Skip to content

Commit 3e80095

Browse files
authored
Merge pull request #1625 from zapbot/update-site-content
Update site content
2 parents 6f1bab1 + f1d977d commit 3e80095

File tree

16 files changed

+335
-102
lines changed

16 files changed

+335
-102
lines changed

alerttags/cwe-200/index.html

Lines changed: 0 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -211,48 +211,12 @@ <h4><a href="https://cwe.mitre.org/data/definitions/200.html">https://cwe.mitre.
211211
</tr>
212212

213213

214-
<tr>
215-
<td><a href="/docs/alerts/120000-1/">Information Disclosure - Information in Browser localStorage</a></td>
216-
<td><a href=""></a></td>
217-
</tr>
218-
219-
220-
<tr>
221-
<td><a href="/docs/alerts/120000-2/">Information Disclosure - Information in Browser sessionStorage</a></td>
222-
<td><a href=""></a></td>
223-
</tr>
224-
225-
226-
<tr>
227-
<td><a href="/docs/alerts/120002-1/">Information Disclosure - JWT in Browser localStorage</a></td>
228-
<td><a href=""></a></td>
229-
</tr>
230-
231-
232-
<tr>
233-
<td><a href="/docs/alerts/120002-2/">Information Disclosure - JWT in Browser sessionStorage</a></td>
234-
<td><a href=""></a></td>
235-
</tr>
236-
237-
238214
<tr>
239215
<td><a href="/docs/alerts/100013/">Information Disclosure - Private IP Address</a></td>
240216
<td><a href=""></a></td>
241217
</tr>
242218

243219

244-
<tr>
245-
<td><a href="/docs/alerts/120001-1/">Information Disclosure - Sensitive Information in Browser localStorage</a></td>
246-
<td><a href=""></a></td>
247-
</tr>
248-
249-
250-
<tr>
251-
<td><a href="/docs/alerts/120001-2/">Information Disclosure - Sensitive Information in Browser sessionStorage</a></td>
252-
<td><a href=""></a></td>
253-
</tr>
254-
255-
256220
<tr>
257221
<td><a href="/docs/alerts/10025/">Information Disclosure - Sensitive Information in HTTP Referrer Header</a></td>
258222
<td><a href=""></a></td>

alerttags/cwe-200/index.xml

Lines changed: 0 additions & 42 deletions
Original file line numberDiff line numberDiff line change
@@ -84,55 +84,13 @@
8484
<guid>/docs/alerts/100012/</guid>
8585
<description>&lt;p&gt;An IBAN number was discovered in the HTTP response body.&lt;/p&gt;</description>
8686
</item>
87-
<item>
88-
<title>Information Disclosure - Information in Browser localStorage</title>
89-
<link>/docs/alerts/120000-1/</link>
90-
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
91-
<guid>/docs/alerts/120000-1/</guid>
92-
<description>&lt;p&gt;Information was stored in browser localStorage.&#xA;This is not unusual or necessarily unsafe - this informational alert has been raised to help you get a better understanding of what this app is doing. For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
93-
</item>
94-
<item>
95-
<title>Information Disclosure - Information in Browser sessionStorage</title>
96-
<link>/docs/alerts/120000-2/</link>
97-
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
98-
<guid>/docs/alerts/120000-2/</guid>
99-
<description>&lt;p&gt;Information was stored in browser sessionStorage.&#xA;This is not unusual or necessarily unsafe - this informational alert has been raised to help you get a better understanding of what this app is doing. For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
100-
</item>
101-
<item>
102-
<title>Information Disclosure - JWT in Browser localStorage</title>
103-
<link>/docs/alerts/120002-1/</link>
104-
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
105-
<guid>/docs/alerts/120002-1/</guid>
106-
<description>&lt;p&gt;JWT was stored in browser localStorage.&#xA;This is dangerous because data stored in localStorage does not expire. .&lt;/p&gt;</description>
107-
</item>
108-
<item>
109-
<title>Information Disclosure - JWT in Browser sessionStorage</title>
110-
<link>/docs/alerts/120002-2/</link>
111-
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
112-
<guid>/docs/alerts/120002-2/</guid>
113-
<description>&lt;p&gt;JWT was stored in browser sessionStorage.&#xA;This is not unusual or necessarily unsafe - this informational alert has been raised to help you get a better understanding of what this app is doing. For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
114-
</item>
11587
<item>
11688
<title>Information Disclosure - Private IP Address</title>
11789
<link>/docs/alerts/100013/</link>
11890
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
11991
<guid>/docs/alerts/100013/</guid>
12092
<description>&lt;p&gt;A private IP such as 10.x.x.x, 172.x.x.x, 192.168.x.x or IPV6 fe00:: has been found in the HTTP response body. This information might be helpful for further attacks targeting internal systems.&lt;/p&gt;</description>
12193
</item>
122-
<item>
123-
<title>Information Disclosure - Sensitive Information in Browser localStorage</title>
124-
<link>/docs/alerts/120001-1/</link>
125-
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
126-
<guid>/docs/alerts/120001-1/</guid>
127-
<description>&lt;p&gt;Sensitive Information appears to have been stored in browser localStorage. This can violate PCI and most organizational compliance policies.&#xA;For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
128-
</item>
129-
<item>
130-
<title>Information Disclosure - Sensitive Information in Browser sessionStorage</title>
131-
<link>/docs/alerts/120001-2/</link>
132-
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
133-
<guid>/docs/alerts/120001-2/</guid>
134-
<description>&lt;p&gt;Sensitive Information appears to have been stored in browser sessionStorage. This can violate PCI and most organizational compliance policies.&#xA;For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
135-
</item>
13694
<item>
13795
<title>Information Disclosure - Sensitive Information in HTTP Referrer Header</title>
13896
<link>/docs/alerts/10025/</link>

