
|
|
- id: generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak
|
|
patterns:
|
|
- pattern-regex: ^(AIza[0-9A-Za-z_-]{35}(?!\S))$
|
|
message: Detects potential Google Maps API keys in code
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
metadata:
|
|
description: Detects potential Google Maps API keys in code
|
|
severity: MEDIUM
|
|
category: security
|
|
confidence: MEDIUM
|
|
impact: HIGH
|
|
likelihood: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
owasp:
|
|
- A3:2017 Sensitive Data Exposure
|
|
references:
|
|
- https://ozguralp.medium.com/unauthorized-google-maps-api-key-usage-cases-and-why-you-need-to-care-1ccb28bf21e
|
|
cwe:
|
|
- 'CWE-538: Insertion of Sensitive Information into Externally-Accessible File
|
|
or Directory'
|
|
technology:
|
|
- Google Maps
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak
|
|
shortlink: https://sg.run/DL5d
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 52196
|
|
rv_id: 945530
|
|
rule_id: EwU3kN
|
|
version_id: NdTqkGz
|
|
url: https://semgrep.dev/playground/r/NdTqkGz/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak
|
|
origin: community
|
|
- id: terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_kinesis_stream" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
resource "aws_kinesis_stream" $ANYTHING {
|
|
...
|
|
encryption_type = "KMS"
|
|
...
|
|
}
|
|
message: The AWS Kinesis stream does not encrypt data at rest. The data could be
|
|
read if the Kinesis stream storage layer is compromised. Enable Kinesis stream
|
|
server-side encryption.
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
cwe:
|
|
- 'CWE-311: Missing Encryption of Sensitive Data'
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/kinesis_stream#encryption_type
|
|
- https://docs.aws.amazon.com/streams/latest/dev/server-side-encryption.html
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
rule-origin-note: published from /src/aws-kinesis-stream-unencrypted.yml in None
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted
|
|
shortlink: https://sg.run/KZ0L
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 52199
|
|
rv_id: 1263728
|
|
rule_id: 8GU72N
|
|
version_id: pZT037O
|
|
url: https://semgrep.dev/playground/r/pZT037O/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted
|
|
origin: community
|
|
- id: terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
resource "aws_sqs_queue_policy" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "aws_sqs_queue" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: policy = "$JSONPOLICY"
|
|
- metavariable-pattern:
|
|
metavariable: $JSONPOLICY
|
|
language: json
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
{..., "Effect": "Deny", ...}
|
|
- pattern-either:
|
|
- pattern: |
|
|
{..., "Principal": "*", ...}
|
|
- pattern: |
|
|
{..., "Principal": [..., "*", ...], ...}
|
|
- pattern: |
|
|
{..., "Principal": { "AWS": "*" }, ...}
|
|
- pattern: |
|
|
{..., "Principal": { "AWS": [..., "*", ...] }, ...}
|
|
- pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnNotLike\": {\n \"aws:SourceArn\":
|
|
...\n }\n},\n...}\n"
|
|
- pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnLike\": {\n \"aws:SourceArn\":
|
|
...\n }\n},\n...}\n"
|
|
- pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnEquals\": {\n \"aws:SourceArn\":
|
|
...\n }\n},\n...}\n"
|
|
- pattern-not-inside: "{..., \n\"Condition\": {\n \"StringNotLike\": {\n
|
|
\ \"aws:PrincipalARN\": ...\n }\n},\n...}\n"
|
|
- patterns:
|
|
- pattern-inside: policy = jsonencode(...)
|
|
- pattern-not-inside: |
|
|
{..., Effect = "Deny", ...}
|
|
- pattern-not-inside: "{..., \nCondition = {\n ArnNotLike = {\n \"aws:SourceArn\"
|
|
= ...\n }\n},\n...}\n"
|
|
- pattern-not-inside: "{..., \nCondition = {\n ArnLike = {\n \"aws:SourceArn\"
|
|
= ...\n }\n},\n...}\n"
|
|
- pattern-not-inside: "{..., \nCondition = {\n ArnEquals = {\n \"aws:SourceArn\"
|
|
= ...\n }\n}\n...}\n"
|
|
- pattern-not-inside: "{..., \nCondition = {\n StringNotLike = {\n \"aws:PrincipalARN\"
|
|
= ...\n }\n},\n...}\n"
|
|
- pattern-either:
|
|
- pattern: |
|
|
{..., Principal = "*", ...}
|
|
- pattern: |
|
|
{..., Principal = [..., "*", ...], ...}
|
|
- pattern: |
|
|
{..., Principal = { AWS = "*" }, ...}
|
|
- pattern: |
|
|
{..., Principal = { AWS = [..., "*", ...] }, ...}
|
|
message: Wildcard used in your SQS queue policy principal. This grants access to
|
|
all users, including anonymous users (public access). Unless you explicitly require
|
|
anyone on the internet to be able to read or write to your queue, limit principals,
|
|
actions and resources to what you need according to least privilege.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/732.html
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue_policy
|
|
- https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-security-best-practices.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
rule-origin-note: published from /src/aws-sqs-queue-policy-wildcard-principal.yml
|
|
in None
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal
|
|
shortlink: https://sg.run/z3eW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 53517
|
|
rv_id: 1263741
|
|
rule_id: PeUl9d
|
|
version_id: O9TpxgE
|
|
url: https://semgrep.dev/playground/r/O9TpxgE/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_lambda_permission" $ANYTHING {
|
|
...
|
|
principal = "$PRINCIPAL"
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
resource "aws_lambda_permission" $ANYTHING {
|
|
...
|
|
source_arn = ...
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $PRINCIPAL
|
|
regex: .*[.]amazonaws[.]com$
|
|
message: The AWS Lambda permission has an AWS service principal but does not specify
|
|
a source ARN. If you grant permission to a service principal without specifying
|
|
the source, other accounts could potentially configure resources in their account
|
|
to invoke your Lambda function. Set the source_arn value to the ARN of the AWS
|
|
resource that invokes the function, eg. an S3 bucket, CloudWatch Events Rule,
|
|
API Gateway, or SNS topic.
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/732.html
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_permission
|
|
- https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-lambda-permission.html
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn
|
|
shortlink: https://sg.run/kOP7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 54772
|
|
rv_id: 1263732
|
|
rule_id: OrU9Ox
|
|
version_id: 1QTypq5
|
|
url: https://semgrep.dev/playground/r/1QTypq5/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn
|
|
origin: community
|
|
- id: terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active
|
|
patterns:
|
|
- pattern: |
|
|
resource "aws_lambda_function" $ANYTHING {
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
resource "aws_lambda_function" $ANYTHING {
|
|
...
|
|
tracing_config {
|
|
...
|
|
mode = "Active"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
message: The AWS Lambda function does not have active X-Ray tracing enabled. X-Ray
|
|
tracing enables end-to-end debugging and analysis of all function activity. This
|
|
makes it easier to trace the flow of logs and identify bottlenecks, slow downs
|
|
and timeouts.
|
|
languages:
|
|
- hcl
|
|
severity: INFO
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- aws
|
|
- terraform
|
|
owasp:
|
|
- A09:2021 Security Logging and Monitoring Failures
|
|
cwe:
|
|
- 'CWE-778: Insufficient Logging'
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/778.html
|
|
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_function#mode
|
|
- https://docs.aws.amazon.com/lambda/latest/dg/services-xray.html
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insufficient Logging
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active
|
|
shortlink: https://sg.run/wO2Y
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 54773
|
|
rv_id: 946713
|
|
rule_id: eqUl1O
|
|
version_id: QkTZ6vk
|
|
url: https://semgrep.dev/playground/r/QkTZ6vk/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active
|
|
origin: community
|
|
- id: java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
ObjectMapper $OM = new ObjectMapper(...);
|
|
...
|
|
- pattern-inside: |
|
|
$OM.enableDefaultTyping();
|
|
...
|
|
- pattern: $OM.readValue($JSON, ...);
|
|
- patterns:
|
|
- pattern-inside: |
|
|
class $CLASS {
|
|
...
|
|
@JsonTypeInfo(use = Id.CLASS,...)
|
|
$TYPE $VAR;
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $TYPE
|
|
regex: (Object|Serializable|Comparable)
|
|
- pattern: $OM.readValue($JSON, $CLASS.class);
|
|
- patterns:
|
|
- pattern-inside: |
|
|
class $CLASS {
|
|
...
|
|
ObjectMapper $OM;
|
|
...
|
|
$INITMETHODTYPE $INITMETHOD(...) {
|
|
...
|
|
$OM = new ObjectMapper();
|
|
...
|
|
$OM.enableDefaultTyping();
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: "$METHODTYPE $METHOD(...) {\n ... \n}\n"
|
|
- pattern: $OM.readValue($JSON, ...);
|
|
message: When using Jackson to marshall/unmarshall JSON to Java objects, enabling
|
|
default typing is dangerous and can lead to RCE. If an attacker can control `$JSON`
|
|
it might be possible to provide a malicious JSON which can be used to exploit
|
|
unsecure deserialization. In order to prevent this issue, avoid to enable default
|
|
typing (globally or by using "Per-class" annotations) and avoid using `Object`
|
|
and other dangerous types for member variable declaration which creating classes
|
|
for Jackson based deserialization.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
subcategory:
|
|
- audit
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
confidence: MEDIUM
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
owasp:
|
|
- A8:2017 Insecure Deserialization
|
|
- A8:2021 Software and Data Integrity Failures
|
|
references:
|
|
- https://swapneildash.medium.com/understanding-insecure-implementation-of-jackson-deserialization-7b3d409d2038
|
|
- https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
|
|
- https://adamcaudill.com/2017/10/04/exploiting-jackson-rce-cve-2017-7525/
|
|
technology:
|
|
- jackson
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization
|
|
shortlink: https://sg.run/GDop
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 56948
|
|
rv_id: 945724
|
|
rule_id: QrUD20
|
|
version_id: 2KTYbA9
|
|
url: https://semgrep.dev/playground/r/2KTYbA9/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization
|
|
origin: community
|
|
- id: java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
- https://xerces.apache.org/xerces2-j/features.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing
|
|
shortlink: https://sg.run/Gj32
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 59048
|
|
rv_id: 1263061
|
|
rule_id: j2Udpk
|
|
version_id: YDTZeko
|
|
url: https://semgrep.dev/playground/r/YDTZeko/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing
|
|
origin: community
|
|
message: DOCTYPE declarations are enabled for this SAXParserFactory. This is vulnerable
|
|
to XML external entity attacks. Disable this by setting the feature `http://apache.org/xml/features/disallow-doctype-decl`
|
|
to true. Alternatively, allow DOCTYPE declarations and only prohibit external
|
|
entities declarations. This can be done by setting the features `http://xml.org/sax/features/external-general-entities`
|
|
and `http://xml.org/sax/features/external-parameter-entities` to false. NOTE -
|
|
The previous links are not meant to be clicked. They are the literal config key
|
|
values that are supposed to be used to disable these features. For more information,
|
|
see https://semgrep.dev/docs/cheat-sheets/java-xxe/#3a-documentbuilderfactory.
|
|
mode: taint
|
|
pattern-sources:
|
|
- by-side-effect: true
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY = SAXParserFactory.newInstance();
|
|
- patterns:
|
|
- pattern: $FACTORY
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = SAXParserFactory.newInstance();
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = SAXParserFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = SAXParserFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = SAXParserFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $FACTORY.newSAXParser();
|
|
pattern-sanitizers:
|
|
- by-side-effect: true
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
- pattern: |
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
- focus-metavariable: $FACTORY
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl",
|
|
true);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
|
|
...
|
|
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: $M($X)
|
|
- focus-metavariable: $X
|
|
fix: |
|
|
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
|
$FACTORY.newSAXParser();
|
|
languages:
|
|
- java
|
|
- id: java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://blog.sonarsource.com/secure-xml-processor
|
|
- https://xerces.apache.org/xerces2-j/features.html
|
|
category: security
|
|
technology:
|
|
- java
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled
|
|
shortlink: https://sg.run/1wyQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 59622
|
|
rv_id: 1263062
|
|
rule_id: v8UeQ1
|
|
version_id: 6xT29GK
|
|
url: https://semgrep.dev/playground/r/6xT29GK/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled
|
|
origin: community
|
|
message: DOCTYPE declarations are enabled for this TransformerFactory. This is vulnerable
|
|
to XML external entity attacks. Disable this by setting the attributes "accessExternalDTD"
|
|
and "accessExternalStylesheet" to "".
|
|
mode: taint
|
|
pattern-sources:
|
|
- by-side-effect: true
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY = TransformerFactory.newInstance();
|
|
- patterns:
|
|
- pattern: $FACTORY
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = TransformerFactory.newInstance();
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = TransformerFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = TransformerFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = TransformerFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
class $C {
|
|
...
|
|
$V $FACTORY = TransformerFactory.newInstance();
|
|
static {
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $FACTORY.newTransformer(...);
|
|
pattern-sanitizers:
|
|
- by-side-effect: true
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
- pattern: |
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
- pattern: |
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ...
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
- pattern: |
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
|
|
- focus-metavariable: $FACTORY
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
|
|
...
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
class $C {
|
|
...
|
|
$T $M(...) {
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
|
|
...
|
|
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: $M($X)
|
|
- focus-metavariable: $X
|
|
fix: |
|
|
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
|
|
$FACTORY.newTransformer(...);
|
|
languages:
|
|
- java
|
|
- id: java.android.security.exported_activity.exported_activity
|
|
patterns:
|
|
- pattern-not-inside: <activity ... android:exported="false" ... />
|
|
- pattern-inside: "<activity ... /> \n"
|
|
- pattern-either:
|
|
- pattern: |
|
|
<activity ... android:exported="true" ... />
|
|
- pattern: |
|
|
<activity ... <intent-filter> ... />
|
|
message: The application exports an activity. Any application on the device can
|
|
launch the exported activity which may compromise the integrity of your application
|
|
or its data. Ensure that any exported activities do not have privileged access
|
|
to your application's control plane.
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
paths:
|
|
exclude:
|
|
- sources/
|
|
- classes3.dex
|
|
- '*.so'
|
|
include:
|
|
- '*AndroidManifest.xml'
|
|
metadata:
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
cwe:
|
|
- 'CWE-926: Improper Export of Android Application Components'
|
|
confidence: MEDIUM
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
owasp:
|
|
- A5:2021 Security Misconfiguration
|
|
technology:
|
|
- Android
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/926.html
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/java.android.security.exported_activity.exported_activity
|
|
shortlink: https://sg.run/eNGZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 60632
|
|
rv_id: 945629
|
|
rule_id: v8Ul0r
|
|
version_id: rxT6rGR
|
|
url: https://semgrep.dev/playground/r/rxT6rGR/java.android.security.exported_activity.exported_activity
|
|
origin: community
|
|
- id: dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile
|
|
patterns:
|
|
- pattern: |
|
|
RUN sudo ...
|
|
message: Avoid using sudo in Dockerfiles. Running processes as a non-root user can
|
|
help reduce the potential impact of configuration errors and security vulnerabilities.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- dockerfile
|
|
cwe:
|
|
- 'CWE-250: Execution with Unnecessary Privileges'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/250.html
|
|
- https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#user
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile
|
|
shortlink: https://sg.run/80Q7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 66384
|
|
rv_id: 1262661
|
|
rule_id: kxUlx1
|
|
version_id: pZT03zY
|
|
url: https://semgrep.dev/playground/r/pZT03zY/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile
|
|
origin: community
|
|
languages:
|
|
- dockerfile
|
|
severity: WARNING
|
|
- id: swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults
|
|
message: Potentially sensitive data was observed to be stored in UserDefaults, which
|
|
is not adequate protection of sensitive information. For data of a sensitive nature,
|
|
applications should leverage the Keychain.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
category: security
|
|
cwe:
|
|
- 'CWE-311: Missing Encryption of Sensitive Data'
|
|
masvs:
|
|
- 'MASVS-STORAGE-1: The app securely stores sensitive data'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
references:
|
|
- https://developer.apple.com/library/archive/documentation/Security/Conceptual/SecureCodingGuide/Articles/ValidatingInput.html
|
|
- https://mas.owasp.org/MASVS/controls/MASVS-STORAGE-1/
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- ios
|
|
- macos
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults
|
|
shortlink: https://sg.run/qvoO
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 66512
|
|
rv_id: 1263696
|
|
rule_id: KxUqoZ
|
|
version_id: 3ZT4Xy2
|
|
url: https://semgrep.dev/playground/r/3ZT4Xy2/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults
|
|
origin: community
|
|
languages:
|
|
- swift
|
|
options:
|
|
symbolic_propagation: true
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: $KEY)
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: $KEY)
|
|
- metavariable-regex:
|
|
metavariable: $VALUE
|
|
regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$
|
|
- focus-metavariable: $VALUE
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: $KEY)
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: $KEY)
|
|
- metavariable-regex:
|
|
metavariable: $KEY
|
|
regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$
|
|
- focus-metavariable: $KEY
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: $KEY)
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: $KEY)
|
|
- metavariable-regex:
|
|
metavariable: $VALUE
|
|
regex: (?i).*(api_key|apikey)$
|
|
- focus-metavariable: $VALUE
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: $KEY)
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: $KEY)
|
|
- metavariable-regex:
|
|
metavariable: $KEY
|
|
regex: (?i).*(api_key|apikey)$
|
|
- focus-metavariable: $KEY
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: $KEY)
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: $KEY)
|
|
- metavariable-regex:
|
|
metavariable: $VALUE
|
|
regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$
|
|
- focus-metavariable: $VALUE
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: $KEY)
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: $KEY)
|
|
- metavariable-regex:
|
|
metavariable: $KEY
|
|
regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$
|
|
- focus-metavariable: $KEY
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: $KEY)
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: $KEY)
|
|
- metavariable-regex:
|
|
metavariable: $VALUE
|
|
regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$
|
|
- focus-metavariable: $VALUE
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set("$VALUE", forKey: $KEY)
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: "$KEY")
|
|
- pattern: |
|
|
UserDefaults.standard.set($VALUE, forKey: $KEY)
|
|
- metavariable-regex:
|
|
metavariable: $KEY
|
|
regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$
|
|
- focus-metavariable: $KEY
|
|
- id: java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request
|
|
message: Detected input from a HTTPServletRequest going into the environment variables
|
|
of an 'exec' command. Instead, call the command with user-supplied arguments
|
|
by using the overloaded method with one String array as the argument. `exec({"command",
|
|
"arg1", "arg2"})`.
