测试版 Shoulder 目前处于测试阶段 — 结果有时可能不正确。您的反馈塑造我们接下来要修复的内容。 分享反馈

OWASP Top 10 2021

OWASP Top 10是Web应用程序安全的标准意识文档。它代表了关于Web应用程序最关键安全风险的广泛共识。

版本: 2025 2021
10 类别
197 映射的CWE
#1 🔓

Broken Access Control

Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized information disclosure, modification, or destruction of data.

#2 🔐

Cryptographic Failures

Failures related to cryptography which often lead to sensitive data exposure. This was previously known as Sensitive Data Exposure.

#3 💉

Injection

Injection flaws occur when an application sends hostile data to an interpreter. This includes SQL, NoSQL, OS command, ORM, LDAP, and Expression Language injection.

#4 📐

Insecure Design

Insecure design is a broad category representing different weaknesses, expressed as missing or ineffective control design. This is distinct from implementation flaws.

#5 ⚙️

Security Misconfiguration

The application might be vulnerable if it is missing appropriate security hardening or has improperly configured permissions on cloud services.

#6 📦

Vulnerable and Outdated Components

Components such as libraries, frameworks, and other software modules run with the same privileges as the application. If a vulnerable component is exploited, it can cause serious data loss.

#7 🔑

Identification and Authentication Failures

Confirmation of the user's identity, authentication, and session management is critical to protect against authentication-related attacks.

#8

Software and Data Integrity Failures

Software and data integrity failures relate to code and infrastructure that does not protect against integrity violations, including insecure deserialization.

#9 📊

Security Logging and Monitoring Failures

This category helps detect, escalate, and respond to active breaches. Without logging and monitoring, breaches cannot be detected.

#10 🌐

Server-Side Request Forgery

SSRF flaws occur whenever a web application fetches a remote resource without validating the user-supplied URL.

扫描OWASP Top 10漏洞

Shoulder检测多个OWASP类别中的模式。运行扫描以发现代码中的问题。

npx @shoulderdev/cli trust . 威胁中心 →