<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-200 on ZAP</title>
    <link>/alerttags/cwe-200/</link>
    <description>Recent content in CWE-200 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-200/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Admin/management path observed</title>
      <link>/docs/alerts/200019-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-1/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Android assetlinks.json observed</title>
      <link>/docs/alerts/200013-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-3/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>API docs endpoint observed</title>
      <link>/docs/alerts/200012-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-3/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apple app-site-association observed</title>
      <link>/docs/alerts/200013-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-4/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AWS Access Key ID pattern</title>
      <link>/docs/alerts/200011-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-2/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud metadata IP referenced</title>
      <link>/docs/alerts/200016-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-4/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Content Security Policy Violations Reporting Enabled</title>
      <link>/docs/alerts/100004/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100004/</guid>
      <description></description>
    </item>
    <item>
      <title>Credit Card Number</title>
      <link>/docs/alerts/200006-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200006-1/</guid>
      <description>&lt;p&gt;Sensitive data is anything that should not be accessible to admin access, known as sensitive data. Sensitive data may include personally identifiable information (PII), such as Social Security numbers, financial information, or login credentials. Sensitive Data Exposure occurs when an organization unknowingly exposes sensitive data or when a security incident leads to the accidental or unlawful destruction, loss, alteration, or admin disclosure of, or access to sensitive data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Debug/diagnostic path observed</title>
      <link>/docs/alerts/200019-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-2/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Environment hints (dev/staging/test) in response</title>
      <link>/docs/alerts/200016-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-3/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Environment/config file observed</title>
      <link>/docs/alerts/200019-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-7/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via fetch headers</title>
      <link>/docs/alerts/210013-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-2/</guid>
      <description>&lt;p&gt;Tainted data sent in fetch() headers (e.g. Authorization, custom tokens).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via fetch URL</title>
      <link>/docs/alerts/210013-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-1/</guid>
      <description>&lt;p&gt;Tainted data used in fetch() URL, potentially exfiltrating sensitive information.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via image.src beacon</title>
      <link>/docs/alerts/210013-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-7/</guid>
      <description>&lt;p&gt;Tainted data embedded into image src URL for beacon-style exfiltration.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via navigator.sendBeacon</title>
      <link>/docs/alerts/210013-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-6/</guid>
      <description>&lt;p&gt;Tainted data sent via navigator.sendBeacon().&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via XMLHttpRequest body</title>
      <link>/docs/alerts/210013-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-4/</guid>
      <description>&lt;p&gt;Tainted data sent in XMLHttpRequest.send() body.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via XMLHttpRequest headers</title>
      <link>/docs/alerts/210013-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-5/</guid>
      <description>&lt;p&gt;Tainted data sent in XMLHttpRequest.setRequestHeader() values.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via XMLHttpRequest URL</title>
      <link>/docs/alerts/210013-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-3/</guid>
      <description>&lt;p&gt;Tainted data used in XMLHttpRequest.open() URL.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Firebase config exposed</title>
      <link>/docs/alerts/200011-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-6/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GitHub token pattern</title>
      <link>/docs/alerts/200011-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-4/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Google API key pattern</title>
      <link>/docs/alerts/200011-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-9/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphiQL / GraphQL Playground detected</title>
      <link>/docs/alerts/200012-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-5/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL endpoint observed</title>
      <link>/docs/alerts/200012-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-4/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL path observed</title>
      <link>/docs/alerts/200019-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-5/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTML references .map files</title>
      <link>/docs/alerts/200009-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-2/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Image Exposes Location or Privacy Data</title>
      <link>/docs/alerts/10103/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10103/</guid>
      <description>&lt;p&gt;The image was found to contain embedded location information, such as GPS coordinates, or another privacy exposure, such as camera serial number.  Depending on the context of the image in the website, this information may expose private details of the users of a site.  For example, a site that allows users to upload profile pictures taken in the home may expose the home&amp;rsquo;s address.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Amazon S3 Bucket URL</title>