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
(HttpServletRequest $REQ)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);
|
|
...
|
|
for (javax.servlet.http.Cookie $COOKIE: $COOKIES) {
|
|
...
|
|
}
|
|
- pattern: |
|
|
$COOKIE.getValue(...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: (java.lang.Runtime $R).exec($CMD, $ENV_ARGS, ...);
|
|
- focus-metavariable: $ENV_ARGS
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- java
|
|
cwe:
|
|
- 'CWE-454: External Initialization of Trusted Variables or Data Stores'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: false
|
|
cwe2021-top25: false
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request
|
|
shortlink: https://sg.run/EJAB
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 70981
|
|
rv_id: 1409391
|
|
rule_id: nJULjy
|
|
version_id: LjTRL6W
|
|
url: https://semgrep.dev/playground/r/LjTRL6W/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request
|
|
origin: community
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
provisioner "remote-exec" {
|
|
...
|
|
}
|
|
- pattern: |
|
|
provisioner "local-exec" {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "aws_instance" "..." {
|
|
...
|
|
}
|
|
id: terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec
|
|
message: Provisioners are a tool of last resort and should be avoided where possible.
|
|
Provisioner behavior cannot be mapped by Terraform as part of a plan, and execute
|
|
arbitrary shell commands by design.
|
|
languages:
|
|
- terraform
|
|
severity: WARNING
|
|
metadata:
|
|
category: security
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A01:2017 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-77: Improper Neutralization of Special Elements used in a Command (''Command
|
|
Injection'')'
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
subcategory:
|
|
- audit
|
|
confidence: HIGH
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
technology:
|
|
- terraform
|
|
references:
|
|
- https://developer.hashicorp.com/terraform/language/resources/provisioners/remote-exec
|
|
- https://developer.hashicorp.com/terraform/language/resources/provisioners/local-exec
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
- Other
|
|
source: https://semgrep.dev/r/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec
|
|
shortlink: https://sg.run/7EjQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 70982
|
|
rv_id: 1263736
|
|
rule_id: EwUxO1
|
|
version_id: bZT53j1
|
|
url: https://semgrep.dev/playground/r/bZT53j1/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec
|
|
origin: community
|
|
- id: terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy
|
|
metadata:
|
|
category: security
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A05:2017 - Sensitive Data Exposure
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
cwe:
|
|
- 'CWE-1220: Insufficient Granularity of Access Control'
|
|
references:
|
|
- https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-amazon-web-services#configuring-the-role-and-trust-policy
|
|
- https://dagrz.com/writing/aws-security/hacking-github-aws-oidc/
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy
|
|
shortlink: https://sg.run/LWlY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 70983
|
|
rv_id: 1263748
|
|
rule_id: 7KU3dr
|
|
version_id: 7ZTE346
|
|
url: https://semgrep.dev/playground/r/7ZTE346/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy
|
|
origin: community
|
|
message: '`$POLICY` is missing a `condition` block which scopes users of this policy
|
|
to specific GitHub repositories. Without this, `$POLICY` is open to all users
|
|
on GitHub. Add a `condition` block on the variable `token.actions.githubusercontent.com:sub`
|
|
which scopes it to prevent this.'
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
match:
|
|
where:
|
|
- metavariable: $IDENTIFIER
|
|
regex: .*oidc-provider/token\.actions\.githubusercontent\.com
|
|
all:
|
|
- inside: |
|
|
data "aws_iam_policy_document" $POLICY {
|
|
...
|
|
}
|
|
- |
|
|
statement {
|
|
...
|
|
principals {
|
|
...
|
|
type = "Federated"
|
|
identifiers = [..., $IDENTIFIER, ...]
|
|
}
|
|
}
|
|
- not: |
|
|
statement {
|
|
...
|
|
condition {
|
|
...
|
|
variable = "token.actions.githubusercontent.com:sub"
|
|
}
|
|
}
|
|
- id: clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe
|
|
languages:
|
|
- clojure
|
|
severity: ERROR
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
asvs:
|
|
section: V5 Validation, Sanitization and Encoding
|
|
control_id: 5.5.2 Insecue XML Deserialization
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
|
|
version: '4'
|
|
references:
|
|
- https://semgrep.dev/blog/2022/xml-security-in-java
|
|
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
|
|
- https://xerces.apache.org/xerces2-j/features.html
|
|
source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/xxe-clojure-xml/xxe-clojure-xml.yml
|
|
category: security
|
|
technology:
|
|
- clojure
|
|
- xml
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe
|
|
shortlink: https://sg.run/v7An
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 71533
|
|
rv_id: 1262608
|
|
rule_id: bwU3Gj
|
|
version_id: WrTqKyD
|
|
url: https://semgrep.dev/playground/r/WrTqKyD/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe
|
|
origin: community
|
|
message: DOCTYPE declarations are enabled for javax.xml.parsers.SAXParserFactory.
|
|
Without prohibiting external entity declarations, this is vulnerable to XML external
|
|
entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl"
|
|
to true. Alternatively, allow DOCTYPE declarations and only prohibit external
|
|
entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities"
|
|
and "http://xml.org/sax/features/external-parameter-entities" to false.
|
|
patterns:
|
|
- pattern-inside: |
|
|
(ns ... (:require [clojure.xml :as ...]))
|
|
...
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
(def ... ... ( ... ))
|
|
- pattern-inside: |
|
|
(defn ... ... ( ... ))
|
|
- pattern-either:
|
|
- pattern: (clojure.xml/parse $INPUT)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
(doto (javax.xml.parsers.SAXParserFactory/newInstance) ...)
|
|
- pattern: (.setFeature "http://apache.org/xml/features/disallow-doctype-decl"
|
|
false)
|
|
- pattern-not-inside: |
|
|
(doto (javax.xml.parsers.SAXParserFactory/newInstance)
|
|
...
|
|
(.setFeature "http://xml.org/sax/features/external-general-entities" false)
|
|
...
|
|
(.setFeature "http://xml.org/sax/features/external-parameter-entities" false)
|
|
...)
|
|
- pattern-not-inside: |
|
|
(doto (javax.xml.parsers.SAXParserFactory/newInstance)
|
|
...
|
|
(.setFeature "http://xml.org/sax/features/external-parameter-entities" false)
|
|
...
|
|
(.setFeature "http://xml.org/sax/features/external-general-entities" false)
|
|
...)
|
|
- id: clojure.lang.security.use-of-sha1.use-of-sha1
|
|
languages:
|
|
- clojure
|
|
severity: WARNING
|
|
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
|
|
collision resistant and is therefore not suitable as a cryptographic signature.
|
|
Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function
|
|
applications.
|
|
metadata:
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
|
|
technology:
|
|
- clojure
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
- 'CWE-328: Use of Weak Hash'
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/clojure.lang.security.use-of-sha1.use-of-sha1
|
|
shortlink: https://sg.run/dvwX
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 71534
|
|
rv_id: 1262610
|
|
rule_id: NbUy12
|
|
version_id: K3TKk7E
|
|
url: https://semgrep.dev/playground/r/K3TKk7E/clojure.lang.security.use-of-sha1.use-of-sha1
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: (MessageDigest/getInstance $ALGO)
|
|
- pattern: (java.security.MessageDigest/getInstance $ALGO)
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: (((org\.apache\.commons\.codec\.digest\.)?MessageDigestAlgorithms/)?"?(SHA-1|SHA1)"?)
|
|
- id: generic.visualforce.security.ncino.html.usesriforcdns.use-SRI-for-CDNs
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
message: 'Consuming CDNs without including a SubResource Integrity (SRI) can expose
|
|
your application and its users to compromised code. SRIs allow you to consume
|
|
specific versions of content where if even a single byte is compromised, the resource
|
|
will not be loaded. Add an integrity attribute to your <script> and <link> tags
|
|
pointing to CDN content to ensure the resources have not been compromised. A crossorigin
|
|
attribute should also be added. For a more thorough explanation along with explicit
|
|
instructions on remediating, follow the directions from Mozilla here: https://developer.mozilla.org/en-US/blog/securing-cdn-using-sri-why-how/'
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-346: Origin Validation Error'
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe2020-top25': true
|
|
cwe2021-top25': true
|
|
cwe2022-top25': true
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- salesforce
|
|
- visualforce
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/352.html
|
|
- https://developer.mozilla.org/en-US/blog/securing-cdn-using-sri-why-how/
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/generic.visualforce.security.ncino.html.usesriforcdns.use-SRI-for-CDNs
|
|
shortlink: https://sg.run/1pXb
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 72422
|
|
rv_id: 1262905
|
|
rule_id: AbU20Y
|
|
version_id: 5PTo1or
|
|
url: https://semgrep.dev/playground/r/5PTo1or/generic.visualforce.security.ncino.html.usesriforcdns.use-SRI-for-CDNs
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: <link...href="$URL..."...>
|
|
- pattern: <script...src="$URL..."...>
|
|
- metavariable-regex:
|
|
metavariable: $URL
|
|
regex: http[A-Za-z0-9\/\.\-\:]
|
|
- pattern-not: <script...integrity="..."...src="..."...>
|
|
- pattern-not: <script...src="..."...integrity="..."...>
|
|
- pattern-not: <link...integrity="..."...href="..."...>
|
|
- pattern-not: <link...href="..."...integrity="..."...>
|
|
paths:
|
|
include:
|
|
- '*.component'
|
|
- '*.page'
|
|
- id: generic.visualforce.security.ncino.vf.xssfromunescapedurlparam.xss-from-unescaped-url-param
|
|
languages:
|
|
- generic
|
|
severity: ERROR
|
|
message: To remediate this issue, ensure that all URL parameters are properly escaped
|
|
before including them in scripts. Please update your code to use either the JSENCODE
|
|
method to escape URL parameters or the escape="true" attribute on <apex:outputText>
|
|
tags. Passing URL parameters directly into scripts and DOM sinks creates an opportunity
|
|
for Cross-Site Scripting attacks. Cross-Site Scripting (XSS) attacks are a type
|
|
of injection, in which malicious scripts are injected into otherwise benign and
|
|
trusted websites. To remediate this issue, ensure that all URL parameters are
|
|
properly escaped before including them in scripts.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://developer.salesforce.com/docs/atlas.en-us.apexcode.meta/apexcode/pages_security_tips_xss.htm
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- salesforce
|
|
- visualforce
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/generic.visualforce.security.ncino.vf.xssfromunescapedurlparam.xss-from-unescaped-url-param
|
|
shortlink: https://sg.run/9bGk
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 72423
|
|
rv_id: 1262906
|
|
rule_id: BYUAJ2
|
|
version_id: GxTkekB
|
|
url: https://semgrep.dev/playground/r/GxTkekB/generic.visualforce.security.ncino.vf.xssfromunescapedurlparam.xss-from-unescaped-url-param
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: <apex:outputText...escape="false"...value="{!...CurrentPage.parameters.$URL_PARAM}".../>
|
|
- pattern: <apex:outputText...value="{!...CurrentPage.parameters.$URL_PARAM}"...escape="false".../>
|
|
- pattern: <script>...'{!...CurrentPage.parameters.$URL_PARAM}'...</script>
|
|
- pattern-not: <script>...'{!...JSENCODE(...CurrentPage.parameters.$URL_PARAM})'...</script>
|
|
paths:
|
|
include:
|
|
- '*.component'
|
|
- '*.page'
|
|
- id: generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute
|
|
languages:
|
|
- generic
|
|
severity: INFO
|
|
message: Visualforce Pages must have the cspHeader attribute set to true. This attribute
|
|
is available in API version 55 or higher.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://help.salesforce.com/s/articleView?id=sf.csp_trusted_sites.htm&type=5
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- salesforce
|
|
- visualforce
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute
|
|
shortlink: https://sg.run/yoj8
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 72424
|
|
rv_id: 1262907
|
|
rule_id: DbUj7d
|
|
version_id: RGT0L0r
|
|
url: https://semgrep.dev/playground/r/RGT0L0r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute
|
|
origin: community
|
|
patterns:
|
|
- pattern: <apex:page...>...</apex:page>
|
|
- pattern-not: <apex:page...cspHeader="true"...>...</apex:page>
|
|
- pattern-not: <apex:page...>...<!--deprecated-->...</apex:page>
|
|
- pattern-not: <apex:page...>...<!-- deprecated -->...</apex:page>
|
|
paths:
|
|
include:
|
|
- '*.page'
|
|
- id: generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version
|
|
languages:
|
|
- generic
|
|
severity: WARNING
|
|
message: Visualforce Pages must use API version 55 or higher for required use of
|
|
the cspHeader attribute set to true.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://developer.salesforce.com/docs/atlas.en-us.api_meta.meta/api_meta/meta_pages.htm
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- salesforce
|
|
- visualforce
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version
|
|
shortlink: https://sg.run/rWr6
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 72425
|
|
rv_id: 1262908
|
|
rule_id: WAUwJW
|
|
version_id: A8Tgdgn
|
|
url: https://semgrep.dev/playground/r/A8Tgdgn/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: <apiVersion.../apiVersion>
|
|
- pattern-either:
|
|
- pattern-regex: '[>][0-9].[0-9][<]'
|
|
- pattern-regex: '[>][1-4][0-9].[0-9][<]'
|
|
- pattern-regex: '[>][5][0-4].[0-9][<]'
|
|
paths:
|
|
include:
|
|
- '*.page-meta.xml'
|
|
- id: python.django.security.hashids-with-django-secret.hashids-with-django-secret
|
|
languages:
|
|
- python
|
|
message: The Django secret key is used as salt in HashIDs. The HashID mechanism
|
|
is not secure. By observing sufficient HashIDs, the salt used to construct them
|
|
can be recovered. This means the Django secret key can be obtained by attackers,
|
|
through the HashIDs.
|
|
metadata:
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- "A02:2021 \u2013 Cryptographic Failures"
|
|
references:
|
|
- https://docs.djangoproject.com/en/4.2/ref/settings/#std-setting-SECRET_KEY
|
|
- http://carnage.github.io/2015/08/cryptanalysis-of-hashids
|
|
technology:
|
|
- django
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.django.security.hashids-with-django-secret.hashids-with-django-secret
|
|
shortlink: https://sg.run/bxeZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 72426
|
|
rv_id: 946163
|
|
rule_id: 0oUXqy
|
|
version_id: 0bT15nn
|
|
url: https://semgrep.dev/playground/r/0bT15nn/python.django.security.hashids-with-django-secret.hashids-with-django-secret
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: hashids.Hashids(..., salt=django.conf.settings.SECRET_KEY, ...)
