베타 Shoulder는 베타 버전입니다 — 결과가 가끔 잘못될 수 있습니다. 여러분의 피드백이 다음에 무엇을 고칠지 결정합니다. 피드백 공유
🐹
Go Security
90 규칙
54 CWE 7 critical

Go 보안 취약점

Shoulder는 Go로 구축된 Go 애플리케이션에 특화된 90개의 보안 패턴을 탐지합니다.

프레임워크 커버리지

취약점 카테고리

CWE-693 6 규칙
Protection Mechanism Failure
CWE-307 5 규칙
Improper Restriction of Excessive Authentication Attempts
CWE-942 5 규칙
Permissive Cross-domain Policy with Untrusted Domains
CWE-20 4 규칙
Improper Input Validation
CWE-200 4 규칙
Exposure of Sensitive Information to an Unauthorized Actor
1 critical
CWE-362 4 규칙
Concurrent Execution Using Shared Resource with Improper Synchronization ('Race Condition')
CWE-94 3 규칙
Improper Control of Generation of Code ('Code Injection')
2 critical
CWE-306 3 규칙
Missing Authentication for Critical Function
CWE-319 3 규칙
Cleartext Transmission of Sensitive Information
CWE-400 3 규칙
Uncontrolled Resource Consumption
CWE-489 3 규칙
Active Debug Code
CWE-639 3 규칙
Authorization Bypass Through User-Controlled Key
CWE-22 2 규칙
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-502 2 규칙
Deserialization of Untrusted Data
CWE-74 1 규칙
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-78 1 규칙
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
1 critical
CWE-89 1 규칙
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
1 critical
CWE-90 1 규칙
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CWE-93 1 규칙
Improper Neutralization of CRLF Sequences ('CRLF Injection')
CWE-113 1 규칙
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
🐹

Go 프로젝트 스캔

Shoulder CLI를 실행하여 Go 고유의 취약점을 찾으세요.