Vulnerabilidades de Segurança Node.js
Shoulder detecta 125 padrões de segurança específicos para aplicações Node.js construídas com Node.js.
Cobertura de Frameworks
Categorias de Vulnerabilidade
CWE-20
7 regras
Improper Input Validation
CWE-200
5 regras
Exposure of Sensitive Information to an Unauthorized Actor
2 critical
CWE-704
5 regras
Incorrect Type Conversion or Cast
CWE-798
5 regras
Use of Hard-coded Credentials
2 critical
CWE-89
4 regras
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
4 critical
CWE-79
3 regras
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1 critical
CWE-94
3 regras
Improper Control of Generation of Code ('Code Injection')
1 critical
CWE-285
3 regras
Improper Authorization
3 critical
CWE-639
3 regras
Authorization Bypass Through User-Controlled Key
1 critical
CWE-22
2 regras
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
1 critical
CWE-117
2 regras
Improper Output Neutralization for Logs
CWE-209
2 regras
Generation of Error Message Containing Sensitive Information
CWE-327
2 regras
Use of a Broken or Risky Cryptographic Algorithm
CWE-400
2 regras
Uncontrolled Resource Consumption
CWE-502
2 regras
Deserialization of Untrusted Data
1 critical
CWE-601
2 regras
URL Redirection to Untrusted Site ('Open Redirect')
CWE-770
2 regras
Allocation of Resources Without Limits or Throttling
CWE-915
2 regras
Improperly Controlled Modification of Dynamically-Determined Object Attributes
2 critical
CWE-918
2 regras
Server-Side Request Forgery (SSRF)
CWE-1104
2 regras
Use of Unmaintained Third Party Components
Escaneie seu projeto Node.js
Execute o CLI Shoulder para encontrar vulnerabilidades específicas de Node.js.