|
|
- pattern: hashids.Hashids(django.conf.settings.SECRET_KEY, ...)
|
|
severity: ERROR
|
|
- id: python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret
|
|
languages:
|
|
- python
|
|
message: The Flask secret key is used as salt in HashIDs. The HashID mechanism is
|
|
not secure. By observing sufficient HashIDs, the salt used to construct them can
|
|
be recovered. This means the Flask secret key can be obtained by attackers, through
|
|
the HashIDs.
|
|
metadata:
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- "A02:2021 \u2013 Cryptographic Failures"
|
|
references:
|
|
- https://flask.palletsprojects.com/en/2.2.x/config/#SECRET_KEY
|
|
- http://carnage.github.io/2015/08/cryptanalysis-of-hashids
|
|
technology:
|
|
- flask
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret
|
|
shortlink: https://sg.run/N0Rx
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 72427
|
|
rv_id: 946220
|
|
rule_id: KxUX3z
|
|
version_id: 0bT15Px
|
|
url: https://semgrep.dev/playground/r/0bT15Px/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: hashids.Hashids(..., salt=flask.current_app.config['SECRET_KEY'], ...)
|
|
- pattern: hashids.Hashids(flask.current_app.config['SECRET_KEY'], ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$APP = flask.Flask(...)
|
|
...
|
|
- pattern-either:
|
|
- pattern: hashids.Hashids(..., salt=$APP.config['SECRET_KEY'], ...)
|
|
- pattern: hashids.Hashids($APP.config['SECRET_KEY'], ...)
|
|
severity: ERROR
|
|
- id: python.lang.security.use-defused-xml-parse.use-defused-xml-parse
|
|
metadata:
|
|
owasp:
|
|
- A04:2017 - XML External Entities (XXE)
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
cwe:
|
|
- 'CWE-611: Improper Restriction of XML External Entity Reference'
|
|
references:
|
|
- https://docs.python.org/3/library/xml.html
|
|
- https://github.com/tiran/defusedxml
|
|
- https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing
|
|
category: security
|
|
technology:
|
|
- python
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- XML Injection
|
|
source: https://semgrep.dev/r/python.lang.security.use-defused-xml-parse.use-defused-xml-parse
|
|
shortlink: https://sg.run/n3jG
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 72436
|
|
rv_id: 1263541
|
|
rule_id: X5Uqnx
|
|
version_id: vdT06ER
|
|
url: https://semgrep.dev/playground/r/vdT06ER/python.lang.security.use-defused-xml-parse.use-defused-xml-parse
|
|
origin: community
|
|
message: The native Python `xml` library is vulnerable to XML External Entity (XXE)
|
|
attacks. These attacks can leak confidential data and "XML bombs" can cause denial
|
|
of service. Do not use this library to parse untrusted input. Instead the Python
|
|
documentation recommends using `defusedxml`.
|
|
languages:
|
|
- python
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern: xml.etree.ElementTree.parse($...ARGS)
|
|
- pattern-not: xml.etree.ElementTree.parse("...")
|
|
fix: defusedxml.etree.ElementTree.parse($...ARGS)
|
|
- id: php.lang.security.tainted-exec.tainted-exec
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: $_REQUEST
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
- pattern: $_COOKIE
|
|
pattern-sinks:
|
|
- pattern: exec(...)
|
|
- pattern: system(...)
|
|
- pattern: popen(...)
|
|
- pattern: passthru(...)
|
|
- pattern: shell_exec(...)
|
|
- pattern: pcntl_exec(...)
|
|
- pattern: proc_open(...)
|
|
pattern-sanitizers:
|
|
- pattern: escapeshellarg(...)
|
|
message: Executing non-constant commands. This can lead to command injection. You
|
|
should use `escapeshellarg()` when using command.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
references:
|
|
- https://www.stackhawk.com/blog/php-command-injection/
|
|
- https://brightsec.com/blog/code-injection-php/
|
|
- https://www.acunetix.com/websitesecurity/php-security-2/
|
|
category: security
|
|
technology:
|
|
- php
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/php.lang.security.tainted-exec.tainted-exec
|
|
shortlink: https://sg.run/JAkP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 73146
|
|
rv_id: 1263300
|
|
rule_id: 9AUw06
|
|
version_id: BjTkZ4y
|
|
url: https://semgrep.dev/playground/r/BjTkZ4y/php.lang.security.tainted-exec.tainted-exec
|
|
origin: community
|
|
languages:
|
|
- php
|
|
severity: ERROR
|
|
- id: php.lang.security.injection.tainted-session.tainted-session
|
|
severity: WARNING
|
|
message: Session key based on user input risks session poisoning. The user can determine
|
|
the key used for the session, and thus write any session variable. Session variables
|
|
are typically trusted to be set only by the application, and manipulating the
|
|
session can result in access control issues.
|
|
metadata:
|
|
technology:
|
|
- php
|
|
category: security
|
|
cwe:
|
|
- 'CWE-284: Improper Access Control'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://en.wikipedia.org/wiki/Session_poisoning
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/php.lang.security.injection.tainted-session.tainted-session
|
|
shortlink: https://sg.run/bxNp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 73470
|
|
rv_id: 1263289
|
|
rule_id: 4bUdoP
|
|
version_id: 8KT5rPE
|
|
url: https://semgrep.dev/playground/r/8KT5rPE/php.lang.security.injection.tainted-session.tainted-session
|
|
origin: community
|
|
languages:
|
|
- php
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
- pattern: $_COOKIE
|
|
- pattern: $_REQUEST
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $A . $B
|
|
- pattern: bin2hex(...)
|
|
- pattern: crc32(...)
|
|
- pattern: crypt(...)
|
|
- pattern: filter_input(...)
|
|
- pattern: filter_var(...)
|
|
- pattern: hash(...)
|
|
- pattern: md5(...)
|
|
- pattern: preg_filter(...)
|
|
- pattern: preg_grep(...)
|
|
- pattern: preg_match_all(...)
|
|
- pattern: sha1(...)
|
|
- pattern: sprintf(...)
|
|
- pattern: str_contains(...)
|
|
- pattern: str_ends_with(...)
|
|
- pattern: str_starts_with(...)
|
|
- pattern: strcasecmp(...)
|
|
- pattern: strchr(...)
|
|
- pattern: stripos(...)
|
|
- pattern: stristr(...)
|
|
- pattern: strnatcasecmp(...)
|
|
- pattern: strnatcmp(...)
|
|
- pattern: strncmp(...)
|
|
- pattern: strpbrk(...)
|
|
- pattern: strpos(...)
|
|
- pattern: strripos(...)
|
|
- pattern: strrpos(...)
|
|
- pattern: strspn(...)
|
|
- pattern: strstr(...)
|
|
- pattern: strtok(...)
|
|
- pattern: substr_compare(...)
|
|
- pattern: substr_count(...)
|
|
- pattern: vsprintf(...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-inside: $_SESSION[$KEY] = $VAL;
|
|
- pattern: $KEY
|
|
- id: yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions
|
|
patterns:
|
|
- pattern: |
|
|
"*"
|
|
- pattern-inside: |
|
|
resources: $A
|
|
...
|
|
- pattern-inside: |
|
|
verbs: $A
|
|
...
|
|
- pattern-inside: |
|
|
- apiGroups: [""]
|
|
...
|
|
- pattern-inside: |
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
...
|
|
- pattern-inside: |
|
|
kind: ClusterRole
|
|
...
|
|
message: 'Semgrep detected a Kubernetes core API ClusterRole with excessive permissions.
|
|
Attaching excessive permissions to a ClusterRole associated with the core namespace
|
|
allows the V1 API to perform arbitrary actions on arbitrary resources attached
|
|
to the cluster. Prefer explicit allowlists of verbs/resources when configuring
|
|
the core API namespace. '
|
|
languages:
|
|
- yaml
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-269: Improper Privilege Management'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A06:2017 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://kubernetes.io/docs/reference/access-authn-authz/rbac/#role-and-clusterrole
|
|
- https://kubernetes.io/docs/concepts/security/rbac-good-practices/#general-good-practice
|
|
- https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#api-groups
|
|
category: security
|
|
technology:
|
|
- kubernetes
|
|
cwe2021-top25: false
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions
|
|
shortlink: https://sg.run/x6Dz
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 73474
|
|
rv_id: 1263935
|
|
rule_id: GdUR2A
|
|
version_id: 9lT4bw7
|
|
url: https://semgrep.dev/playground/r/9lT4bw7/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions
|
|
origin: community
|
|
- id: python.fastapi.security.wildcard-cors.wildcard-cors
|
|
languages:
|
|
- python
|
|
message: CORS policy allows any origin (using wildcard '*'). This is insecure and
|
|
should be avoided.
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: '[..., "*", ...]'
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
$APP.add_middleware(
|
|
CORSMiddleware,
|
|
allow_origins=$ORIGIN,
|
|
...);
|
|
- focus-metavariable: $ORIGIN
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-942: Permissive Cross-domain Policy with Untrusted Domains'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
category: security
|
|
technology:
|
|
- python
|
|
- fastapi
|
|
references:
|
|
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
|
|
- https://cwe.mitre.org/data/definitions/942.html
|
|
likelihood: HIGH
|
|
impact: LOW
|
|
confidence: MEDIUM
|
|
vulnerability_class:
|
|
- Configuration
|
|
subcategory:
|
|
- vuln
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/python.fastapi.security.wildcard-cors.wildcard-cors
|
|
shortlink: https://sg.run/KxApY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 112311
|
|
rv_id: 1263413
|
|
rule_id: lBU4JQ3
|
|
version_id: A8Tgd1R
|
|
url: https://semgrep.dev/playground/r/A8Tgd1R/python.fastapi.security.wildcard-cors.wildcard-cors
|
|
origin: community
|
|
- id: javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify
|
|
message: Detected the decoding of a JWT token without a verify step. JWT tokens
|
|
must be verified before use, otherwise the token's integrity is unknown. This
|
|
means a malicious actor could forge a JWT token with any claims. Set 'verify'
|
|
to `true` before using the token.
|
|
severity: ERROR
|
|
metadata:
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A02:2025 - Security Misconfiguration
|
|
- A07:2025 - Authentication Failures
|
|
cwe:
|
|
- 'CWE-287: Improper Authentication'
|
|
- 'CWE-345: Insufficient Verification of Data Authenticity'
|
|
- 'CWE-347: Improper Verification of Cryptographic Signature'
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- jwt-simple
|
|
- jwt
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
references:
|
|
- https://www.npmjs.com/package/jwt-simple
|
|
- https://cwe.mitre.org/data/definitions/287
|
|
- https://cwe.mitre.org/data/definitions/345
|
|
- https://cwe.mitre.org/data/definitions/347
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify
|
|
shortlink: https://sg.run/zdjod
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 120561
|
|
rv_id: 1263191
|
|
rule_id: r6UyNLy
|
|
version_id: 3ZT4Xxv
|
|
url: https://semgrep.dev/playground/r/3ZT4Xxv/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
patterns:
|
|
- pattern-inside: |
|
|
$JWT = require('jwt-simple');
|
|
...
|
|
- pattern: $JWT.decode($TOKEN, $SECRET, $NOVERIFY, ...)
|
|
- metavariable-pattern:
|
|
metavariable: $NOVERIFY
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
true
|
|
- pattern: |
|
|
"..."
|
|
- id: php.lang.security.injection.printed-request.printed-request
|
|
mode: taint
|
|
message: '`Printing user input risks cross-site scripting vulnerability. You should
|
|
use `htmlentities()` when showing data to users.'
|
|
languages:
|
|
- php
|
|
severity: ERROR
|
|
pattern-sources:
|
|
- pattern: $_REQUEST
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
pattern-sinks:
|
|
- pattern: print($...VARS);
|
|
pattern-sanitizers:
|
|
- pattern: htmlentities(...)
|
|
- pattern: htmlspecialchars(...)
|
|
- pattern: strip_tags(...)
|
|
- pattern: isset(...)
|
|
- pattern: empty(...)
|
|
- pattern: esc_html(...)
|
|
- pattern: esc_attr(...)
|
|
- pattern: wp_kses(...)
|
|
- pattern: e(...)
|
|
- pattern: twig_escape_filter(...)
|
|
- pattern: xss_clean(...)
|
|
- pattern: html_escape(...)
|
|
- pattern: Html::escape(...)
|
|
- pattern: Xss::filter(...)
|
|
- pattern: escapeHtml(...)
|
|
- pattern: escapeHtml(...)
|
|
- pattern: escapeHtmlAttr(...)
|
|
fix: print(htmlentities($...VARS));
|
|
metadata:
|
|
technology:
|
|
- php
|
|
cwe:
|
|
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
|
|
Scripting'')'
|
|
owasp:
|
|
- A07:2017 - Cross-Site Scripting (XSS)
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
references:
|
|
- https://www.php.net/manual/en/function.htmlentities.php
|
|
- https://www.php.net/manual/en/reserved.variables.request.php
|
|
- https://www.php.net/manual/en/reserved.variables.post.php
|
|
- https://www.php.net/manual/en/reserved.variables.get.php
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cross-Site-Scripting (XSS)
|
|
source: https://semgrep.dev/r/php.lang.security.injection.printed-request.printed-request
|
|
shortlink: https://sg.run/QrxEJ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 128886
|
|
rv_id: 1263284
|
|
rule_id: KxUvRBw
|
|
version_id: ZRTKAk4
|
|
url: https://semgrep.dev/playground/r/ZRTKAk4/php.lang.security.injection.printed-request.printed-request
|
|
origin: community
|
|
- id: go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone
|
|
patterns:
|
|
- pattern-inside: |
|
|
&sessions.Options{
|
|
...,
|
|
SameSite: http.SameSiteNoneMode,
|
|
...,
|
|
}
|
|
- pattern: |
|
|
&sessions.Options{
|
|
...,
|
|
}
|
|
message: Found SameSiteNoneMode setting in Gorilla session options. Consider setting
|
|
SameSite to Lax, Strict or Default for enhanced security.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute'
|
|
owasp:
|
|
- A05:2021 - Security Misconfiguration
|
|
- A02:2025 - Security Misconfiguration
|
|
references:
|
|
- https://pkg.go.dev/github.com/gorilla/sessions#Options
|
|
category: security
|
|
technology:
|
|
- gorilla
|
|
confidence: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cookie Security
|
|
source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone
|
|
shortlink: https://sg.run/x8Nwj
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 133074
|
|
rv_id: 1262913
|
|
rule_id: YGUpGd4
|
|
version_id: K3TKkKB
|
|
url: https://semgrep.dev/playground/r/K3TKkKB/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone
|
|
origin: community
|
|
fix-regex:
|
|
regex: (SameSite\s*:\s+)http.SameSiteNoneMode
|
|
replacement: \1http.SameSiteDefaultMode
|
|
severity: WARNING
|
|
languages:
|
|
- go
|
|
- id: solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx
|
|
languages:
|
|
- solidity
|
|
message: Missing check for 'from' and 'to' being the same before updating balances
|
|
could lead to incorrect balance manipulation on self-transfers. Include a check
|
|
to ensure 'from' and 'to' are not the same before updating balances to prevent
|
|
balance manipulation during self-transfers.
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- blockchain
|
|
- solidity
|
|
cwe: 'CWE-682: Incorrect Calculation'
|
|
subcategory:
|
|
- vuln
|
|
confidence: HIGH
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
owasp:
|
|
- A7:2021 Identification and Authentication Failures
|
|
references:
|
|
- https://blog.verichains.io/p/miner-project-attacked-by-vulnerabilities
|
|
- https://x.com/shoucccc/status/1757777764646859121
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx
|
|
shortlink: https://sg.run/Or6X7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 133075
|
|
rv_id: 946620
|
|
rule_id: 6JUv7Nz
|
|
version_id: A8TJzYz
|
|
url: https://semgrep.dev/playground/r/A8TJzYz/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
_balances[$FROM] = $FROM_BALANCE - value;
|
|
- pattern: |
|
|
_balances[$TO] = $TO_BALANCE + value;
|
|
- pattern-not-inside: |
|
|
if ($FROM != $TO) {
|
|
...
|
|
_balances[$FROM] = $FROM_BALANCE - value;
|
|
...
|
|
_balances[$TO] = $TO_BALANCE + value;
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
function _update(address $FROM, address $TO, uint256 value, bool mint) internal virtual {
|
|
...
|
|
}
|
|
- id: yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication
|
|
languages:
|
|
- yaml
|
|
message: Basic authentication is considered weak and should be avoided. Use a different
|
|
authentication scheme, such of OAuth2, OpenID Connect, or mTLS.
