1+ {
2+ "analyzer" : " seqra" ,
3+ "labels" : {
4+ "java.security.avoid-implementing-custom-digests" : [
5+ " severity:HIGH"
6+ ],
7+ "java.security.insecure-resteasy-deserialization" : [
8+ " severity:HIGH"
9+ ],
10+ "java.security.overly-permissive-file-permission-inline" : [
11+ " severity:HIGH"
12+ ],
13+ "java.security.gcm-nonce-reuse" : [
14+ " severity:HIGH"
15+ ],
16+ "java.security.use-of-rc2" : [
17+ " severity:HIGH"
18+ ],
19+ "java.security.use-of-rc4" : [
20+ " severity:HIGH"
21+ ],
22+ "java.security.csrf-disabled-in-spring-app" : [
23+ " severity:HIGH"
24+ ],
25+ "java.security.java-jwt-decode-without-verify" : [
26+ " severity:HIGH"
27+ ],
28+ "java.security.dangerous-permissions" : [
29+ " severity:HIGH"
30+ ],
31+ "java.security.use-of-sha1" : [
32+ " severity:HIGH"
33+ ],
34+ "java.security.constant-db-password" : [
35+ " severity:CRITICAL"
36+ ],
37+ "java.security.bad-hexa-conversion" : [
38+ " severity:HIGH"
39+ ],
40+ "java.security.server-dangerous-object-deserialization" : [
41+ " severity:CRITICAL"
42+ ],
43+ "java.security.url-rewriting" : [
44+ " severity:HIGH"
45+ ],
46+ "java.security.java-empty-db-password" : [
47+ " severity:CRITICAL"
48+ ],
49+ "java.security.use-of-blowfish" : [
50+ " severity:HIGH"
51+ ],
52+ "java.security.insecure-jms-deserialization" : [
53+ " severity:HIGH"
54+ ],
55+ "java.security.java-anonymous-ldap" : [
56+ " severity:HIGH"
57+ ],
58+ "java.security.use-of-md5" : [
59+ " severity:HIGH"
60+ ],
61+ "java.security.use-of-default-aes" : [
62+ " severity:HIGH"
63+ ],
64+ "java.security.jjwt-none-alg" : [
65+ " severity:CRITICAL"
66+ ],
67+ "java.security.string-normalize-after-validation" : [
68+ " severity:HIGH"
69+ ],
70+ "java.security.jjwt-hs256" : [
71+ " severity:HIGH"
72+ ],
73+ "java.security.apache-rpc-enabled-extensions" : [
74+ " severity:HIGH"
75+ ],
76+ "java.security.wicket-xss" : [
77+ " severity:HIGH"
78+ ],
79+ "java.security.hardcoded-password" : [
80+ " severity:CRITICAL"
81+ ],
82+ "java.security.desede-is-deprecated" : [
83+ " severity:HIGH"
84+ ],
85+ "java.security.java-saml-ignore-comments" : [
86+ " severity:HIGH"
87+ ],
88+ "java.security.ldap-entry-poisoning" : [
89+ " severity:HIGH"
90+ ],
91+ "java.security.no-null-cipher" : [
92+ " severity:HIGH"
93+ ],
94+ "java.security.cookie-missing-httponly" : [
95+ " severity:HIGH"
96+ ],
97+ "java.security.cbc-padding-oracle" : [
98+ " severity:HIGH"
99+ ],
100+ "java.security.des-is-deprecated" : [
101+ " severity:HIGH"
102+ ],
103+ "java.security.stacktrace-printing-in-error-message" : [
104+ " severity:HIGH"
105+ ],
106+ "java.security.jwt-none-alg" : [
107+ " severity:CRITICAL"
108+ ],
109+ "java.security.aes-hardcoded-key" : [
110+ " severity:HIGH"
111+ ],
112+ "java.security.weak-ec-key-size" : [
113+ " severity:HIGH"
114+ ],
115+ "java.security.permissive-cors" : [
116+ " severity:HIGH"
117+ ],
118+ "java.security.rsa-no-padding" : [
119+ " severity:HIGH"
120+ ],
121+ "java.security.cookie-issecure-false" : [
122+ " severity:HIGH"
123+ ],
124+ "java.security.mongo-hostname-verification-disabled" : [
125+ " severity:HIGH"
126+ ],
127+ "java.security.defaulthttpclient-is-deprecated" : [
128+ " severity:HIGH"
129+ ],
130+ "java.security.unrestricted-request-mapping" : [
131+ " severity:HIGH"
132+ ],
133+ "java.security.ecb-cipher" : [
134+ " severity:HIGH"
135+ ],
136+ "java.security.hazelcast-symmetric-encryption" : [
137+ " severity:HIGH"
138+ ],
139+ "java.security.jwt-hardcoded-secret" : [
140+ " severity:HIGH"
141+ ],
142+ "java.security.default-resteasy-provider-abuse" : [
143+ " severity:HIGH"
144+ ],
145+ "java.security.unsafe-reflection-in-servlet-app" : [
146+ " severity:HIGH"
147+ ],
148+ "java.security.format-string-external-manipulation-in-spring-app" : [
149+ " severity:HIGH"
150+ ],
151+ "java.security.http-response-splitting-in-servlet-app" : [
152+ " severity:HIGH"
153+ ],
154+ "java.security.ssti-in-spring-app" : [
155+ " severity:CRITICAL"
156+ ],
157+ "java.security.bean-injection" : [
158+ " severity:CRITICAL"
159+ ],
160+ "java.security.groovy-injection-in-servlet-app" : [
161+ " severity:CRITICAL"