alerttags/cwe-359/index.html

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -145,6 +145,30 @@ <h4><a href="https://cwe.mitre.org/data/definitions/359.html">https://cwe.mitre.
145145
<tbody>
146146

147147

148+
<tr>
149+
<td><a href="/docs/alerts/120000-1/">Information Disclosure - Information in Browser localStorage</a></td>
150+
<td><a href=""></a></td>
151+
</tr>
152+
153+
154+
<tr>
155+
<td><a href="/docs/alerts/120000-2/">Information Disclosure - Information in Browser sessionStorage</a></td>
156+
<td><a href=""></a></td>
157+
</tr>
158+
159+
160+
<tr>
161+
<td><a href="/docs/alerts/120001-1/">Information Disclosure - Sensitive Information in Browser localStorage</a></td>
162+
<td><a href=""></a></td>
163+
</tr>
164+
165+
166+
<tr>
167+
<td><a href="/docs/alerts/120001-2/">Information Disclosure - Sensitive Information in Browser sessionStorage</a></td>
168+
<td><a href=""></a></td>
169+
</tr>
170+
171+
148172
<tr>
149173
<td><a href="/docs/alerts/10062/">PII Disclosure</a></td>
150174
<td><a href=""></a></td>

alerttags/cwe-359/index.xml

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,34 @@
77
<generator>Hugo</generator>
88
<language>en-us</language>
99
<atom:link href="/alerttags/cwe-359/index.xml" rel="self" type="application/rss+xml" />
10+
<item>
11+
<title>Information Disclosure - Information in Browser localStorage</title>
12+
<link>/docs/alerts/120000-1/</link>
13+
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
14+
<guid>/docs/alerts/120000-1/</guid>
15+
<description>&lt;p&gt;Information was stored in browser localStorage.&#xA;This is not unusual or necessarily unsafe - this informational alert has been raised to help you get a better understanding of what this app is doing. For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
16+
</item>
17+
<item>
18+
<title>Information Disclosure - Information in Browser sessionStorage</title>
19+
<link>/docs/alerts/120000-2/</link>
20+
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
21+
<guid>/docs/alerts/120000-2/</guid>
22+
<description>&lt;p&gt;Information was stored in browser sessionStorage.&#xA;This is not unusual or necessarily unsafe - this informational alert has been raised to help you get a better understanding of what this app is doing. For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
23+
</item>
24+
<item>
25+
<title>Information Disclosure - Sensitive Information in Browser localStorage</title>
26+
<link>/docs/alerts/120001-1/</link>
27+
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
28+
<guid>/docs/alerts/120001-1/</guid>
29+
<description>&lt;p&gt;Sensitive Information appears to have been stored in browser localStorage. This can violate PCI and most organizational compliance policies.&#xA;For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
30+
</item>
31+
<item>
32+
<title>Information Disclosure - Sensitive Information in Browser sessionStorage</title>
33+
<link>/docs/alerts/120001-2/</link>
34+
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
35+
<guid>/docs/alerts/120001-2/</guid>
36+
<description>&lt;p&gt;Sensitive Information appears to have been stored in browser sessionStorage. This can violate PCI and most organizational compliance policies.&#xA;For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
37+
</item>
1038
<item>
1139
<title>PII Disclosure</title>
1240
<link>/docs/alerts/10062/</link>