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern-inside: |
|
|
openapi: $VERSION
|
|
...
|
|
components:
|
|
...
|
|
securitySchemes:
|
|
...
|
|
$SCHEME:
|
|
...
|
|
- metavariable-regex:
|
|
metavariable: $VERSION
|
|
regex: 3.*
|
|
- pattern: |
|
|
type: http
|
|
...
|
|
scheme: basic
|
|
metadata:
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- openapi
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
cwe: 'CWE-287: Improper Authentication'
|
|
owasp:
|
|
- A04:2021 Insecure Design
|
|
- A07:2021 Identification and Authentication Failures
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/287.html
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design/
|
|
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication
|
|
shortlink: https://sg.run/v8wNW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 133077
|
|
rv_id: 947072
|
|
rule_id: zdUKgEX
|
|
version_id: 0bT1ErG
|
|
url: https://semgrep.dev/playground/r/0bT1ErG/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication
|
|
origin: community
|
|
- id: python.twilio.security.twiml-injection.twiml-injection
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
message: Using non-constant TwiML (Twilio Markup Language) argument when creating
|
|
a Twilio conversation could allow the injection of additional TwiML commands
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-91: XML Injection'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- python
|
|
- twilio
|
|
- twiml
|
|
confidence: MEDIUM
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://codeberg.org/fennix/funjection
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/python.twilio.security.twiml-injection.twiml-injection
|
|
shortlink: https://sg.run/GdEEy
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 134692
|
|
rv_id: 1263580
|
|
rule_id: oqUgjj2
|
|
version_id: kbTzGp1
|
|
url: https://semgrep.dev/playground/r/kbTzGp1/python.twilio.security.twiml-injection.twiml-injection
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- pattern: |
|
|
f"..."
|
|
- pattern: |
|
|
"..." % ...
|
|
- pattern: |
|
|
"...".format(...)
|
|
- patterns:
|
|
- pattern: $ARG
|
|
- pattern-inside: |
|
|
def $F(..., $ARG, ...):
|
|
...
|
|
pattern-sanitizers:
|
|
- pattern: xml.sax.saxutils.escape(...)
|
|
- pattern: html.escape(...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: |
|
|
$CLIENT.calls.create(..., twiml=$SINK, ...)
|
|
- focus-metavariable: $SINK
|
|
- id: kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded
|
|
message: A secret is hard-coded in the application. Secrets stored in source code,
|
|
such as credentials, identifiers, and other types of sensitive data, can be leaked
|
|
and used by internal or external malicious actors. It is recommended to rotate
|
|
the secret and retrieve them from a secure secret vault or Hardware Security Module
|
|
(HSM), alternatively environment variables can be used if allowed by your company
|
|
policy.
|
|
severity: WARNING
|
|
metadata:
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
cwe:
|
|
- 'CWE-798: Use of Hard-coded Credentials'
|
|
cwe2020-top25: true
|
|
cwe2021-top25: true
|
|
cwe2022-top25: true
|
|
owasp:
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
references:
|
|
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
|
|
technology:
|
|
- secrets
|
|
vulnerability_class:
|
|
- Hard-coded Secrets
|
|
source_rule_url: https://semgrep.dev/playground/r/d8Ur5BA/achufistov6_personal_org.build-gradle-password-hardcoded
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded
|
|
shortlink: https://sg.run/qN29x
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 137856
|
|
rv_id: 1263257
|
|
rule_id: ReUD6Kg
|
|
version_id: DkTRbLX
|
|
url: https://semgrep.dev/playground/r/DkTRbLX/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded
|
|
origin: community
|
|
languages:
|
|
- kotlin
|
|
options:
|
|
symbolic_propagation: true
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: '$PASS = env[...] ?: $VALUE'
|
|
- metavariable-regex:
|
|
metavariable: $PASS
|
|
regex: (password|pass|passwd|loginPassword)
|
|
- metavariable-pattern:
|
|
language: generic
|
|
metavariable: $VALUE
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern-regex: ^[A-Za-z0-9/+=]+$
|
|
paths:
|
|
include:
|
|
- '*build.gradle.kts'
|
|
- id: php.lang.security.injection.tainted-callable.tainted-callable
|
|
severity: WARNING
|
|
message: Callable based on user input risks remote code execution.
|
|
metadata:
|
|
technology:
|
|
- php
|
|
category: security
|
|
cwe:
|
|
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://www.php.net/manual/en/language.types.callable.php
|
|
subcategory:
|
|
- vuln
|
|
impact: HIGH
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Code Injection
|
|
source: https://semgrep.dev/r/php.lang.security.injection.tainted-callable.tainted-callable
|
|
shortlink: https://sg.run/YGb33
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 141958
|
|
rv_id: 1263285
|
|
rule_id: 0oULBKK
|
|
version_id: nWT2L5x
|
|
url: https://semgrep.dev/playground/r/nWT2L5x/php.lang.security.injection.tainted-callable.tainted-callable
|
|
origin: community
|
|
languages:
|
|
- php
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
- pattern: $_COOKIE
|
|
- pattern: $_REQUEST
|
|
- pattern: file_get_contents('php://input')
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $CALLABLE
|
|
- pattern-either:
|
|
- pattern-inside: $ARRAYITERATOR->uasort($CALLABLE)
|
|
- pattern-inside: $ARRAYITERATOR->uksort($CALLABLE)
|
|
- pattern-inside: $EVENTHTTP->setCallback($CALLABLE, ...)
|
|
- pattern-inside: $EVENTHTTPCONNECTION->setCloseCallback($CALLABLE, ...)
|
|
- pattern-inside: $EVLOOP->fork($CALLABLE, ...)
|
|
- pattern-inside: $EVLOOP->idle($CALLABLE, ...)
|
|
- pattern-inside: $EVLOOP->prepare($CALLABLE, ...)
|
|
- pattern-inside: $EVWATCHER->setCallback($CALLABLE)
|
|
- pattern-inside: $GEARMANCLIENT->setClientCallback($CALLABLE)
|
|
- pattern-inside: $GEARMANCLIENT->setCompleteCallback($CALLABLE)
|
|
- pattern-inside: $GEARMANCLIENT->setCreatedCallback($CALLABLE)
|
|
- pattern-inside: $GEARMANCLIENT->setDataCallback($CALLABLE)
|
|
- pattern-inside: $GEARMANCLIENT->setExceptionCallback($CALLABLE)
|
|
- pattern-inside: $GEARMANCLIENT->setFailCallback($CALLABLE)
|
|
- pattern-inside: $GEARMANCLIENT->setStatusCallback($CALLABLE)
|
|
- pattern-inside: $GEARMANCLIENT->setWarningCallback($CALLABLE)
|
|
- pattern-inside: $GEARMANCLIENT->setWorkloadCallback($CALLABLE)
|
|
- pattern-inside: $IMAGICK->setProgressMonitor($CALLABLE)
|
|
- pattern-inside: $OAUTHPROVIDER->consumerHandler($CALLABLE)
|
|
- pattern-inside: $OAUTHPROVIDER->tokenHandler($CALLABLE)
|
|
- pattern-inside: $PDO->sqliteCreateCollation($NAME, $CALLABLE)
|
|
- pattern-inside: $PDOSTATEMENT->fetchAll(PDO::FETCH_FUNC, $CALLABLE)
|
|
- pattern-inside: $SQLITE3->createCollation($NAME, $CALLABLE)
|
|
- pattern-inside: $SQLITE3->setAuthorizer($CALLABLE)
|
|
- pattern-inside: $ZIPARCHIVE->registerCancelCallback($CALLABLE)
|
|
- pattern-inside: $ZIPARCHIVE->registerProgressCallback($RATE, $CALLABLE)
|
|
- pattern-inside: $ZMQDEVICE->setIdleCallback($CALLABLE, ...)
|
|
- pattern-inside: $ZMQDEVICE->setTimerCallback($CALLABLE, ...)
|
|
- pattern-inside: apcu_entry($KEY, $CALLABLE, ...)
|
|
- pattern-inside: array_filter($ARRAY, $CALLABLE, ...)
|
|
- pattern-inside: array_map($CALLABLE, ...)
|
|
- pattern-inside: array_reduce($ARRAY, $CALLABLE, ...)
|
|
- pattern-inside: array_walk_recursive($ARRAY, $CALLABLE, ...)
|
|
- pattern-inside: array_walk($ARRAY, $CALLABLE, ...)
|
|
- pattern-inside: call_user_func_array($CALLABLE, ...)
|
|
- pattern-inside: call_user_func($CALLABLE, ...)
|
|
- pattern-inside: Closure::fromCallable($CALLABLE)
|
|
- pattern-inside: createCollation($NAME, $CALLABLE)
|
|
- pattern-inside: eio_grp($CALLABLE, ...)
|
|
- pattern-inside: eio_nop($PRI, $CALLABLE, ...)
|
|
- pattern-inside: eio_sync($PRI, $CALLABLE, ...)
|
|
- pattern-inside: EvPrepare::createStopped($CALLABLE, ...)
|
|
- pattern-inside: fann_set_callback($ANN, $CALLABLE)
|
|
- pattern-inside: fdf_enum_values($FDF_DOCUMENT, $CALLABLE, ...)
|
|
- pattern-inside: forward_static_call_array($CALLABLE, ...)
|
|
- pattern-inside: forward_static_call($CALLABLE, ...)
|
|
- pattern-inside: header_register_callback($CALLABLE)
|
|
- pattern-inside: ibase_set_event_handler($CALLABLE, ...)
|
|
- pattern-inside: IntlChar::enumCharTypes($CALLABLE)
|
|
- pattern-inside: iterator_apply($ITERATOR, $CALLABLE)
|
|
- pattern-inside: ldap_set_rebind_proc($LDAP, $CALLABLE)
|
|
- pattern-inside: libxml_set_external_entity_loader($CALLABLE, ...)
|
|
- pattern-inside: new CallbackFilterIterator($ITERATOR, $CALLABLE)
|
|
- pattern-inside: new EvCheck($CALLABLE, ...)
|
|
- pattern-inside: new EventHttpRequest($CALLABLE, ...)
|
|
- pattern-inside: new EvFork($CALLABLE, ...)
|
|
- pattern-inside: new EvIdle($CALLABLE, ...)
|
|
- pattern-inside: new Fiber($CALLABLE)
|
|
- pattern-inside: new Memcached($PERSISTENT_ID, $CALLABLE, ...)
|
|
- pattern-inside: new RecursiveCallbackFilterIterator($ITERATOR, $CALLABLE)
|
|
- pattern-inside: new Zookeeper($HOST, $CALLABLE, ...)
|
|
- pattern-inside: ob_start($CALLABLE, ...)
|
|
- pattern-inside: oci_register_taf_callback($CONNECTION, $CALLABLE)
|
|
- pattern-inside: readline_callback_handler_install($PROMPT, $CALLABLE)
|
|
- pattern-inside: readline_completion_function($CALLABLE)
|
|
- pattern-inside: register_shutdown_function($CALLABLE, ...)
|
|
- pattern-inside: register_tick_function($CALLABLE, ...)
|
|
- pattern-inside: rnp_ffi_set_pass_provider($FFI, $CALLABLE)
|
|
- pattern-inside: sapi_windows_set_ctrl_handler($CALLABLE, ...)
|
|
- pattern-inside: set_error_handler($CALLABLE, ...)
|
|
- pattern-inside: set_exception_handler($CALLABLE)
|
|
- pattern-inside: setAuthorizer($CALLABLE)
|
|
- pattern-inside: spl_autoload_register($CALLABLE, ...)
|
|
- pattern-inside: uasort($ARRAY, $CALLABLE)
|
|
- pattern-inside: uksort($ARRAY, $CALLABLE)
|
|
- pattern-inside: usort($ARRAY, $CALLABLE)
|
|
- pattern-inside: xml_set_character_data_handler($PARSER, $CALLABLE)
|
|
- pattern-inside: xml_set_default_handler($PARSER, $CALLABLE)
|
|
- pattern-inside: xml_set_element_handler($PARSER, $CALLABLE, $CALLABLE)
|
|
- pattern-inside: xml_set_notation_decl_handler($PARSER, $CALLABLE)
|
|
- pattern-inside: Yar_Concurrent_Client::loop($CALLABLE, ...)
|
|
- id: javascript.node-crypto.security.aead-no-final.aead-no-final
|
|
message: The 'final' call of a Decipher object checks the authentication tag in
|
|
a mode for authenticated encryption. Failing to call 'final' will invalidate all
|
|
integrity guarantees of the released ciphertext.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-310: CWE CATEGORY: Cryptographic Issues'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- node-crypto
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
references:
|
|
- https://nodejs.org/api/crypto.html#deciphersetauthtagbuffer-encoding
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures/
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.node-crypto.security.aead-no-final.aead-no-final
|
|
shortlink: https://sg.run/r6EEA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 146569
|
|
rv_id: 1263222
|
|
rule_id: 2ZUz884
|
|
version_id: zyTb2X0
|
|
url: https://semgrep.dev/playground/r/zyTb2X0/javascript.node-crypto.security.aead-no-final.aead-no-final
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern: |
|
|
$DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...)
|
|
...
|
|
$DECIPHER.update(...)
|
|
- pattern-not-inside: |
|
|
$DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...)
|
|
...
|
|
$DECIPHER.final(...)
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: .*(-gcm|-ccm|-ocb|chacha20-poly1305)$
|
|
- id: javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length
|
|
message: The call to 'createDecipheriv' with the Galois Counter Mode (GCM) mode
|
|
of operation is missing an expected authentication tag length. If the expected
|
|
authentication tag length is not specified or otherwise checked, the application
|
|
might be tricked into verifying a shorter-than-expected authentication tag. This
|
|
can be abused by an attacker to spoof ciphertexts or recover the implicit authentication
|
|
key of GCM, allowing arbitrary forgeries.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-310: CWE CATEGORY: Cryptographic Issues'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
category: security
|
|
subcategory:
|
|
- vuln
|
|
technology:
|
|
- node-crypto
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://www.securesystems.de/blog/forging_ciphertexts_under_Galois_Counter_Mode_for_the_Node_js_crypto_module/
|
|
- https://nodejs.org/api/crypto.html#cryptocreatedecipherivalgorithm-key-iv-options
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures/
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length
|
|
shortlink: https://sg.run/NbGG1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 146571
|
|
rv_id: 1263223
|
|
rule_id: j2UgPP3
|
|
version_id: pZT03qd
|
|
url: https://semgrep.dev/playground/r/pZT03qd/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length
|
|
origin: community
|
|
languages:
|
|
- javascript
|
|
- typescript
|
|
severity: ERROR
|
|
patterns:
|
|
- pattern: |
|
|
$CRYPTO.createDecipheriv('$ALGO', $KEY, $IV)
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: .*(-gcm)$
|
|
- id: php.lang.security.injection.tainted-exec.tainted-exec
|
|
languages:
|
|
- php
|
|
severity: WARNING
|
|
message: User input is passed to a function that executes a shell command. This
|
|
can lead to remote code execution.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
category: security
|
|
technology:
|
|
- php
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
subcategory:
|
|
- vuln
|
|
impact: HIGH
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/php.lang.security.injection.tainted-exec.tainted-exec
|
|
shortlink: https://sg.run/kxEEz
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 146572
|
|
rv_id: 1263286
|
|
rule_id: 10UOGG5
|
|
version_id: ExTExyR
|
|
url: https://semgrep.dev/playground/r/ExTExyR/php.lang.security.injection.tainted-exec.tainted-exec
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
- pattern: $_COOKIE
|
|
- pattern: $_REQUEST
|
|
- pattern: file_get_contents('php://input')
|
|
pattern-sanitizers:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: escapeshellcmd(...)
|
|
- pattern: escapeshellarg(...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: exec(...)
|
|
- pattern: system(...)
|
|
- pattern: passthru(...)
|
|
- patterns:
|
|
- pattern: proc_open(...)
|
|
- pattern-not: proc_open([...], ...)
|
|
- pattern: popen(...)
|
|
- pattern: expect_popen(...)
|
|
- pattern: shell_exec(...)
|
|
- pattern: |
|
|
`...`
|
|
- id: yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false
|
|
languages:
|
|
- yaml
|
|
message: 'Found ''x-openai-isConsequential: false'' in a state-changing HTTP method:
|
|
$METHOD $PATH. This Action configuration will enable the ''Always Allow'' option
|
|
for state-changing HTTP methods, such as POST, PUT, PATCH, or DELETE. The risk
|
|
of a user selecting the ''Always Allow'' button is that the agent could perform
|
|
unintended actions on behalf of the user. When working with sensitive functionality,
|
|
it is always best to include a Human In The Loop (HITL) type of control. Consider
|
|
the trade-off between security and user friction and then make a risk-based decision
|
|
about this function.'