162+ ],
163+ "java.security.spring-el-injection" : [
164+ " severity:CRITICAL"
165+ ],
166+ "java.security.file-disclosure-request-dispatcher" : [
167+ " severity:CRITICAL"
168+ ],
169+ "java.security.xpath-injection-in-servlet-app" : [
170+ " severity:CRITICAL"
171+ ],
172+ "java.security.unvalidated-redirect-in-servlet-app" : [
173+ " severity:HIGH"
174+ ],
175+ "java.security.xxe-in-spring-app" : [
176+ " severity:CRITICAL"
177+ ],
178+ "java.security.xxe-in-servlet-app" : [
179+ " severity:CRITICAL"
180+ ],
181+ "java.security.mongodb-injection-in-spring-app" : [
182+ " severity:CRITICAL"
183+ ],
184+ "java.security.unsafe-object-mapper-in-spring-app" : [
185+ " severity:CRITICAL"
186+ ],
187+ "java.security.path-traversal-in-servlet-app" : [
188+ " severity:CRITICAL"
189+ ],
190+ "java.security.xss-in-spring-app" : [
191+ " severity:CRITICAL"
192+ ],
193+ "java.security.unsafe-jackson-deserialization-in-servlet-app" : [
194+ " severity:CRITICAL"
195+ ],
196+ "java.security.sql-injection-in-servlet-app" : [
197+ " severity:CRITICAL"
198+ ],
199+ "java.security.os-command-injection-in-servlet-app" : [
200+ " severity:CRITICAL"
201+ ],
202+ "java.security.unsafe-jackson-deserialization-in-spring-app" : [
203+ " severity:CRITICAL"
204+ ],
205+ "java.security.unsafe-reflection-in-spring-app" : [
206+ " severity:HIGH"
207+ ],
208+ "java.security.el-injection-in-servlet-app" : [
209+ " severity:CRITICAL"
210+ ],
211+ "java.security.java-servlet-unsafe-snake-yaml-deserialization" : [
212+ " severity:CRITICAL"
213+ ],
214+ "java.security.format-string-external-manipulation-in-servlet-app" : [
215+ " severity:HIGH"
216+ ],
217+ "java.security.ssrf-in-servlet-app" : [
218+ " severity:CRITICAL"
219+ ],
220+ "java.security.java-servlet-parameter-pollution" : [
221+ " severity:CRITICAL"
222+ ],
223+ "java.security.unvalidated-redirect-in-spring-app" : [
224+ " severity:HIGH"
225+ ],
226+ "java.security.ldap-injection-in-servlet-app" : [
227+ " severity:CRITICAL"
228+ ],
229+ "java.security.ldap-injection-in-spring-app" : [
230+ " severity:CRITICAL"
231+ ],
232+ "java.security.os-command-injection-in-spring-app" : [
233+ " severity:CRITICAL"
234+ ],
235+ "java.security.ssrf-in-spring-app" : [
236+ " severity:CRITICAL"
237+ ],
238+ "java.security.spring-unsafe-snake-yaml-deserialization" : [
239+ " severity:CRITICAL"
240+ ],
241+ "java.security.xpath-injection-in-spring-app" : [
242+ " severity:CRITICAL"
243+ ],
244+ "java.security.jsp-file-disclosure" : [
245+ " severity:CRITICAL"
246+ ],
247+ "java.security.http-response-splitting-in-spring-app" : [
248+ " severity:HIGH"
249+ ],
250+ "java.security.java-servlet-smtp-crlf-injection" : [
251+ " severity:CRITICAL"
252+ ],
253+ "java.security.ssti-in-servlet-app" : [
254+ " severity:CRITICAL"
255+ ],
256+ "java.security.mongodb-injection-in-servlet-app" : [
257+ " severity:CRITICAL"
258+ ],
259+ "java.security.sql-catalog-external-manipulation-in-servlet-app" : [
260+ " severity:CRITICAL"
261+ ],
262+ "java.security.sql-catalog-external-manipulation-in-spring-app" : [
263+ " severity:CRITICAL"
264+ ],
265+ "java.security.unsafe-object-mapper-in-servlet-app" : [
266+ " severity:CRITICAL"
267+ ],
268+ "java.security.seam-log-injection" : [
269+ " severity:CRITICAL"
270+ ],
271+ "java.security.ognl-injection-in-servlet-app" : [
272+ " severity:CRITICAL"
273+ ],
274+ "java.security.script-engine-injection-in-servlet-app" : [
275+ " severity:CRITICAL"
276+ ],
277+ "java.security.sql-injection-in-spring-app" : [
278+ " severity:CRITICAL"
279+ ],
280+ "java.security.xss-in-servlet-app" : [
281+ " severity:CRITICAL"
282+ ],
283+ "java.security.spring-smtp-crlf-injection" : [
284+ " severity:CRITICAL"
285+ ],
286+ "java.security.script-engine-injection-in-spring-app" : [
287+ " severity:CRITICAL"
288+ ],
289+ "java.security.path-traversal-in-spring-app" : [
290+ " severity:CRITICAL"
291+ ],
292+ "java.security.ognl-injection-in-spring-app" : [
293+ " severity:CRITICAL"
294+ ],
295+ "java.security.groovy-injection-in-spring-app" : [
296+ " severity:CRITICAL"
297+ ]
298+ }
299+ }
0 commit comments