alerttags/cwe-922/index.html

Lines changed: 219 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,219 @@
1+
<!doctype html>
2+
<html lang="en">
3+
4+
<head>
5+
<meta charset="utf-8">
6+
<meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover">
7+
<meta name="description" content="The world’s most widely used web app scanner. Free and open source. ZAP is a community project actively maintained by a dedicated international team, and a GitHub Top 1000 project.">
8+
9+
<link rel="alternate" type="application/rss+xml" href="/alerttags/cwe-922/index.xml" title="ZAP" />
10+
<title>ZAP &ndash; CWE-922</title>
11+
12+
<link rel="shortcut icon" href="/img/favicon.ico" type="image/x-icon" />
13+
<link href="https://fonts.googleapis.com/css?family=Quicksand:500,700" rel="stylesheet">
14+
<link href="https://fonts.googleapis.com/css?family=Istok+Web|Open+Sans:400,700|Rubik&display=swap" rel="stylesheet">
15+
<script src="https://cdnjs.cloudflare.com/ajax/libs/lunr.js/2.3.6/lunr.min.js"></script>
16+
17+
<script async src="https://www.googletagmanager.com/gtag/js?id=G-JDLGW1172L"></script>
18+
<script>
19+
window.dataLayer = window.dataLayer || [];
20+
function gtag(){dataLayer.push(arguments);}
21+
gtag('js', new Date());
22+
gtag('config', 'G-JDLGW1172L');
23+
</script>
24+
25+
26+
27+
<link href="/main.90b582.css" rel="stylesheet">
28+
29+
</head>
30+
<body>
31+
<div id="page-container">
32+
<div id="content-wrap">
33+
<header class="site-header">
34+
<div class="wrapper flex jc-sb ai-c">
35+
<div class="flex">
36+
<nav class="site-nav" role="navigation">
37+
<a href="/" aria-label="return to landing page" class="logo">
38+
<img src = "/img/zap-by-checkmarx.svg" height="65px" alt="ZAP By Checkmarx"/>
39+
</a>
40+
</nav>
41+
</div>
42+
<div class="nav-content flex">
43+
<nav class="site-nav" role="navigation">
44+
<div class="hamburger-icon">
45+
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24"><path d="M0 0h24v24H0z" fill="none"/><path d="M3 18h18v-2H3v2zm0-5h18v-2H3v2zm0-7v2h18V6H3z"/></svg>
46+
</div>
47+
<input class="hamburger-click" aria-label="site menu" type="checkbox" />
48+
<ul id="primary-menu" class="flex">
49+
50+
51+
52+
<li class="">
53+
<a href="/blog/" title="Blog page">
54+
Blog
55+
</a>
56+
</li>
57+
58+
59+
60+
<li class="">
61+
<a href="/videos/" title="Videos page">
62+
Videos
63+
</a>
64+
</li>
65+
66+
67+
68+
<li class="">
69+
<a href="/docs/" title="Documentation page">
70+
Documentation
71+
</a>
72+
</li>
73+
74+
75+
76+
<li class="">
77+
<a href="/community/" title="Community page">
78+
Community
79+
</a>
80+
</li>
81+
82+
83+
<li id="search-menu">
84+
<a class="toggler" href="#">
85+
<img height="20" width="20" src="/img/search.svg" alt="Search icon"/>
86+
</a>
87+
88+
<form data-no-csrf action="/search">
89+
<input type="text" name="q" placeholder="Search ..." style="width: 100%" />
90+
</form>
91+
</li>
92+
</ul>
93+
</nav>
94+
<div class="download-button">