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern-inside: |
|
|
post:
|
|
...
|
|
x-openai-isConsequential: false
|
|
- pattern-inside: |
|
|
put:
|
|
...
|
|
x-openai-isConsequential: false
|
|
- pattern-inside: |
|
|
patch:
|
|
...
|
|
x-openai-isConsequential: false
|
|
- pattern-inside: |
|
|
delete:
|
|
...
|
|
x-openai-isConsequential: false
|
|
metadata:
|
|
category: security
|
|
subcategory:
|
|
- audit
|
|
technology:
|
|
- openapi
|
|
- openai
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
cwe: 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')'
|
|
owasp:
|
|
- A04:2021 Insecure Design
|
|
- LLM08:2023 - Excessive Agency
|
|
references:
|
|
- https://platform.openai.com/docs/actions/consequential-flag
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design/
|
|
- https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false
|
|
shortlink: https://sg.run/x8EEP
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 146574
|
|
rv_id: 947071
|
|
rule_id: yyURooD
|
|
version_id: WrTEZN8
|
|
url: https://semgrep.dev/playground/r/WrTEZN8/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false
|
|
origin: community
|
|
- id: python.lang.security.insecure-uuid-version.insecure-uuid-version
|
|
patterns:
|
|
- pattern: uuid.uuid1(...)
|
|
message: Using UUID version 1 for UUID generation can lead to predictable UUIDs
|
|
based on system information (e.g., MAC address, timestamp). This may lead to security
|
|
risks such as the sandwich attack. Consider using `uuid.uuid4()` instead for better
|
|
randomness and security.
|
|
metadata:
|
|
references:
|
|
- https://www.landh.tech/blog/20230811-sandwich-attack/
|
|
cwe:
|
|
- 'CWE-330: Use of Insufficiently Random Values'
|
|
owasp:
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.3.2 Insecure UUID Generation
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v63-random-values
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- python
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.lang.security.insecure-uuid-version.insecure-uuid-version
|
|
shortlink: https://sg.run/BYBgW
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 148295
|
|
rv_id: 1263539
|
|
rule_id: kxUd1yD
|
|
version_id: O9Tpx97
|
|
url: https://semgrep.dev/playground/r/O9Tpx97/python.lang.security.insecure-uuid-version.insecure-uuid-version
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
fix-regex:
|
|
regex: uuid1
|
|
replacement: uuid4
|
|
- id: go.lang.security.audit.crypto.sha224-hash.sha224-hash
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import "crypto/sha256"
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
sha256.New224()
|
|
- pattern: |
|
|
sha256.Sum224(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
import "golang.org/x/crypto/sha3"
|
|
...
|
|
- pattern-either:
|
|
- pattern: |
|
|
sha3.New224()
|
|
- pattern: |
|
|
sha3.Sum224(...)
|
|
message: This code uses a 224-bit hash function, which is deprecated or disallowed
|
|
in some security policies. Consider updating to a stronger hash function such
|
|
as SHA-384 or higher to ensure compliance and security.
|
|
languages:
|
|
- go
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
category: security
|
|
technology:
|
|
- go
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
|
|
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/go.lang.security.audit.crypto.sha224-hash.sha224-hash
|
|
shortlink: https://sg.run/ReJwY
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 151749
|
|
rv_id: 1262925
|
|
rule_id: GdUvElR
|
|
version_id: 9lT4b4w
|
|
url: https://semgrep.dev/playground/r/9lT4b4w/go.lang.security.audit.crypto.sha224-hash.sha224-hash
|
|
origin: community
|
|
- id: java.lang.security.audit.crypto.use-of-sha224.use-of-sha224
|
|
message: This code uses a 224-bit hash function, which is deprecated or disallowed
|
|
in some security policies. Consider updating to a stronger hash function such
|
|
as SHA-384 or higher to ensure compliance and security.
|
|
languages:
|
|
- java
|
|
severity: WARNING
|
|
metadata:
|
|
functional-categories:
|
|
- crypto::search::hash-algorithm::javax.crypto
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- java
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
|
|
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224
|
|
shortlink: https://sg.run/Ab2KQ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 151750
|
|
rv_id: 1263017
|
|
rule_id: ReUDGEz
|
|
version_id: YDTZewo
|
|
url: https://semgrep.dev/playground/r/YDTZewo/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.getSha3_224Digest()
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.getSha512_224Digest()
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224(...)
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224Hex(...)
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224(...)
|
|
- pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224Hex(...)
|
|
- pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_224)
|
|
- pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_512_224)
|
|
- pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA3_224)
|
|
- patterns:
|
|
- pattern: java.security.MessageDigest.getInstance("$ALGO", ...);
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: .*224
|
|
- id: php.lang.security.audit.sha224-hash.sha224-hash
|
|
pattern-either:
|
|
- pattern: hash('sha224', ...);
|
|
- pattern: hash('sha512/224', ...);
|
|
- pattern: hash('sha3-224', ...);
|
|
- pattern: hash_hmac('sha224', ...);
|
|
- pattern: hash_hmac('sha512/224', ...);
|
|
- pattern: hash_hmac('sha3-224', ...);
|
|
message: This code uses a 224-bit hash function, which is deprecated or disallowed
|
|
in some security policies. Consider updating to a stronger hash function such
|
|
as SHA-384 or higher to ensure compliance and security.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
|
|
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
|
|
category: security
|
|
technology:
|
|
- php
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/php.lang.security.audit.sha224-hash.sha224-hash
|
|
shortlink: https://sg.run/BYXqv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 151751
|
|
rv_id: 1263275
|
|
rule_id: AbU97EA
|
|
version_id: bZT53Jo
|
|
url: https://semgrep.dev/playground/r/bZT53Jo/php.lang.security.audit.sha224-hash.sha224-hash
|
|
origin: community
|
|
languages:
|
|
- php
|
|
severity: WARNING
|
|
- id: python.lang.security.audit.sha224-hash.sha224-hash
|
|
message: This code uses a 224-bit hash function, which is deprecated or disallowed
|
|
in some security policies. Consider updating to a stronger hash function such
|
|
as SHA-384 or higher to ensure compliance and security.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
|
|
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
|
|
category: security
|
|
technology:
|
|
- python
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/python.lang.security.audit.sha224-hash.sha224-hash
|
|
shortlink: https://sg.run/Db1Yv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 151752
|
|
rv_id: 1263511
|
|
rule_id: BYUX0y9
|
|
version_id: 5PTo1QL
|
|
url: https://semgrep.dev/playground/r/5PTo1QL/python.lang.security.audit.sha224-hash.sha224-hash
|
|
origin: community
|
|
severity: WARNING
|
|
languages:
|
|
- python
|
|
pattern-either:
|
|
- pattern: hashlib.sha224(...)
|
|
- pattern: hashlib.sha3_224(...)
|
|
- id: ruby.lang.security.audit.sha224-hash.sha224-hash
|
|
message: This code uses a 224-bit hash function, which is deprecated or disallowed
|
|
in some security policies. Consider updating to a stronger hash function such
|
|
as SHA-384 or higher to ensure compliance and security.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-328: Use of Weak Hash'
|
|
references:
|
|
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
|
|
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
|
|
category: security
|
|
technology:
|
|
- ruby
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Insecure Hashing Algorithm
|
|
source: https://semgrep.dev/r/ruby.lang.security.audit.sha224-hash.sha224-hash
|
|
shortlink: https://sg.run/WABbo
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 151753
|
|
rv_id: 1263592
|
|
rule_id: DbU60wQ
|
|
version_id: 8KT5rRY
|
|
url: https://semgrep.dev/playground/r/8KT5rRY/ruby.lang.security.audit.sha224-hash.sha224-hash
|
|
origin: community
|
|
languages:
|
|
- ruby
|
|
severity: WARNING
|
|
pattern-either:
|
|
- pattern: Digest::SHA224.$FUNC
|
|
- pattern: OpenSSL::Digest::SHA224.$FUNC
|
|
- pattern: SHA3::Digest::SHA224(...)
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: OpenSSL::HMAC.hexdigest("$ALGO", ...)
|
|
- pattern: OpenSSL::HMAC.digest("$ALGO", ...)
|
|
- pattern: OpenSSL::HMAC.new($KEY, "$ALGO")
|
|
- pattern: OpenSSL::Digest.digest("$ALGO", ...)
|
|
- pattern: OpenSSL::Digest.new("$ALGO", ...)
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: .*224
|
|
- id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql
|
|
patterns:
|
|
- pattern-inside: |
|
|
resource "google_sql_database_instance" "..." {
|
|
...
|
|
database_version = "$DB"
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "google_sql_database_instance" "..." {
|
|
...
|
|
ip_configuration {
|
|
...
|
|
ssl_mode = $VALUE
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "google_sql_database_instance" "..." {
|
|
...
|
|
ip_configuration {
|
|
...
|
|
ssl_mode = "TRUSTED_CLIENT_CERTIFICATE_REQUIRED"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $DB
|
|
regex: .*(MYSQL|POSTGRES).*
|
|
- focus-metavariable: $VALUE
|
|
fix: |
|
|
"TRUSTED_CLIENT_CERTIFICATE_REQUIRED"
|
|
message: Ensure all Cloud SQL database instance require incoming connections to
|
|
use SSL. To enable this for PostgresSQL and MySQL, use `ssl_mode="TRUSTED_CLIENT_CERTIFICATE_REQUIRED"`.
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- gcp
|
|
references:
|
|
- https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql
|
|
shortlink: https://sg.run/WANR2
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 153509
|
|
rv_id: 1263874
|
|
rule_id: 5rUdGAz
|
|
version_id: 2KTv22E
|
|
url: https://semgrep.dev/playground/r/2KTv22E/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver
|
|
patterns:
|
|
- pattern-inside: |
|
|
resource "google_sql_database_instance" "..." {
|
|
...
|
|
database_version = "$DB"
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "google_sql_database_instance" "..." {
|
|
...
|
|
ip_configuration {
|
|
...
|
|
ssl_mode = $VALUE
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-not-inside: |
|
|
resource "google_sql_database_instance" "..." {
|
|
...
|
|
ip_configuration {
|
|
...
|
|
ssl_mode = "ENCRYPTED_ONLY"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $DB
|
|
regex: .*(SQLSERVER).*
|
|
- focus-metavariable: $VALUE
|
|
fix: |
|
|
"ENCRYPTED_ONLY"
|
|
message: Ensure all Cloud SQL database instance require incoming connections to
|
|
use SSL. For SQL Server, `ssl_mode="ENCRYPTED_ONLY"` is the most secure value
|
|
that is supported.
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- gcp
|
|
references:
|
|
- https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver
|
|
shortlink: https://sg.run/0o92j
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 153510
|
|
rv_id: 1263875
|
|
rule_id: GdUvX6A
|
|
version_id: X0Tzyyl
|
|
url: https://semgrep.dev/playground/r/X0Tzyyl/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true
|
|
message: Function `flask.url_for` with `_external=True` argument will generate URLs
|
|
using the `Host` header of the HTTP request, which may lead to security risks
|
|
such as Host header injection
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-673: External Influence of Sphere Definition'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- flask
|
|
references:
|
|
- https://flask.palletsprojects.com/en/latest/api/#flask.url_for
|
|
- https://portswigger.net/kb/issues/00500300_host-header-injection
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: LOW
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Other
|
|
source: https://semgrep.dev/r/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true
|
|
shortlink: https://sg.run/gEGeR
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 191541
|
|
rv_id: 1263418
|
|
rule_id: JDU5oql
|
|
version_id: K3TKk6n
|
|
url: https://semgrep.dev/playground/r/K3TKk6n/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true
|
|
origin: community
|
|
languages:
|
|
- python
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-not: flask.url_for(..., _external=False, ...)
|
|
- pattern-not: url_for(..., _external=False, ...)
|
|
- pattern-either:
|
|
- pattern: flask.url_for(..., _external=$VAR, ...)
|
|
- pattern: url_for(..., _external=$VAR, ...)
|
|
- id: php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit
|
|
languages:
|
|
- php
|
|
severity: WARNING
|
|
message: Detected usage of vulnerable functions with user input, which could lead
|
|
to SSRF vulnerabilities.
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $_GET[...]
|
|
- pattern: $_POST[...]
|
|
- pattern: $_REQUEST[...]
|
|
- pattern: get_option(...)
|
|
- pattern: get_user_meta(...)
|
|
- pattern: get_query_var(...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- focus-metavariable: $URL
|
|
- pattern-either:
|
|
- pattern: wp_remote_get($URL, ...)
|
|
- pattern: wp_safe_remote_get($URL, ...)
|
|
- pattern: wp_safe_remote_request($URL, ...)
|
|
- pattern: wp_safe_remote_head($URL, ...)
|
|
- pattern: wp_oembed_get($URL, ...)
|
|
- pattern: vip_safe_wp_remote_get($URL, ...)
|
|
- pattern: wp_safe_remote_post($URL, ...)
|
|
paths:
|
|
include:
|
|
- '**/wp-content/plugins/**/*.php'
|
|
metadata:
|
|
cwe: 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
owasp: A10:2021 - Server-Side Request Forgery (SSRF)
|
|
category: security
|
|
confidence: MEDIUM
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
technology:
|
|
- Wordpress Plugins
|
|
references:
|
|
- https://developer.wordpress.org/reference/functions/wp_safe_remote_get/
|
|
- https://developer.wordpress.org/reference/functions/wp_remote_get/
|
|
- https://patchstack.com/articles/exploring-the-unpatched-wordpress-ssrf/
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit
|
|
shortlink: https://sg.run/K3y06
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 191611
|
|
rv_id: 1039233
|
|
rule_id: 6JUZyKX
|
|
version_id: JdTp6rq
|
|
url: https://semgrep.dev/playground/r/JdTp6rq/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit
|
|
origin: community
|
|
- id: yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor
|
|
languages:
|
|
- yaml
|
|
message: The Shai-hulud backdoor creates a purposefully vulnerable github action
|
|
with the name `discussion.yaml`.
|
|
paths:
|
|
include:
|
|
- '**/.github/workflows/discussion.yaml'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-509: Replicating Malicious Code (Virus or Worm)'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
technology:
|
|
- github-actions
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source_rule_url: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack
|
|
references:
|
|
- https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor
|
|
shortlink: https://sg.run/JdYPZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 238946
|
|
rv_id: 1263927
|
|
rule_id: 7KUDRPj
|
|
version_id: 6xT29ol
|
|
url: https://semgrep.dev/playground/r/6xT29ol/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: 'steps: [...]'
|
|
- pattern-inside: |
|
|
- run: ...
|
|
...
|
|
- pattern: 'run: $SHELL'
|
|
- metavariable-pattern:
|
|
language: generic
|
|
metavariable: $SHELL
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: ${{ github.event.issue.title }}
|
|
- pattern: ${{ github.event.issue.body }}
|
|
- pattern: ${{ github.event.pull_request.title }}
|
|
- pattern: ${{ github.event.pull_request.body }}
|
|
- pattern: ${{ github.event.comment.body }}
|
|
- pattern: ${{ github.event.review.body }}
|
|
- pattern: ${{ github.event.review_comment.body }}
|
|
- pattern: ${{ github.event.pages. ... .page_name}}
|
|
- pattern: ${{ github.event.head_commit.message }}
|
|
- pattern: ${{ github.event.head_commit.author.email }}
|
|
- pattern: ${{ github.event.head_commit.author.name }}
|
|
- pattern: ${{ github.event.commits ... .author.email }}
|
|
- pattern: ${{ github.event.commits ... .author.name }}
|
|
- pattern: ${{ github.event.pull_request.head.ref }}
|
|
- pattern: ${{ github.event.pull_request.head.label }}
|
|
- pattern: ${{ github.event.pull_request.head.repo.default_branch }}
|
|
- pattern: ${{ github.head_ref }}
|
|
- pattern: ${{ github.event.inputs ... }}
|
|
- pattern: ${{ github.event.discussion.title }}
|
|
- pattern: ${{ github.event.discussion.body }}
|
|
- pattern: ${{ inputs ... }}
|
|
severity: ERROR
|
|
- id: go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface
|
|
languages:
|
|
- go
|
|
message: Deserializing into `interface{}` allows arbitrary data structures and types,
|
|
which can lead to security vulnerabilities (CWE-502). Use a concrete struct type
|
|
instead.
