<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-205 on ZAP</title>
    <link>/alerttags/cwe-205/</link>
    <description>Recent content in CWE-205 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-205/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Access Control Issue - Improper Authorization</title>
      <link>/docs/alerts/10102/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10102/</guid>
      <description>&lt;p&gt;Insufficient Authorization results when an application does not perform adequate authorization checks to ensure that the user is performing a function or accessing data in a manner consistent with the security policy. Authorization procedures should enforce what a user, service or application is permitted to do. When a user is authenticated to a web site, it does not necessarily mean that the user should have full access to all content and functionality.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cookie Slack Detector</title>
      <link>/docs/alerts/90027/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90027/</guid>
      <description>&lt;p&gt;Repeated GET requests: drop a different cookie each time, followed by normal request with all cookies to stabilize session, compare responses against original baseline GET. This can reveal areas where cookie based authentication/attributes are not actually enforced.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL Server Implementation Identified</title>
      <link>/docs/alerts/50007-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/50007-2/</guid>
      <description>&lt;p&gt;The server is using &amp;ldquo;Example GraphQL Engine&amp;rdquo;, which is a GraphQL implementation for &amp;ldquo;Example Technology 1&amp;rdquo; and &amp;ldquo;Example Technology 2&amp;rdquo;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
