OWASP Top 10 2021
OWASP Top 10은 웹 애플리케이션 보안을 위한 표준 인식 문서입니다. 웹 애플리케이션에 가장 중요한 보안 위험에 대한 광범위한 합의를 나타냅니다.
Broken Access Control
Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized information disclosure, modification, or destruction of data.
Cryptographic Failures
Failures related to cryptography which often lead to sensitive data exposure. This was previously known as Sensitive Data Exposure.
Injection
Injection flaws occur when an application sends hostile data to an interpreter. This includes SQL, NoSQL, OS command, ORM, LDAP, and Expression Language injection.
Insecure Design
Insecure design is a broad category representing different weaknesses, expressed as missing or ineffective control design. This is distinct from implementation flaws.
Security Misconfiguration
The application might be vulnerable if it is missing appropriate security hardening or has improperly configured permissions on cloud services.
Vulnerable and Outdated Components
Components such as libraries, frameworks, and other software modules run with the same privileges as the application. If a vulnerable component is exploited, it can cause serious data loss.
Identification and Authentication Failures
Confirmation of the user's identity, authentication, and session management is critical to protect against authentication-related attacks.
Software and Data Integrity Failures
Software and data integrity failures relate to code and infrastructure that does not protect against integrity violations, including insecure deserialization.
Security Logging and Monitoring Failures
This category helps detect, escalate, and respond to active breaches. Without logging and monitoring, breaches cannot be detected.
Server-Side Request Forgery
SSRF flaws occur whenever a web application fetches a remote resource without validating the user-supplied URL.
OWASP Top 10 취약점 스캔
Shoulder는 여러 OWASP 카테고리에 걸쳐 패턴을 감지합니다. 스캔을 실행하여 코드의 문제를 찾으세요.
npx @shoulderdev/cli trust .
위협 센터 →