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-502: Deserialization of Untrusted Data'
|
|
owasp:
|
|
- A08:2017 - Insecure Deserialization
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
category: security
|
|
technology:
|
|
- go
|
|
confidence: HIGH
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
subcategory:
|
|
- vuln
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/502.html
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- 'Insecure Deserialization '
|
|
source: https://semgrep.dev/r/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface
|
|
shortlink: https://sg.run/6WbKL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 274359
|
|
rv_id: 1409387
|
|
rule_id: 4bUAQDG
|
|
version_id: ZRTDkjk
|
|
url: https://semgrep.dev/playground/r/ZRTDkjk/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
var $VAR interface{}
|
|
...
|
|
json.Unmarshal($DATA, &$VAR)
|
|
- pattern: |
|
|
var $VAR interface{}
|
|
...
|
|
yaml.Unmarshal($DATA, &$VAR)
|
|
- pattern: |
|
|
var $VAR interface{}
|
|
...
|
|
xml.Unmarshal($DATA, &$VAR)
|
|
- id: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
|
|
message: "GitHub Actions step uses a mutable tag or branch reference. Tags and branch
|
|
names can be silently repointed by the action owner, enabling supply-chain attacks
|
|
\u2014 as seen in the trivy-action and kics-github-action compromises. Pin the
|
|
reference to a full 40-character commit SHA instead, e.g. `uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`."
|
|
severity: WARNING
|
|
languages:
|
|
- yaml
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-1357: Reliance on Insufficiently Trustworthy Component'
|
|
- 'CWE-353: Missing Support for Integrity Check'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
- A08:2025 - Software and Data Integrity Failures
|
|
references:
|
|
- https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions
|
|
technology:
|
|
- github-actions
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
- Other
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
|
|
shortlink: https://sg.run/2LgAL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 288863
|
|
rv_id: 1413422
|
|
rule_id: GdUxYDx
|
|
version_id: xyTRDAd
|
|
url: https://semgrep.dev/playground/r/xyTRDAd/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: '{steps: ...}'
|
|
- pattern: |
|
|
uses: "$ACTION"
|
|
- metavariable-pattern:
|
|
metavariable: $ACTION
|
|
language: generic
|
|
patterns:
|
|
- pattern-not-regex: ^\./
|
|
- pattern-not-regex: ^docker://
|
|
- pattern-not-regex: '@[0-9a-f]{40}(\s|$)'
|
|
- id: yaml.github-actions.security.secrets-inherit.secrets-inherit
|
|
languages:
|
|
- yaml
|
|
severity: ERROR
|
|
message: 'This workflow uses `secrets: inherit` to pass all of the calling workflow''s
|
|
secrets to a reusable workflow. This violates the principle of least privilege
|
|
because the called workflow receives access to every secret in the repository,
|
|
not just the ones it needs. If the called workflow is compromised or sourced from
|
|
a third party, an attacker gains access to all repository secrets. Instead, explicitly
|
|
pass only the secrets that the called workflow requires using the `secrets:` map,
|
|
e.g. `secrets: { MY_SECRET: ${{ secrets.MY_SECRET }} }`.'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-250: Execution with Unnecessary Privileges'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://docs.github.com/en/actions/sharing-automations/reusing-workflows#passing-inputs-and-secrets-to-a-reusable-workflow
|
|
- https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions
|
|
technology:
|
|
- github-actions
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.secrets-inherit.secrets-inherit
|
|
shortlink: https://sg.run/X2PZB
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 288864
|
|
rv_id: 1413424
|
|
rule_id: ReUQnKg
|
|
version_id: e1T42L1
|
|
url: https://semgrep.dev/playground/r/e1T42L1/yaml.github-actions.security.secrets-inherit.secrets-inherit
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
jobs:
|
|
...
|
|
- pattern: 'secrets: inherit'
|
|
- id: package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)\[install\](?P<TARGET>[^\[]*?)(?=\[|\z)
|
|
- metavariable-regex:
|
|
metavariable: $TARGET
|
|
regex: ^(?![\s\S]*minimumReleaseAge)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern-regex: minimumReleaseAge\s*=\s*\d+
|
|
- pattern-regex: =\s*(?P<AGE>\d+)
|
|
- metavariable-comparison:
|
|
metavariable: $AGE
|
|
comparison: int($AGE) < 604800
|
|
- focus-metavariable: $AGE
|
|
- patterns:
|
|
- pattern-regex: (?m)minimumReleaseAge[ \t]*=[ \t]*(?P<VAL>[^\s\d][^\n]*)
|
|
- focus-metavariable: $VAL
|
|
- patterns:
|
|
- pattern-regex: (?m)minimumReleaseAge\s*=\s*$
|
|
message: 'This bunfig.toml does not set a minimum release age or sets it too low.
|
|
Newly published packages can be malicious or unstable. Add `minimumReleaseAge
|
|
= 604800` under the `[install]` section to wait 7 days before resolving newly
|
|
published package versions. Added in: v1.3 Reference: https://bun.sh/docs/runtime/bunfig'
|
|
languages:
|
|
- generic
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/bunfig.toml'
|
|
- '**/.bunfig.toml'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- bun
|
|
- javascript
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://bun.sh/docs/runtime/bunfig
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age
|
|
shortlink: https://sg.run/JqPrR
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291646
|
|
rv_id: 1423385
|
|
rule_id: oqUyJOb
|
|
version_id: BjTyRe5
|
|
url: https://semgrep.dev/playground/r/BjTyRe5/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age
|
|
origin: community
|
|
- id: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
updates:
|
|
...
|
|
- pattern: |
|
|
- package-ecosystem: $ECOSYSTEM
|
|
...
|
|
- pattern-not: |
|
|
- package-ecosystem: $ECOSYSTEM
|
|
...
|
|
cooldown:
|
|
...
|
|
...
|
|
- patterns:
|
|
- pattern-inside: |
|
|
updates:
|
|
...
|
|
- pattern-regex: default-days\s*:\s*(?P<DAYS>\d+)
|
|
- metavariable-comparison:
|
|
metavariable: $DAYS
|
|
comparison: int($DAYS) < 7
|
|
- focus-metavariable: $DAYS
|
|
- patterns:
|
|
- pattern-inside: |
|
|
updates:
|
|
...
|
|
- pattern: |
|
|
cooldown:
|
|
default-days: $DAYS
|
|
- metavariable-regex:
|
|
metavariable: $DAYS
|
|
regex: ^\D
|
|
- focus-metavariable: $DAYS
|
|
message: 'This Dependabot configuration does not set a cooldown period. Newly published
|
|
packages can be malicious or unstable. Add a `cooldown` block with `default-days:
|
|
7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing
|
|
updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown'
|
|
languages:
|
|
- yaml
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/.github/dependabot.yml'
|
|
- '**/.github/dependabot.yaml'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- dependabot
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown
|
|
shortlink: https://sg.run/5WvGK
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291647
|
|
rv_id: 1423386
|
|
rule_id: zdUArOL
|
|
version_id: DkTwEGl
|
|
url: https://semgrep.dev/playground/r/DkTwEGl/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown
|
|
origin: community
|
|
- id: package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?:(?:^---\n)(?:[^\n]*\n)|^)(?P<TARGET>(?:(?!\n---)[\s\S])*\S(?:(?!\n---)[\s\S])*)
|
|
- pattern-not-regex: min-release-age
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern-regex: min-release-age\s*=\s*\d+
|
|
- pattern-regex: =\s*(?P<AGE>\d+)
|
|
- metavariable-comparison:
|
|
metavariable: $AGE
|
|
comparison: int($AGE) < 7
|
|
- focus-metavariable: $AGE
|
|
- patterns:
|
|
- pattern-regex: (?m)min-release-age[ \t]*=[ \t]*(?P<VAL>[^\s\d][^\n]*)
|
|
- focus-metavariable: $VAL
|
|
- patterns:
|
|
- pattern-regex: (?m)min-release-age\s*=\s*$
|
|
message: 'This .npmrc does not set a minimum release age or sets it too low. Newly
|
|
published packages can be malicious or unstable. Add `min-release-age = 7` to
|
|
wait 7 days before resolving newly published package versions. Added in: v11.10
|
|
Reference: https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/'
|
|
languages:
|
|
- generic
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/.npmrc'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- npm
|
|
- javascript
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/
|
|
- https://github.com/npm/cli/pull/8965
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age
|
|
shortlink: https://sg.run/GRo1z
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291648
|
|
rv_id: 1423387
|
|
rule_id: pKU6A82
|
|
version_id: WrT7LdL
|
|
url: https://semgrep.dev/playground/r/WrT7LdL/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age
|
|
origin: community
|
|
- id: package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies
|
|
message: 'Missing or incorrect blockExoticSubdeps. Set `blockExoticSubdeps: true`
|
|
to transitive dependencies from being installed from untrusted sources. Added
|
|
in: v10.26.0 Reference: https://pnpm.io/settings#blockexoticsubdeps'
|
|
languages:
|
|
- yaml
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/pnpm-workspace.yaml'
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:packages|catalog)\s*:)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern: |
|
|
blockExoticSubdeps: $VAL
|
|
- metavariable-regex:
|
|
metavariable: $VAL
|
|
regex: ^(?!true$).+
|
|
- focus-metavariable: $VAL
|
|
- patterns:
|
|
- pattern-regex: (?m)^\s*blockExoticSubdeps\s*:\s*$
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- pnpm
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://pnpm.io/settings#blockexoticsubdeps
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies
|
|
shortlink: https://sg.run/RrWRv
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291649
|
|
rv_id: 1423388
|
|
rule_id: 2ZUQEZ5
|
|
version_id: 0bTGnwj
|
|
url: https://semgrep.dev/playground/r/0bTGnwj/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies
|
|
origin: community
|
|
- id: package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age
|
|
message: 'This pnpm workspace configuration does not set a minimum release age.
|
|
Newly published packages can be malicious or unstable. Add `minimumReleaseAge:
|
|
10080` (minutes) to wait at least seven days before installing newly published
|
|
package versions. Added in: v10.16.0 Reference: https://pnpm.io/settings#minimumreleaseage'
|
|
languages:
|
|
- yaml
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/pnpm-workspace.yaml'
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:packages|catalog)\s*:)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern-regex: ^\s*minimumReleaseAge\s*:\s*(?P<AGE>\d+)
|
|
- metavariable-comparison:
|
|
metavariable: $AGE
|
|
comparison: int($AGE) < 10080
|
|
- focus-metavariable: $AGE
|
|
- patterns:
|
|
- pattern: |
|
|
minimumReleaseAge: $AGE
|
|
- metavariable-regex:
|
|
metavariable: $AGE
|
|
regex: ^\D
|
|
- focus-metavariable: $AGE
|
|
- patterns:
|
|
- pattern-regex: (?m)^\s*minimumReleaseAge\s*:\s*$
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- pnpm
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://pnpm.io/settings#minimumreleaseage
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age
|
|
shortlink: https://sg.run/Aj0o0
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291650
|
|
rv_id: 1423389
|
|
rule_id: X5Uwn1n
|
|
version_id: K3TgxrW
|
|
url: https://semgrep.dev/playground/r/K3TgxrW/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age
|
|
origin: community
|
|
- id: package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy
|
|
message: 'Missing or incorrect trustPolicy. Set `trustPolicy: no-downgrade` to prevent
|
|
malicious package updates from downgrading security settings. Added in: v10.21.0
|
|
Reference: https://pnpm.io/settings#trustpolicy'
|
|
languages:
|
|
- yaml
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/pnpm-workspace.yaml'
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:packages|catalog)\s*:)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern: |
|
|
trustPolicy: $VAL
|
|
- metavariable-regex:
|
|
metavariable: $VAL
|
|
regex: ^(?!no-downgrade$).+
|
|
- focus-metavariable: $VAL
|
|
- patterns:
|
|
- pattern-regex: (?m)^\s*trustPolicy\s*:\s*$
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- pnpm
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://pnpm.io/settings#minimumreleaseage
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy
|
|
shortlink: https://sg.run/B2Kz7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291651
|
|
rv_id: 1423390
|
|
rule_id: j2U6J8N
|
|
version_id: qkTvDQn
|
|
url: https://semgrep.dev/playground/r/qkTvDQn/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy
|
|
origin: community
|
|
- id: package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-inside: |
|
|
"packageRules": [
|
|
...
|
|
]
|
|
- pattern-either:
|
|
- pattern: |
|
|
{ ..., "matchPackageNames": [...], ... }
|
|
- pattern: |
|
|
{ ..., "matchPackagePatterns": [...], ... }
|
|
- pattern: |
|
|
{ ..., "matchDepTypes": [...], ... }
|
|
- pattern-not: |
|
|
{
|
|
...,
|
|
"minimumReleaseAge": $AGE,
|
|
...
|
|
}
|
|
- pattern-not: |
|
|
{
|
|
...,
|
|
"minimumReleaseAge": false,
|
|
...
|
|
}
|
|
- patterns:
|
|
- pattern-inside: |
|
|
"packageRules": [
|
|
...
|
|
]
|
|
- pattern-regex: '"minimumReleaseAge":\s*"(?P<AGE>\d+) days?"'
|
|
- metavariable-comparison:
|
|
metavariable: $AGE
|
|
comparison: int($AGE) < 7
|
|
- focus-metavariable: $AGE
|
|
- patterns:
|
|
- pattern-inside: |
|
|
"packageRules": [
|
|
...
|
|
]
|
|
- pattern: |
|
|
"minimumReleaseAge": "$AGE"
|
|
- metavariable-regex:
|
|
metavariable: $AGE
|
|
regex: ^(?!\d+ days?$)
|
|
- focus-metavariable: $AGE
|
|
message: 'This Renovate configuration does not set a minimum release age. Newly
|
|
published packages can be malicious or unstable. Add `"minimumReleaseAge": "7
|
|
days"` within a `packageRules` entry to wait 7 days before proposing updates to
|
|
newly published package versions. Set `"minimumReleaseAge": false` to set an exception
|
|
for minimal release age for the package rule. Added in: v42'
|
|
languages:
|
|
- json
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/renovate.json'
|
|
- '**/renovate.json5'
|
|
- '**/.renovaterc'
|
|
- '**/.renovaterc.json'
|
|
- '**/.renovaterc.json5'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- renovate
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://docs.renovatebot.com/configuration-options/#minimumreleaseage
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age
|
|
shortlink: https://sg.run/D8l2q
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291652
|
|
rv_id: 1443454
|
|
rule_id: 10UbQrX
|
|
version_id: jQT1KAX
|
|
url: https://semgrep.dev/playground/r/jQT1KAX/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age
|
|
origin: community
|
|
- id: package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)\[tool\.uv\](?P<TARGET>[^\[]*?)(?=\[|\z)
|
|
- metavariable-regex:
|
|
metavariable: $TARGET
|
|
regex: ^(?![\s\S]*exclude-newer)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern-regex: exclude-newer\s*=\s*"(?P<DAYS>\d+) days?"
|
|
- metavariable-comparison:
|
|
metavariable: $DAYS
|
|
comparison: int($DAYS) < 7
|
|
- focus-metavariable: $DAYS
|
|
- patterns:
|
|
- pattern-regex: exclude-newer\s*=\s*"(?P<VAL>[^"]+)"
|
|
- metavariable-regex:
|
|
metavariable: $VAL
|
|
regex: ^(?!\d+ days?$)(?!\d{4}-\d{2}-\d{2}$)(?!\d{4}-\d{2}-\d{2}T)
|
|
- focus-metavariable: $VAL
|
|
message: 'This pyproject.toml configures uv but does not set a dependency cooldown.
|
|
Newly published packages can be malicious or unstable. Add `exclude-newer = "7
|
|
days"` under `[tool.uv]` to wait 7 days before resolving newly published package
|
|
versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns'
|
|
languages:
|
|
- generic
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/pyproject.toml'
|
|
- '**/uv.toml'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- uv
|
|
- python
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown
|
|
shortlink: https://sg.run/WeY0Z
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291653
|
|
rv_id: 1423392
|
|
rule_id: 9AUo6vE
|
|
version_id: YDTwLle
|
|
url: https://semgrep.dev/playground/r/YDTwLle/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown
|
|
origin: community
|
|
- id: package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:nodeLinker|yarnPath|enableGlobalCache|npmScopes|npmRegistryServer)\s*:)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
|
|
- focus-metavariable: $TARGET
|
|
- patterns:
|
|
- pattern-regex: (?m)npmMinimalAgeGate\s*:\s*['"]?(?P<DAYS>\d+)d['"]?
