Skip to content

Commit d30ba0e

Browse files
committed
[feat] Add seqra.json
1 parent c75910d commit d30ba0e

1 file changed

Lines changed: 299 additions & 0 deletions

File tree

config/labels/analyzers/seqra.json

Lines changed: 299 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,299 @@
1+
{
2+
"analyzer": "seqra",
3+
"labels": {
4+
"java.security.avoid-implementing-custom-digests": [
5+
"severity:HIGH"
6+
],
7+
"java.security.insecure-resteasy-deserialization": [
8+
"severity:HIGH"
9+
],
10+
"java.security.overly-permissive-file-permission-inline": [
11+
"severity:HIGH"
12+
],
13+
"java.security.gcm-nonce-reuse": [
14+
"severity:HIGH"
15+
],
16+
"java.security.use-of-rc2": [
17+
"severity:HIGH"
18+
],
19+
"java.security.use-of-rc4": [
20+
"severity:HIGH"
21+
],
22+
"java.security.csrf-disabled-in-spring-app": [
23+
"severity:HIGH"
24+
],
25+
"java.security.java-jwt-decode-without-verify": [
26+
"severity:HIGH"
27+
],
28+
"java.security.dangerous-permissions": [
29+
"severity:HIGH"
30+
],
31+
"java.security.use-of-sha1": [
32+
"severity:HIGH"
33+
],
34+
"java.security.constant-db-password": [
35+
"severity:CRITICAL"
36+
],
37+
"java.security.bad-hexa-conversion": [
38+
"severity:HIGH"
39+
],
40+
"java.security.server-dangerous-object-deserialization": [
41+
"severity:CRITICAL"
42+
],
43+
"java.security.url-rewriting": [
44+
"severity:HIGH"
45+
],
46+
"java.security.java-empty-db-password": [
47+
"severity:CRITICAL"
48+
],
49+
"java.security.use-of-blowfish": [
50+
"severity:HIGH"
51+
],
52+
"java.security.insecure-jms-deserialization": [
53+
"severity:HIGH"
54+
],
55+
"java.security.java-anonymous-ldap": [
56+
"severity:HIGH"
57+
],
58+
"java.security.use-of-md5": [
59+
"severity:HIGH"
60+
],
61+
"java.security.use-of-default-aes": [
62+
"severity:HIGH"
63+
],
64+
"java.security.jjwt-none-alg": [
65+
"severity:CRITICAL"
66+
],
67+
"java.security.string-normalize-after-validation": [
68+
"severity:HIGH"
69+
],
70+
"java.security.jjwt-hs256": [
71+
"severity:HIGH"
72+
],
73+
"java.security.apache-rpc-enabled-extensions": [
74+
"severity:HIGH"
75+
],
76+
"java.security.wicket-xss": [
77+
"severity:HIGH"
78+
],
79+
"java.security.hardcoded-password": [
80+
"severity:CRITICAL"
81+
],
82+
"java.security.desede-is-deprecated": [
83+
"severity:HIGH"
84+
],
85+
"java.security.java-saml-ignore-comments": [
86+
"severity:HIGH"
87+
],
88+
"java.security.ldap-entry-poisoning": [
89+
"severity:HIGH"
90+
],
91+
"java.security.no-null-cipher": [
92+
"severity:HIGH"
93+
],
94+
"java.security.cookie-missing-httponly": [
95+
"severity:HIGH"
96+
],
97+
"java.security.cbc-padding-oracle": [
98+
"severity:HIGH"
99+
],
100+
"java.security.des-is-deprecated": [
101+
"severity:HIGH"
102+
],
103+
"java.security.stacktrace-printing-in-error-message": [
104+
"severity:HIGH"
105+
],
106+
"java.security.jwt-none-alg": [
107+
"severity:CRITICAL"
108+
],
109+
"java.security.aes-hardcoded-key": [
110+
"severity:HIGH"
111+
],
112+
"java.security.weak-ec-key-size": [
113+
"severity:HIGH"
114+
],
115+
"java.security.permissive-cors": [
116+
"severity:HIGH"
117+
],
118+
"java.security.rsa-no-padding": [
119+
"severity:HIGH"
120+
],
121+
"java.security.cookie-issecure-false": [
122+
"severity:HIGH"
123+
],
124+
"java.security.mongo-hostname-verification-disabled": [
125+
"severity:HIGH"
126+
],
127+
"java.security.defaulthttpclient-is-deprecated": [
128+
"severity:HIGH"
129+
],
130+
"java.security.unrestricted-request-mapping": [
131+
"severity:HIGH"
132+
],
133+
"java.security.ecb-cipher": [
134+
"severity:HIGH"
135+
],
136+
"java.security.hazelcast-symmetric-encryption": [
137+
"severity:HIGH"
138+
],
139+
"java.security.jwt-hardcoded-secret": [
140+
"severity:HIGH"
141+
],
142+
"java.security.default-resteasy-provider-abuse": [
143+
"severity:HIGH"
144+
],
145+
"java.security.unsafe-reflection-in-servlet-app": [
146+
"severity:HIGH"
147+
],
148+
"java.security.format-string-external-manipulation-in-spring-app": [
149+
"severity:HIGH"
150+
],
151+
"java.security.http-response-splitting-in-servlet-app": [
152+
"severity:HIGH"
153+
],
154+
"java.security.ssti-in-spring-app": [
155+
"severity:CRITICAL"
156+
],
157+
