BETA Shoulder está en beta — Los hallazgos a veces pueden ser incorrectos. Tu feedback da forma a lo que arreglamos a continuación. Compartir comentarios
🔷
TypeScript Security
121 reglas
70 CWEs 23 critical

Vulnerabilidades de Seguridad TypeScript

Shoulder detecta 121 patrones de seguridad específicos para aplicaciones TypeScript construidas con TypeScript.

Cobertura de Frameworks

Categorías de Vulnerabilidad

CWE-20 7 reglas
Improper Input Validation
CWE-200 5 reglas
Exposure of Sensitive Information to an Unauthorized Actor
2 critical
CWE-704 5 reglas
Incorrect Type Conversion or Cast
CWE-798 5 reglas
Use of Hard-coded Credentials
2 critical
CWE-89 4 reglas
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
4 critical
CWE-79 3 reglas
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1 critical
CWE-94 3 reglas
Improper Control of Generation of Code ('Code Injection')
1 critical
CWE-285 3 reglas
Improper Authorization
3 critical
CWE-639 3 reglas
Authorization Bypass Through User-Controlled Key
1 critical
CWE-22 2 reglas
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
1 critical
CWE-209 2 reglas
Generation of Error Message Containing Sensitive Information
CWE-327 2 reglas
Use of a Broken or Risky Cryptographic Algorithm
CWE-400 2 reglas
Uncontrolled Resource Consumption
CWE-502 2 reglas
Deserialization of Untrusted Data
1 critical
CWE-601 2 reglas
URL Redirection to Untrusted Site ('Open Redirect')
CWE-770 2 reglas
Allocation of Resources Without Limits or Throttling
CWE-915 2 reglas
Improperly Controlled Modification of Dynamically-Determined Object Attributes
2 critical
CWE-918 2 reglas
Server-Side Request Forgery (SSRF)
CWE-1321 2 reglas
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CWE-74 1 reglas
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
🔷

Escanea tu proyecto TypeScript

Ejecuta el CLI Shoulder para encontrar vulnerabilidades específicas de TypeScript.