-
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
Description
Security Audit: OWASP Top 10
Perform a comprehensive security audit focusing on OWASP Top 10 vulnerabilities.
Scope
Check for:
- A01:2021 Broken Access Control - Authorization flaws, privilege escalation
- A02:2021 Cryptographic Failures - Weak crypto, exposed secrets
- A03:2021 Injection - SQL, NoSQL, OS, LDAP injection
- A04:2021 Insecure Design - Missing security controls
- A05:2021 Security Misconfiguration - Default configs, verbose errors
- A06:2021 Vulnerable Components - Outdated dependencies
- A07:2021 Auth Failures - Weak passwords, session issues
- A08:2021 Data Integrity Failures - Deserialization, CI/CD
- A09:2021 Logging Failures - Missing audit logs
- A10:2021 SSRF - Server-side request forgery
Output
Save findings to AUDIT-OWASP.md in repository root.
Format
# OWASP Top 10 Security Audit
## Summary
X critical, Y high, Z medium findings
## Findings by Category
### A01: Broken Access Control
- Finding 1...
- Finding 2...
### A02: Cryptographic Failures
...Be thorough. Check every endpoint, every input, every auth flow.