95+
<a id="cta-download" href="/download/" class="button button--orange">Download</a>
96+
</div>
97+
<div class="social-links header-social">
98+
<ul class="flex ai-c no-list-style m-10 px-20">
99+
<li>
100+
<a href="https://github.com/zaproxy" aria-label="Go to ZAP's GitHub repo"> <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 19.36 18.88"><path d="M9.68 0a9.68 9.68 0 0 0-3.06 18.86c.48.09.64-.21.64-.46v-1.8C4.57 17.18 4 15.45 4 15.45A2.57 2.57 0 0 0 2.93 14c-.88-.6.07-.59.07-.59a2 2 0 0 1 1.48 1 2.06 2.06 0 0 0 2.82.8A2 2 0 0 1 7.91 14c-2.15-.29-4.41-1.12-4.41-4.83a3.72 3.72 0 0 1 1-2.59A3.53 3.53 0 0 1 4.59 4s.82-.26 2.67 1a9 9 0 0 1 4.84 0c1.9-1.25 2.66-1 2.66-1a3.49 3.49 0 0 1 .1 2.57 3.71 3.71 0 0 1 1 2.59c0 3.72-2.26 4.54-4.42 4.78a2.3 2.3 0 0 1 .67 1.79v2.67c0 .25.15.56.64.46A9.68 9.68 0 0 0 9.68 0z" fill="#00549e"/></svg></a>
101+
</li>
102+
<li>
103+
<a href="https://twitter.com/zaproxy" aria-label="Follow ZAP on Twitter"> <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 19.36 15.73"><path d="M19.36 1.86a8 8 0 0 1-2.28.63 3.94 3.94 0 0 0 1.74-2.2 7.53 7.53 0 0 1-2.52 1 4 4 0 0 0-6.77 3.59A11.29 11.29 0 0 1 1.35.73 4 4 0 0 0 2.58 6a3.91 3.91 0 0 1-1.8-.5A4 4 0 0 0 4 9.48a4 4 0 0 1-1.79.06 4 4 0 0 0 3.67 2.76A8 8 0 0 1 0 14a11.32 11.32 0 0 0 6.09 1.78A11.24 11.24 0 0 0 17.38 3.92a8.08 8.08 0 0 0 1.98-2.06z" fill="#00549e"/></svg></a>
104+
</li>
105+
</ul>
106+
</div>
107+
</div>
108+
109+
</div>
110+
</header>
111+
112+
113+
<section class="bolt-header">
114+
<div class="wrapper py-20">
115+
116+
<h1 class="text--white">Alert Tag: CWE-922</h1>
117+
118+
</div>
119+
</section>
120+
<div class="wrapper py-70">
121+
<header class="breadcrumbs">
122+
<a href="/alerttags/">Alert Tags</a> &gt;
123+
124+
<a href="/alerttags/cwe-922">CWE-922</a>
125+
126+
</header>
127+
128+
129+
130+
131+
132+
<h4><a href="https://cwe.mitre.org/data/definitions/922.html">https://cwe.mitre.org/data/definitions/922.html</a></h4>
133+
134+
All of the alerts which use this tag:
135+
136+
137+
<div class="flex latest-versions">
138+
<table data-sort-filter>
139+
<thead>
140+
<tr>
141+
<th>Tag</th>
142+
<th>Link</th>
143+
</tr>
144+
</thead>
145+
<tbody>
146+
147+
148+
<tr>
149+
<td><a href="/docs/alerts/120002-1/">Information Disclosure - JWT in Browser localStorage</a></td>
150+
<td><a href=""></a></td>
151+
</tr>
152+
153+
154+
<tr>
155+
<td><a href="/docs/alerts/120002-2/">Information Disclosure - JWT in Browser sessionStorage</a></td>
156+
<td><a href=""></a></td>
157+
</tr>
158+
159+
</tbody>
160+
</table>
161+
</div>
162+
</div>
163+
164+
</div>
165+
<footer class="site-footer py-20 mt-20">
166+
<div class="wrapper flex jc-sb">
167+
<div class="flex ai-c">
168+