|
|
- metavariable-comparison:
|
|
metavariable: $DAYS
|
|
comparison: int($DAYS) < 7
|
|
- focus-metavariable: $DAYS
|
|
- patterns:
|
|
- pattern-regex: (?m)npmMinimalAgeGate[ \t]*:[ \t]*(?P<VAL>\S+)
|
|
- metavariable-regex:
|
|
metavariable: $VAL
|
|
regex: ^(?!['"]?\d+d['"]?$)
|
|
- focus-metavariable: $VAL
|
|
- patterns:
|
|
- pattern-regex: (?m)^npmMinimalAgeGate\s*:\s*$
|
|
message: 'This .yarnrc.yml does not set a minimal age gate or sets it too low. Newly
|
|
published packages can be malicious or unstable. Add `npmMinimalAgeGate: "7d"`
|
|
to wait 7 days before resolving newly published package versions. Added in: 4.10
|
|
Reference: https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate'
|
|
languages:
|
|
- yaml
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/.yarnrc.yml'
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- yarn
|
|
- javascript
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: HIGH
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate
|
|
shortlink: https://sg.run/0gvNq
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 291654
|
|
rv_id: 1423393
|
|
rule_id: yyUBeEz
|
|
version_id: JdTnXlj
|
|
url: https://semgrep.dev/playground/r/JdTnXlj/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate
|
|
origin: community
|
|
- id: package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age
|
|
message: "This poetry.toml does not set a dependency cooldown via `solver.min-release-age`.
|
|
Without a cooldown, Poetry may resolve newly published package versions that have
|
|
not yet been vetted by the community. Supply chain attacks frequently involve
|
|
publishing a malicious version of a popular package and waiting for it to be pulled
|
|
in \u2014 most are detected and removed within days. Set `min-release-age = 7`
|
|
under `[solver]` to require that package versions are at least 7 days old before
|
|
they are considered during dependency resolution. Added in: v2.4.0"
|
|
languages:
|
|
- generic
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/poetry.toml'
|
|
- '**/config.toml'
|
|
pattern-either:
|
|
- pattern-regex: (?m)^\[solver\]\n(?:^(?!min-release-age|\[|---).*\n)*(?=^\[|^---|\z)
|
|
- pattern-regex: (?ms)^\[solver\](?:[^\[]*?)min-release-age\s*=\s*(?P<TARGET>"[^"]*"|[0-6](?:\s|#|$)|false)
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- poetry
|
|
- python
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: MEDIUM
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://python-poetry.org/docs/configuration/#solvermin-release-age
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age
|
|
shortlink: https://sg.run/JqnYZ
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 309390
|
|
rv_id: 1443453
|
|
rule_id: kxUjBPy
|
|
version_id: X0TYPX6
|
|
url: https://semgrep.dev/playground/r/X0TYPX6/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age
|
|
origin: community
|
|
- id: package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown
|
|
message: 'A Gemfile `source` declaration without a `cooldown` (or with a cooldown
|
|
below 7 days) allows Bundler to resolve newly published gem versions immediately,
|
|
before the community has had time to detect malicious releases. The May 2026 RubyGems
|
|
supply-chain attack demonstrated that threat actors can push compromised gem versions
|
|
and have them automatically pulled into builds within minutes. Add `cooldown:
|
|
7` to each public source declaration so Bundler ignores gem versions published
|
|
within the last 7 days during dependency resolution (e.g. `source "https://rubygems.org",
|
|
cooldown: 7`). If you operate an internal or private registry where the supply-chain
|
|
risk is lower, use `cooldown: 0` as an explicit bypass. Note: this feature requires
|
|
Bundler >= 4.0.13. Cooldown only applies during `bundle update` and `bundle add`;
|
|
`bundle install` with an existing lockfile is unaffected.'
|
|
languages:
|
|
- ruby
|
|
severity: MEDIUM
|
|
paths:
|
|
include:
|
|
- '**/Gemfile'
|
|
- '**/gems.rb'
|
|
exclude:
|
|
- '**/vendor/**'
|
|
- '**/.bundle/**'
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: source "...", ...
|
|
- pattern-not: 'source "...", ..., cooldown: $N, ...'
|
|
- patterns:
|
|
- pattern: 'source "...", ..., cooldown: $N, ...'
|
|
- metavariable-comparison:
|
|
metavariable: $N
|
|
comparison: $N > 0 and $N < 7
|
|
- focus-metavariable: $N
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- bundler
|
|
- ruby
|
|
cwe:
|
|
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
|
|
owasp:
|
|
- A08:2021 - Software and Data Integrity Failures
|
|
confidence: MEDIUM
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
subcategory:
|
|
- audit
|
|
vulnerability_class:
|
|
- Insecure Configuration
|
|
references:
|
|
- https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
source: https://semgrep.dev/r/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown
|
|
shortlink: https://sg.run/5Wlkl
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 309391
|
|
rv_id: 1443455
|
|
rule_id: wdUzPbP
|
|
version_id: 1QTEjAN
|
|
url: https://semgrep.dev/playground/r/1QTEjAN/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown
|
|
origin: community
|
|
- id: yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell
|
|
languages:
|
|
- yaml
|
|
message: "A `run:` step pipes the output of `curl` or `wget` directly into a shell
|
|
interpreter. This is the \"curl | bash\" install pattern \u2014 if the remote
|
|
server is compromised or the URL is hijacked, an attacker can execute arbitrary
|
|
code in your CI runner. Consider downloading the file first, verifying its checksum
|
|
or signature, and then executing it."
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
|
|
Command Injection'')'
|
|
owasp:
|
|
- A03:2021 - Injection
|
|
- A03:2025 - Injection
|
|
references:
|
|
- https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions
|
|
- https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/
|
|
technology:
|
|
- github-actions
|
|
- bash
|
|
- curl
|
|
cwe2021-top25: true
|
|
cwe2022-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Command Injection
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell
|
|
shortlink: https://sg.run/GR8K1
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 309392
|
|
rv_id: 1443456
|
|
rule_id: x8UAgrE
|
|
version_id: 9lT3zYb
|
|
url: https://semgrep.dev/playground/r/9lT3zYb/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: 'steps: [...]'
|
|
- pattern-inside: |
|
|
- run: ...
|
|
...
|
|
- pattern: 'run: $SHELL'
|
|
- metavariable-pattern:
|
|
language: bash
|
|
metavariable: $SHELL
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: curl ... | $CMD ...
|
|
- pattern: wget ... | $CMD ...
|
|
- metavariable-regex:
|
|
metavariable: $CMD
|
|
regex: ^(bash|sh|python3?|ruby|perl)$
|
|
severity: ERROR
|
|
- id: yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret
|
|
languages:
|
|
- yaml
|
|
message: "A secret is exposed in the workflow-level `env:` block, making it available
|
|
to every job and step in this workflow \u2014 including any untrusted code run
|
|
in pull-request workflows. Scope secrets as narrowly as possible: prefer step-level
|
|
`env:` so the secret is only available where it is actually needed."
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
|
|
owasp:
|
|
- A01:2021 - Broken Access Control
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-secrets
|
|
- https://docs.github.com/en/actions/learn-github-actions/variables#defining-environment-variables-for-a-single-workflow
|
|
technology:
|
|
- github-actions
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authorization
|
|
source: https://semgrep.dev/r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret
|
|
shortlink: https://sg.run/Rrn12
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 309393
|
|
rv_id: 1443457
|
|
rule_id: OrUnq7z
|
|
version_id: yeTqX9r
|
|
url: https://semgrep.dev/playground/r/yeTqX9r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret
|
|
origin: community
|
|
patterns:
|
|
- pattern-inside: |
|
|
env:
|
|
...
|
|
- pattern-regex: \$\{\{\s*secrets\.
|
|
- pattern-not-inside: 'jobs: ...'
|
|
severity: WARNING
|
|
- id: ruby.rails.security.injection.tainted-sql-string.tainted-sql-string
|
|
languages:
|
|
- ruby
|
|
severity: ERROR
|
|
message: Detected user input used to manually construct a SQL string. This is usually
|
|
bad practice because manual construction could accidentally result in a SQL injection.
|
|
An attacker could use a SQL injection to steal or modify contents of the database.
|
|
Instead, use a parameterized query which is available by default in most database
|
|
engines. Alternatively, consider using an object-relational mapper (ORM) such
|
|
as ActiveRecord which will protect your queries.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
category: security
|
|
technology:
|
|
- rails
|
|
references:
|
|
- https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: HIGH
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string
|
|
shortlink: https://sg.run/Y85o
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14714
|
|
rv_id: 1263667
|
|
rule_id: bwU8gl
|
|
version_id: YDTZeLL
|
|
url: https://semgrep.dev/playground/r/YDTZeLL/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: params
|
|
- pattern: request
|
|
pattern-sanitizers:
|
|
- pattern: |
|
|
$PARAMS.slice(...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
$RECORD.where($X,...)
|
|
- pattern: |
|
|
$RECORD.find(..., :conditions => $X,...)
|
|
- focus-metavariable: $X
|
|
- patterns:
|
|
- pattern: |
|
|
"$SQLVERB#{$EXPR}..."
|
|
- pattern-not-inside: |
|
|
$FUNC("...", "...#{$EXPR}...",...)
|
|
- focus-metavariable: $SQLVERB
|
|
- pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: Kernel::sprintf("$SQLSTR", $EXPR)
|
|
- pattern: |
|
|
"$SQLSTR" + $EXPR
|
|
- pattern: |
|
|
"$SQLSTR" % $EXPR
|
|
- pattern-not-inside: |
|
|
$FUNC("...", "...#{$EXPR}...",...)
|
|
- focus-metavariable: $EXPR
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(select|delete|insert|create|update|alter|drop)\b
|
|
- id: php.lang.security.injection.tainted-sql-string.tainted-sql-string
|
|
languages:
|
|
- php
|
|
severity: ERROR
|
|
message: User data flows into this manually-constructed SQL string. User data can
|
|
be safely inserted into SQL strings using prepared statements or an object-relational
|
|
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
|
|
injection, which could let an attacker steal or manipulate data from the database.
|
|
Instead, use prepared statements (`$mysqli->prepare("INSERT INTO test(id, label)
|
|
VALUES (?, ?)");`) or a safe library.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://owasp.org/www-community/attacks/SQL_Injection
|
|
category: security
|
|
technology:
|
|
- php
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/php.lang.security.injection.tainted-sql-string.tainted-sql-string
|
|
shortlink: https://sg.run/lZYG
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14757
|
|
rv_id: 1263290
|
|
rule_id: qNUXdL
|
|
version_id: gETB7vY
|
|
url: https://semgrep.dev/playground/r/gETB7vY/php.lang.security.injection.tainted-sql-string.tainted-sql-string
|
|
origin: community
|
|
mode: taint
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: mysqli_real_escape_string(...)
|
|
- pattern: real_escape_string(...)
|
|
- pattern: $MYSQLI->real_escape_string(...)
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
- pattern: $_COOKIE
|
|
- pattern: $_REQUEST
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
sprintf($SQLSTR, ...)
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.*
|
|
- patterns:
|
|
- pattern: |
|
|
"...$EXPR..."
|
|
- metavariable-regex:
|
|
metavariable: $EXPR
|
|
regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.*
|
|
- patterns:
|
|
- pattern: |
|
|
"$SQLSTR".$EXPR
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.*
|
|
- id: php.lang.security.injection.tainted-url-host.tainted-url-host
|
|
languages:
|
|
- php
|
|
severity: WARNING
|
|
message: User data flows into the host portion of this manually-constructed URL.
|
|
This could allow an attacker to send data to their own server, potentially exposing
|
|
sensitive data such as cookies or authorization information sent with this request.
|
|
They could also probe internal servers or other resources that the server running
|
|
this code can access. (This is called server-side request forgery, or SSRF.) Do
|
|
not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or
|
|
hardcode the correct host.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-918: Server-Side Request Forgery (SSRF)'
|
|
owasp:
|
|
- A10:2021 - Server-Side Request Forgery (SSRF)
|
|
- A01:2025 - Broken Access Control
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
|
|
category: security
|
|
technology:
|
|
- php
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
impact: MEDIUM
|
|
likelihood: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Server-Side Request Forgery (SSRF)
|
|
source: https://semgrep.dev/r/php.lang.security.injection.tainted-url-host.tainted-url-host
|
|
shortlink: https://sg.run/Y8no
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14758
|
|
rv_id: 1263291
|
|
rule_id: lBU8K1
|
|
version_id: QkTGqRd
|
|
url: https://semgrep.dev/playground/r/QkTGqRd/php.lang.security.injection.tainted-url-host.tainted-url-host
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: $_GET
|
|
- pattern: $_POST
|
|
- pattern: $_COOKIE
|
|
- pattern: $_REQUEST
|
|
pattern-sinks:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
sprintf($URLSTR, ...)
|
|
- metavariable-pattern:
|
|
metavariable: $URLSTR
|
|
language: generic
|
|
pattern: $SCHEME://%s
|
|
- patterns:
|
|
- pattern: |
|
|
"...{$EXPR}..."
|
|
- pattern-regex: |
|
|
.*://\{.*
|
|
- patterns:
|
|
- pattern: |
|
|
"...$EXPR..."
|
|
- pattern-regex: |
|
|
.*://\$.*
|
|
- patterns:
|
|
- pattern: |
|
|
"...".$EXPR
|
|
- pattern-regex: |
|
|
.*://["'].*
|
|
- id: php.lang.security.md5-used-as-password.md5-used-as-password
|
|
severity: WARNING
|
|
message: It looks like MD5 is used as a password hash. MD5 is not considered a secure
|
|
password hash because it can be cracked by an attacker in a short amount of time.
|
|
Use a suitable password hashing function such as bcrypt. You can use `password_hash($PASSWORD,
|
|
PASSWORD_BCRYPT, $OPTIONS);`.
|
|
languages:
|
|
- php
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
references:
|
|
- https://tools.ietf.org/html/rfc6151
|
|
- https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision
|
|
- https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords
|
|
- https://github.com/returntocorp/semgrep-rules/issues/1609
|
|
- https://www.php.net/password_hash
|
|
category: security
|
|
technology:
|
|
- md5
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/php.lang.security.md5-used-as-password.md5-used-as-password
|
|
shortlink: https://sg.run/66YL
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14759
|
|
rv_id: 1263294
|
|
rule_id: YGUD1O
|
|
version_id: PkTR37j
|
|
url: https://semgrep.dev/playground/r/PkTR37j/php.lang.security.md5-used-as-password.md5-used-as-password
|
|
origin: community
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: md5(...)
|
|
- pattern: hash('md5', ...)
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern: $FUNCTION(...)
|
|
- metavariable-regex:
|
|
metavariable: $FUNCTION
|
|
regex: (?i)(.*password.*)
|
|
- id: java.spring.security.injection.tainted-sql-string.tainted-sql-string
|
|
languages:
|
|
- java
|
|
severity: ERROR
|
|
message: User data flows into this manually-constructed SQL string. User data can
|
|
be safely inserted into SQL strings using prepared statements or an object-relational
|
|
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
|
|
injection, which could let an attacker steal or manipulate data from the database.
|
|
Instead, use prepared statements (`connection.PreparedStatement`) or a safe library.