      <link>/docs/alerts/100036/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100036/</guid>
      <description>&lt;p&gt;An Amazon S3 bucket URL was found in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Google API Key</title>
      <link>/docs/alerts/100034/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100034/</guid>
      <description>&lt;p&gt;A Google API Key was found in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - IBAN Numbers</title>
      <link>/docs/alerts/100012/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100012/</guid>
      <description>&lt;p&gt;An IBAN number was discovered in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Private IP Address</title>
      <link>/docs/alerts/100013/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100013/</guid>
      <description>&lt;p&gt;A private IP such as 10.x.x.x, 172.x.x.x, 192.168.x.x or IPV6 fe00:: has been found in the HTTP response body. This information might be helpful for further attacks targeting internal systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Server Header</title>
      <link>/docs/alerts/100019/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100019/</guid>
      <description>&lt;p&gt;The web/application server is leaking version information via the &amp;lsquo;Server&amp;rsquo; HTTP response header. Access to such information may facilitate attackers identifying other vulnerabilities your web/application server  is subject to.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - X-Powered-By Header</title>
      <link>/docs/alerts/100023/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100023/</guid>
      <description>&lt;p&gt;The web/application server is leaking information via one or more &amp;lsquo;X-Powered-By&amp;rsquo; HTTP response headers. Access to such information may facilitate attackers identifying other frameworks/components your web application is reliant upon and the vulnerabilities such components may be subject to.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Internal IP address leaked in response</title>
      <link>/docs/alerts/200016-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-1/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JavaScript includes sourceMappingURL</title>
      <link>/docs/alerts/200009-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-1/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>localhost/127.0.0.1 referenced in response</title>
      <link>/docs/alerts/200016-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-2/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mapbox token exposed</title>
      <link>/docs/alerts/200011-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-8/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Next.js build metadata exposed</title>
      <link>/docs/alerts/200009-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-4/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>OIDC well-known configuration observed</title>
      <link>/docs/alerts/200013-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-2/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>OpenAPI spec detected</title>
      <link>/docs/alerts/200012-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-2/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>phpinfo endpoint observed</title>
      <link>/docs/alerts/200019-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-9/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Potential .git exposure path observed</title>
      <link>/docs/alerts/200019-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-8/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Potential backup file observed</title>
      <link>/docs/alerts/200019-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-6/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Private key material exposed</title>
      <link>/docs/alerts/200011-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-1/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>security.txt observed</title>
      <link>/docs/alerts/200013-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-1/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sentry DSN exposed</title>
      <link>/docs/alerts/200011-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-5/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server is running on Clacks - GNU Terry Pratchett</title>
      <link>/docs/alerts/100002/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100002/</guid>
      <description>&lt;p&gt;The web/application server is running over the Clacks network, some say it&amp;rsquo;s turtles/IP,  some say it&amp;rsquo;s turtles all the way down the layer stack.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Slack token pattern</title>
      <link>/docs/alerts/200011-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-3/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Social Security Number</title>
      <link>/docs/alerts/200006-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200006-2/</guid>
      <description>&lt;p&gt;Sensitive data is anything that should not be accessible to admin access, known as sensitive data. Sensitive data may include personally identifiable information (PII), such as Social Security numbers, financial information, or login credentials. Sensitive Data Exposure occurs when an organization unknowingly exposes sensitive data or when a security incident leads to the accidental or unlawful destruction, loss, alteration, or admin disclosure of, or access to sensitive data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spring Boot actuator endpoint observed</title>
      <link>/docs/alerts/200019-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-3/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Stripe publishable key exposed</title>
      <link>/docs/alerts/200011-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-7/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Swagger UI detected</title>
      <link>/docs/alerts/200012-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-1/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Swagger/OpenAPI path observed</title>
      <link>/docs/alerts/200019-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-4/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Webpack dev-server / hot reload artifacts</title>
      <link>/docs/alerts/200009-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-3/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