"java.security.bean-injection": [
158+
"severity:CRITICAL"
159+
],
160+
"java.security.groovy-injection-in-servlet-app": [
161+
"severity:CRITICAL"
162+
],
163+
"java.security.spring-el-injection": [
164+
"severity:CRITICAL"
165+
],
166+
"java.security.file-disclosure-request-dispatcher": [
167+
"severity:CRITICAL"
168+
],
169+
"java.security.xpath-injection-in-servlet-app": [
170+
"severity:CRITICAL"
171+
],
172+
"java.security.unvalidated-redirect-in-servlet-app": [
173+
"severity:HIGH"
174+
],
175+
"java.security.xxe-in-spring-app": [
176+
"severity:CRITICAL"
177+
],
178+
"java.security.xxe-in-servlet-app": [
179+
"severity:CRITICAL"
180+
],
181+
"java.security.mongodb-injection-in-spring-app": [
182+
"severity:CRITICAL"
183+
],
184+
"java.security.unsafe-object-mapper-in-spring-app": [
185+
"severity:CRITICAL"
186+
],
187+
"java.security.path-traversal-in-servlet-app": [
188+
"severity:CRITICAL"
189+
],
190+
"java.security.xss-in-spring-app": [
191+
"severity:CRITICAL"
192+
],
193+
"java.security.unsafe-jackson-deserialization-in-servlet-app": [
194+
"severity:CRITICAL"
195+
],
196+
"java.security.sql-injection-in-servlet-app": [
197+
"severity:CRITICAL"
198+
],
199+
"java.security.os-command-injection-in-servlet-app": [
200+
"severity:CRITICAL"
201+
],
202+
"java.security.unsafe-jackson-deserialization-in-spring-app": [
203+
"severity:CRITICAL"
204+
],
205+
"java.security.unsafe-reflection-in-spring-app": [
206+
"severity:HIGH"
207+
],
208+
"java.security.el-injection-in-servlet-app": [
209+
"severity:CRITICAL"
210+
],
211+
"java.security.java-servlet-unsafe-snake-yaml-deserialization": [
212+
"severity:CRITICAL"
213+
],
214+
"java.security.format-string-external-manipulation-in-servlet-app": [
215+
"severity:HIGH"
216+
],
217+
"java.security.ssrf-in-servlet-app": [
218+
"severity:CRITICAL"
219+
],
220+
"java.security.java-servlet-parameter-pollution": [
221+
"severity:CRITICAL"
222+
],
223+
"java.security.unvalidated-redirect-in-spring-app": [
224+
"severity:HIGH"
225+
],
226+
"java.security.ldap-injection-in-servlet-app": [
227+
"severity:CRITICAL"
228+
],
229+
"java.security.ldap-injection-in-spring-app": [
230+
"severity:CRITICAL"
231+
],
232+
"java.security.os-command-injection-in-spring-app": [
233+
"severity:CRITICAL"
234+
],
235+
"java.security.ssrf-in-spring-app": [
236+
"severity:CRITICAL"
237+
],
238+
"java.security.spring-unsafe-snake-yaml-deserialization": [
239+
"severity:CRITICAL"
240+
],
241+
"java.security.xpath-injection-in-spring-app": [
242+
"severity:CRITICAL"
243+
],
244+
"java.security.jsp-file-disclosure": [
245+
"severity:CRITICAL"
246+
],
247+
"java.security.http-response-splitting-in-spring-app": [
248+
"severity:HIGH"
249+
],
250+
"java.security.java-servlet-smtp-crlf-injection": [
251+
"severity:CRITICAL"
252+
],
253+
"java.security.ssti-in-servlet-app": [
254+
"severity:CRITICAL"
255+
],
256+
"java.security.mongodb-injection-in-servlet-app": [
257+
"severity:CRITICAL"
258+
],
259+
"java.security.sql-catalog-external-manipulation-in-servlet-app": [
260+
"severity:CRITICAL"
261+
],
262+
"java.security.sql-catalog-external-manipulation-in-spring-app": [
263+
"severity:CRITICAL"
264+
],
265+
"java.security.unsafe-object-mapper-in-servlet-app": [
266+
"severity:CRITICAL"
267+
],
268+
"java.security.seam-log-injection": [
269+
"severity:CRITICAL"
270+
],
271+
"java.security.ognl-injection-in-servlet-app": [
272+
"severity:CRITICAL"
273+
],
274+
"java.security.script-engine-injection-in-servlet-app": [
275+
"severity:CRITICAL"
276+
],
277+
"java.security.sql-injection-in-spring-app": [
278+
"severity:CRITICAL"
279+
],
280+
"java.security.xss-in-servlet-app": [
281+
"severity:CRITICAL"
282+
],
283+
"java.security.spring-smtp-crlf-injection": [
284+
"severity:CRITICAL"
285+
],
286+
"java.security.script-engine-injection-in-spring-app": [
287+
"severity:CRITICAL"
288+
],
289+
"java.security.path-traversal-in-spring-app": [
290+
"severity:CRITICAL"
291+
],
292+
"java.security.ognl-injection-in-spring-app": [
293+
"severity:CRITICAL"
294+
],
295+
"java.security.groovy-injection-in-spring-app": [
296+
"severity:CRITICAL"
297+
]
298+
}
299+
}

0 commit comments

Comments
 (0)