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
references:
|
|
- https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html
|
|
category: security
|
|
technology:
|
|
- spring
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
interfile: true
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/java.spring.security.injection.tainted-sql-string.tainted-sql-string
|
|
shortlink: https://sg.run/9rzz
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14767
|
|
rv_id: 1409396
|
|
rule_id: 10UdRR
|
|
version_id: 44TbKvr
|
|
url: https://semgrep.dev/playground/r/44TbKvr/java.spring.security.injection.tainted-sql-string.tainted-sql-string
|
|
origin: community
|
|
options:
|
|
taint_assume_safe_numbers: true
|
|
taint_assume_safe_booleans: true
|
|
interfile: true
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
|
|
...
|
|
}
|
|
- metavariable-regex:
|
|
metavariable: $REQ
|
|
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue)
|
|
- metavariable-regex:
|
|
metavariable: $TYPE
|
|
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
|
|
- focus-metavariable: $SOURCE
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"$SQLSTR" + ...
|
|
- pattern: |
|
|
"$SQLSTR".concat(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
StringBuilder $SB = new StringBuilder("$SQLSTR");
|
|
...
|
|
- pattern: $SB.append(...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
$VAR = "$SQLSTR";
|
|
...
|
|
- pattern: $VAR += ...
|
|
- pattern: String.format("$SQLSTR", ...)
|
|
- patterns:
|
|
- pattern-inside: |
|
|
String $VAR = "$SQLSTR";
|
|
...
|
|
- pattern: String.format($VAR, ...)
|
|
- pattern-not-inside: System.out.println(...)
|
|
- pattern-not-inside: $LOG.info(...)
|
|
- pattern-not-inside: $LOG.warn(...)
|
|
- pattern-not-inside: $LOG.warning(...)
|
|
- pattern-not-inside: $LOG.debug(...)
|
|
- pattern-not-inside: $LOG.debugging(...)
|
|
- pattern-not-inside: $LOG.error(...)
|
|
- pattern-not-inside: new Exception(...)
|
|
- pattern-not-inside: throw ...;
|
|
- metavariable-regex:
|
|
metavariable: $SQLSTR
|
|
regex: (?i)(select|delete|insert|create|update|alter|drop)\b
|
|
- id: terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version
|
|
patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: ssl_policy = $ANYTHING
|
|
- pattern-not-regex: ELBSecurityPolicy-TLS13-1-[23]-[(Res)0-9-]+
|
|
- pattern-not-regex: ELBSecurityPolicy-FS-1-2-[(Res)0-9-]+
|
|
- patterns:
|
|
- pattern: protocol = "HTTP"
|
|
- pattern-not-inside: |
|
|
resource $ANYTHING $NAME {
|
|
...
|
|
default_action {
|
|
...
|
|
redirect {
|
|
...
|
|
protocol = "HTTPS"
|
|
...
|
|
}
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource $RESOURCE $X {
|
|
...
|
|
}
|
|
- metavariable-pattern:
|
|
metavariable: $RESOURCE
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
"aws_lb_listener"
|
|
- pattern: |
|
|
"aws_alb_listener"
|
|
message: Detected an AWS load balancer with an insecure TLS version. TLS versions
|
|
less than 1.2 are considered insecure because they can be broken. To fix this,
|
|
set your `ssl_policy` to `"ELBSecurityPolicy-TLS13-1-2-Res-2021-06"`, or include
|
|
a default action to redirect to HTTPS.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- aws
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
references:
|
|
- https://www.ietf.org/rfc/rfc5246.txt
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version
|
|
shortlink: https://sg.run/187G
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 14966
|
|
rv_id: 1263747
|
|
rule_id: 2ZUP9K
|
|
version_id: ExTEx0y
|
|
url: https://semgrep.dev/playground/r/ExTEx0y/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: csharp.lang.security.sqli.csharp-sqli.csharp-sqli
|
|
mode: taint
|
|
pattern-sources:
|
|
- patterns:
|
|
- pattern: |
|
|
(string $X)
|
|
- pattern-not: |
|
|
"..."
|
|
pattern-propagators:
|
|
- pattern: (StringBuilder $B).$ANY(...,(string $X),...)
|
|
from: $X
|
|
to: $B
|
|
pattern-sinks:
|
|
- patterns:
|
|
- pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
new $PATTERN($CMD,...)
|
|
- focus-metavariable: $CMD
|
|
- patterns:
|
|
- pattern: |
|
|
$CMD.$PATTERN = $VALUE;
|
|
- focus-metavariable: $VALUE
|
|
- metavariable-regex:
|
|
metavariable: $PATTERN
|
|
regex: ^(SqlCommand|CommandText|OleDbCommand|OdbcCommand|OracleCommand)$
|
|
pattern-sanitizers:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$CMD.Parameters.Add(...)
|
|
- pattern: |
|
|
$CMD.Parameters.AddRange(...)
|
|
- pattern: |
|
|
$CMD.Parameters.AddWithValue(...)
|
|
- pattern: |
|
|
$CMD.Parameters[$IDX].Value = ...
|
|
by-side-effect: true
|
|
message: Detected a formatted string in a SQL statement. This could lead to SQL
|
|
injection if variables in the SQL statement are not properly sanitized. Use a
|
|
prepared statements instead. You can obtain a PreparedStatement using 'SqlCommand'
|
|
and 'SqlParameter'.
|
|
metadata:
|
|
category: security
|
|
technology:
|
|
- csharp
|
|
owasp:
|
|
- A01:2017 - Injection
|
|
- A03:2021 - Injection
|
|
- A05:2025 - Injection
|
|
cwe:
|
|
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
|
|
(''SQL Injection'')'
|
|
confidence: MEDIUM
|
|
references:
|
|
- https://owasp.org/Top10/A03_2021-Injection
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: LOW
|
|
impact: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- SQL Injection
|
|
source: https://semgrep.dev/r/csharp.lang.security.sqli.csharp-sqli.csharp-sqli
|
|
shortlink: https://sg.run/d2Xd
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15078
|
|
rv_id: 1262648
|
|
rule_id: x8UxeP
|
|
version_id: RGT0LqW
|
|
url: https://semgrep.dev/playground/r/RGT0LqW/csharp.lang.security.sqli.csharp-sqli.csharp-sqli
|
|
origin: community
|
|
languages:
|
|
- csharp
|
|
severity: ERROR
|
|
- id: scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret
|
|
languages:
|
|
- scala
|
|
message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently
|
|
Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html
|
|
Consider using an appropriate security mechanism to protect the credentials (e.g.
|
|
keeping secrets in environment variables)'
|
|
metadata:
|
|
category: security
|
|
cwe:
|
|
- 'CWE-522: Insufficiently Protected Credentials'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
|
|
technology:
|
|
- jwt
|
|
confidence: HIGH
|
|
references:
|
|
- https://owasp.org/Top10/A04_2021-Insecure_Design
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- audit
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret
|
|
shortlink: https://sg.run/Z40o
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15079
|
|
rv_id: 1263691
|
|
rule_id: OrU6W1
|
|
version_id: 7ZTE3kr
|
|
url: https://semgrep.dev/playground/r/7ZTE3kr/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret
|
|
origin: community
|
|
pattern-either:
|
|
- pattern: |
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC256("...");
|
|
- pattern: |
|
|
$SECRET = "...";
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET);
|
|
- pattern: |
|
|
class $CLASS {
|
|
...
|
|
$DECL $SECRET = "...";
|
|
...
|
|
def $FUNC (...): $RETURNTYPE = {
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: |
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC384("...");
|
|
- pattern: |
|
|
$SECRET = "...";
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET);
|
|
- pattern: |
|
|
class $CLASS {
|
|
...
|
|
$DECL $SECRET = "...";
|
|
...
|
|
def $FUNC (...): $RETURNTYPE = {
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern: |
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC512("...");
|
|
- pattern: |
|
|
$SECRET = "...";
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET);
|
|
- pattern: |
|
|
class $CLASS {
|
|
...
|
|
$DECL $SECRET = "...";
|
|
...
|
|
def $FUNC (...): $RETURNTYPE = {
|
|
...
|
|
com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET);
|
|
...
|
|
}
|
|
...
|
|
}
|
|
severity: ERROR
|
|
- id: terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled
|
|
message: Enabling authentication ensures that all communications in the application
|
|
are authenticated. The `auth_settings` block needs to be filled out with the appropriate
|
|
auth backend settings
|
|
patterns:
|
|
- pattern: resource
|
|
- pattern-not-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
auth_settings {
|
|
...
|
|
enabled = true
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
auth_settings {
|
|
...
|
|
enabled = false
|
|
...
|
|
}
|
|
...
|
|
}
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-287: Improper Authentication'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#auth_settings
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled
|
|
shortlink: https://sg.run/JxYw
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15102
|
|
rv_id: 1263755
|
|
rule_id: 0oU23p
|
|
version_id: PkTR3P8
|
|
url: https://semgrep.dev/playground/r/PkTR3P8/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2
|
|
message: Use the latest version of HTTP to ensure you are benefiting from security
|
|
fixes. Add `http2_enabled = true` to your appservice resource block
|
|
patterns:
|
|
- pattern: resource
|
|
- pattern-not-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
site_config {
|
|
...
|
|
http2_enabled = true
|
|
...
|
|
}
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
site_config {
|
|
...
|
|
http2_enabled = false
|
|
...
|
|
}
|
|
...
|
|
}
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response
|
|
Smuggling'')'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#http2_enabled
|
|
owasp:
|
|
- A04:2021 - Insecure Design
|
|
- A06:2025 - Insecure Design
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Validation
|
|
source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2
|
|
shortlink: https://sg.run/5DkA
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15103
|
|
rv_id: 1263756
|
|
rule_id: KxU7LJ
|
|
version_id: JdTzx98
|
|
url: https://semgrep.dev/playground/r/JdTzx98/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: INFO
|
|
- id: terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only
|
|
message: By default, clients can connect to App Service by using both HTTP or HTTPS.
|
|
HTTP should be disabled enabling the HTTPS Only setting.
|
|
patterns:
|
|
- pattern: resource
|
|
- pattern-not-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
https_only = true
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
https_only = false
|
|
...
|
|
}
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#https_only
|
|
- https://docs.microsoft.com/en-us/azure/app-service/configure-ssl-bindings#enforce-https
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only
|
|
shortlink: https://sg.run/GOKp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15104
|
|
rv_id: 1263757
|
|
rule_id: qNUXwx
|
|
version_id: 5PTo1gg
|
|
url: https://semgrep.dev/playground/r/5PTo1gg/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert
|
|
message: Detected an AppService that was not configured to use a client certificate.
|
|
Add `client_cert_enabled = true` in your resource block.
|
|
patterns:
|
|
- pattern: resource
|
|
- pattern-not-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
client_cert_enabled = true
|
|
...
|
|
}
|
|
- pattern-either:
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "..." {
|
|
...
|
|
client_cert_enabled = false
|
|
...
|
|
}
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-295: Improper Certificate Validation'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#client_cert_enabled
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: MEDIUM
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert
|
|
shortlink: https://sg.run/RX1O
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15105
|
|
rv_id: 1263758
|
|
rule_id: lBU8D6
|
|
version_id: GxTkedE
|
|
url: https://semgrep.dev/playground/r/GxTkedE/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: INFO
|
|
- id: terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy
|
|
message: Detected an AppService that was not configured to use TLS 1.2. Add `site_config.min_tls_version
|
|
= "1.2"` in your resource block.
|
|
patterns:
|
|
- pattern: min_tls_version = $ANYTHING
|
|
- pattern-inside: |
|
|
resource "azurerm_app_service" "$NAME" {
|
|
...
|
|
}
|
|
- pattern-not-inside: min_tls_version = "1.2"
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#min_tls_version
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy
|
|
shortlink: https://sg.run/AXRp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15106
|
|
rv_id: 1263759
|
|
rule_id: YGUDbZ
|
|
version_id: RGT0L4x
|
|
url: https://semgrep.dev/playground/r/RGT0L4x/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: ERROR
|
|
- id: terraform.azure.security.storage.storage-enforce-https.storage-enforce-https
|
|
message: Detected a Storage that was not configured to deny action by default. Add
|
|
`enable_https_traffic_only = true` in your resource block.
|
|
patterns:
|
|
- pattern-not-inside: |
|
|
resource "azurerm_storage_account" "..." {
|
|
...
|
|
enable_https_traffic_only = true
|
|
...
|
|
}
|
|
- pattern-inside: |
|
|
resource "azurerm_storage_account" "..." {
|
|
...
|
|
enable_https_traffic_only = false
|
|
...
|
|
}
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-319: Cleartext Transmission of Sensitive Information'
|
|
category: security
|
|
technology:
|
|
- terraform
|
|
- azure
|
|
references:
|
|
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#enable_https_traffic_only
|
|
- https://docs.microsoft.com/en-us/azure/storage/common/storage-require-secure-transfer
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Mishandled Sensitive Information
|
|
source: https://semgrep.dev/r/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https
|
|
shortlink: https://sg.run/0y9v
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15110
|
|
rv_id: 1263805
|
|
rule_id: pKUpDA
|
|
version_id: BjTkZ0A
|
|
url: https://semgrep.dev/playground/r/BjTkZ0A/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https
|
|
origin: community
|
|
languages:
|
|
- hcl
|
|
severity: WARNING
|
|
- id: kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-287: Improper Authentication'
|
|
owasp:
|
|
- A02:2017 - Broken Authentication
|
|
- A07:2021 - Identification and Authentication Failures
|
|
- A07:2025 - Authentication Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ANONYMOUS
|
|
category: security
|
|
technology:
|
|
- kotlin
|
|
references:
|
|
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
|
|
cwe2022-top25: true
|
|
cwe2021-top25: true
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Improper Authentication
|
|
source: https://semgrep.dev/r/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind
|
|
shortlink: https://sg.run/rY2n
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15125
|
|
rv_id: 1263258
|
|
rule_id: v8U9Q7
|
|
version_id: WrTqKgJ
|
|
url: https://semgrep.dev/playground/r/WrTqKgJ/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind
|
|
origin: community
|
|
message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP
|
|
statements. Consider enforcing authentication for LDAP. See https://docs.oracle.com/javase/tutorial/jndi/ldap/auth_mechs.html
|
|
for more information.
|
|
severity: WARNING
|
|
pattern: |
|
|
$ENV.put($CTX.SECURITY_AUTHENTICATION, "none")
|
|
...
|
|
$DCTX = InitialDirContext($ENV, ...)
|
|
languages:
|
|
- kt
|
|
- id: kotlin.lang.security.use-of-sha1.use-of-sha1
|
|
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
|
|
collision resistant and is therefore not suitable as a cryptographic signature.
|
|
Use SHA256 or SHA3 instead.
|
|
languages:
|
|
- kt
|
|
severity: WARNING
|
|
metadata:
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
cwe:
|
|
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
category: security
|
|
technology:
|
|
- kotlin
|
|
references:
|
|
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
|
|
subcategory:
|
|
- vuln
|
|
likelihood: LOW
|
|
impact: MEDIUM
|
|
confidence: MEDIUM
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/kotlin.lang.security.use-of-sha1.use-of-sha1
|
|
shortlink: https://sg.run/N1pp
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15127
|
|
rv_id: 1263268
|
|
rule_id: ZqUOdd
|
|
version_id: 2KTv2XZ
|
|
url: https://semgrep.dev/playground/r/2KTv2XZ/kotlin.lang.security.use-of-sha1.use-of-sha1
|
|
origin: community
|
|
pattern-either:
|
|
- patterns:
|
|
- pattern: |
|
|
$VAR = $MD.getInstance("$ALGO")
|
|
- metavariable-regex:
|
|
metavariable: $ALGO
|
|
regex: (SHA1|SHA-1)
|
|
- pattern: |
|
|
$DU.getSha1Digest().digest(...)
|
|
- id: kotlin.lang.security.weak-rsa.use-of-weak-rsa-key
|
|
message: RSA keys should be at least 2048 bits based on NIST recommendation.
|
|
languages:
|
|
- kt
|
|
severity: WARNING
|
|
metadata:
|
|
cwe:
|
|
- 'CWE-326: Inadequate Encryption Strength'
|
|
owasp:
|
|
- A03:2017 - Sensitive Data Exposure
|
|
- A02:2021 - Cryptographic Failures
|
|
- A04:2025 - Cryptographic Failures
|
|
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE
|
|
asvs:
|
|
section: V6 Stored Cryptography Verification Requirements
|
|
control_id: 6.2.5 Insecure Algorithm
|
|
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
|
|
version: '4'
|
|
references:
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
|
|
category: security
|
|
technology:
|
|
- kotlin
|
|
subcategory:
|
|
- audit
|
|
likelihood: HIGH
|
|
impact: MEDIUM
|
|
confidence: HIGH
|
|
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
|
|
vulnerability_class:
|
|
- Cryptographic Issues
|
|
source: https://semgrep.dev/r/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key
|
|
shortlink: https://sg.run/krq7
|
|
semgrep.dev:
|
|
rule:
|
|
r_id: 15128
|
|
rv_id: 1263269
|
|
rule_id: nJUZNL
|
|
version_id: X0TzypE
|
|
url: https://semgrep.dev/playground/r/X0TzypE/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key
|
|
origin: community
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$KEY = $G.getInstance("RSA")
|
|
...
|
|
$KEY.initialize($BITS)
|
|
- metavariable-comparison:
|
|
metavariable: $BITS
|
|
comparison: $BITS < 2048
|