<div class="footer-logo"><svg xmlns="http://www.w3.org/2000/svg" width="55px" viewBox="0 0 77.58 77.61"><path d="M49.48 21.64a3.46 3.46 0 0 1 .44 3 3.38 3.38 0 0 1-2.16 2.14l-1.17.38 10.74 13.56a3.39 3.39 0 0 1-1.83 5.41l-2 .5L68 65A37.78 37.78 0 0 0 39.85 2c-1.34 0-2.66.07-4 .2zM23.33 48.26a3.4 3.4 0 0 1 .45-6.09L25 41.7l-13.81-10a3.4 3.4 0 0 1 .62-5.86l.2-.09-5.47-3.84a37.79 37.79 0 0 0 55.32 48.6z" fill="#fff"/><path d="M67.84 69.48L49 45.59a.55.55 0 0 1 .28-.87l5.55-1.36a.58.58 0 0 0 .23-.13.48.48 0 0 0 .09-.11.62.62 0 0 0 .08-.24.58.58 0 0 0 0-.26.54.54 0 0 0-.07-.13L42.29 26.37a.75.75 0 0 1-.07-.12.55.55 0 0 1 .31-.74l4.35-1.4a.54.54 0 0 0 .26-.83L30.92.22a.5.5 0 0 0-.61-.22L.32 13a.55.55 0 0 0-.1.94l16.72 11.88a.52.52 0 0 1 .22.49.45.45 0 0 1-.09.26.48.48 0 0 1-.09.11l-.13.08-3.93 1.72a.55.55 0 0 0-.29.31v.13a.59.59 0 0 0 .22.5l8.62 6.22 8.61 6.21a.55.55 0 0 1 0 .87.57.57 0 0 1-.13.08l-5.11 2a.55.55 0 0 0-.28.75.56.56 0 0 0 .21.22l42.43 24.5a.53.53 0 0 0 .64-.79z" fill="#fff"/></svg></div>
169+
<div class="footer-left">
170+
<nav class="footer-nav">
171+
<ul class="flex">
172+
173+
174+
175+
<li class="ml-10"><a href="/blog/" title="Blog page">Blog</a></li>
176+
177+
178+
179+
<li class="ml-10"><a href="/videos/" title="Videos page">Videos</a></li>
180+
181+
182+
183+
<li class="ml-10"><a href="/community/" title="Community page">Community</a></li>
184+
185+
186+
187+
<li class="ml-10"><a href="/docs/statistics/" title="Statistics page">Statistics</a></li>
188+
189+
190+
</ul>
191+
</nav>
192+
193+
</div>
194+
</div>
195+
196+
<div class="flex ai-c">
197+
<span class="OutroFooter">
198+
© Copyright 2024 the ZAP Dev Team</br>
199+
ZAP by <a href="https://checkmarx.com" aria-label="Checkmarx">Checkmarx</a>
200+
</span>
201+
<ul class="flex footer-social">
202+
<li>
203+
<a href="https://github.com/zaproxy/" aria-label="Go to ZAP's GitHub repo"> <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 19.36 18.88"><path d="M9.68 0a9.68 9.68 0 0 0-3.06 18.86c.48.09.64-.21.64-.46v-1.8C4.57 17.18 4 15.45 4 15.45A2.57 2.57 0 0 0 2.93 14c-.88-.6.07-.59.07-.59a2 2 0 0 1 1.48 1 2.06 2.06 0 0 0 2.82.8A2 2 0 0 1 7.91 14c-2.15-.29-4.41-1.12-4.41-4.83a3.72 3.72 0 0 1 1-2.59A3.53 3.53 0 0 1 4.59 4s.82-.26 2.67 1a9 9 0 0 1 4.84 0c1.9-1.25 2.66-1 2.66-1a3.49 3.49 0 0 1 .1 2.57 3.71 3.71 0 0 1 1 2.59c0 3.72-2.26 4.54-4.42 4.78a2.3 2.3 0 0 1 .67 1.79v2.67c0 .25.15.56.64.46A9.68 9.68 0 0 0 9.68 0z" fill="#00549e"/></svg></a>
204+
</li>
205+
<li>
206+
<a href="https://twitter.com/zaproxy" aria-label="Follow ZAP on Twitter"> <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 19.36 15.73"><path d="M19.36 1.86a8 8 0 0 1-2.28.63 3.94 3.94 0 0 0 1.74-2.2 7.53 7.53 0 0 1-2.52 1 4 4 0 0 0-6.77 3.59A11.29 11.29 0 0 1 1.35.73 4 4 0 0 0 2.58 6a3.91 3.91 0 0 1-1.8-.5A4 4 0 0 0 4 9.48a4 4 0 0 1-1.79.06 4 4 0 0 0 3.67 2.76A8 8 0 0 1 0 14a11.32 11.32 0 0 0 6.09 1.78A11.24 11.24 0 0 0 17.38 3.92a8.08 8.08 0 0 0 1.98-2.06z" fill="#00549e"/></svg></a>
207+
</li>
208+
</ul>
209+
</div>
210+
</div>
211+
</footer>
212+
213+
214+
215+
<script src="/main.90ed09.js"></script>
216+
217+
</div>
218+
</body>
219+
</html>

0 commit comments

Comments
 (0)