베타 Shoulder는 베타 버전입니다 — 결과가 가끔 잘못될 수 있습니다. 여러분의 피드백이 다음에 무엇을 고칠지 결정합니다. 피드백 공유

OWASP Top 10 2021

OWASP Top 10은 웹 애플리케이션 보안을 위한 표준 인식 문서입니다. 웹 애플리케이션에 가장 중요한 보안 위험에 대한 광범위한 합의를 나타냅니다.

버전: 2025 2021
10 카테고리
197 매핑된 CWE
#1 🔓

Broken Access Control

Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized information disclosure, modification, or destruction of data.

#2 🔐

Cryptographic Failures

Failures related to cryptography which often lead to sensitive data exposure. This was previously known as Sensitive Data Exposure.

#3 💉

Injection

Injection flaws occur when an application sends hostile data to an interpreter. This includes SQL, NoSQL, OS command, ORM, LDAP, and Expression Language injection.

#4 📐

Insecure Design

Insecure design is a broad category representing different weaknesses, expressed as missing or ineffective control design. This is distinct from implementation flaws.

#5 ⚙️

Security Misconfiguration

The application might be vulnerable if it is missing appropriate security hardening or has improperly configured permissions on cloud services.

#6 📦

Vulnerable and Outdated Components

Components such as libraries, frameworks, and other software modules run with the same privileges as the application. If a vulnerable component is exploited, it can cause serious data loss.

#7 🔑

Identification and Authentication Failures

Confirmation of the user's identity, authentication, and session management is critical to protect against authentication-related attacks.

#8

Software and Data Integrity Failures

Software and data integrity failures relate to code and infrastructure that does not protect against integrity violations, including insecure deserialization.

#9 📊

Security Logging and Monitoring Failures

This category helps detect, escalate, and respond to active breaches. Without logging and monitoring, breaches cannot be detected.

#10 🌐

Server-Side Request Forgery

SSRF flaws occur whenever a web application fetches a remote resource without validating the user-supplied URL.

OWASP Top 10 취약점 스캔

Shoulder는 여러 OWASP 카테고리에 걸쳐 패턴을 감지합니다. 스캔을 실행하여 코드의 문제를 찾으세요.

npx @shoulderdev/cli trust . 위협 센터 →