<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-311 on ZAP</title>
    <link>/alerttags/cwe-311/</link>
    <description>Recent content in CWE-311 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-311/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>HTTP Only Site</title>
      <link>/docs/alerts/10106/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10106/</guid>
      <description>&lt;p&gt;The site is only served under HTTP and not HTTPS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTTPS Configuration</title>
      <link>/docs/alerts/10205-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10205-1/</guid>
      <description>&lt;p&gt;Performs HTTPS configuration analysis including certificate details and supported cipher suites.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTTPS Content Available via HTTP</title>
      <link>/docs/alerts/10047/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10047/</guid>
      <description>&lt;p&gt;Content which was initially accessed via HTTPS (i.e.: using SSL/TLS encryption) is also accessible via HTTP (without encryption).&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTTPS Security Configuration Issues</title>
      <link>/docs/alerts/10205-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10205-2/</guid>
      <description>&lt;p&gt;The HTTPS configuration has one or more security issues identified by the TLS risk assessment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Base64-encoded String</title>
      <link>/docs/alerts/100007/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100007/</guid>
      <description>&lt;p&gt;A Base64-encoded string has been found in the HTTP response body. Base64-encoded data may contain sensitive information such as usernames, passwords or cookies which should be further inspected.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Credit Card Number</title>
      <link>/docs/alerts/100008/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100008/</guid>
      <description>&lt;p&gt;A credit card number was found in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Email Addresses</title>
      <link>/docs/alerts/100009/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100009/</guid>
      <description>&lt;p&gt;An email address was found in the HTTP response body. Exposure of email addresses in HTTP messages can lead to privacy violations  and targeted phishing attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - IP Exposed via F5 BIG-IP Persistence Cookie</title>
      <link>/docs/alerts/100006/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100006/</guid>
      <description>&lt;p&gt;The F5 BIG-IP Persistence cookie set for this website can be decoded to a specific IP and port. An attacker may leverage this information to conduct Social Engineering attacks or other exploits.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Secure Pages Include Mixed Content</title>
      <link>/docs/alerts/10040/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10040/</guid>
      <description>&lt;p&gt;The page includes mixed content, that is content accessed via HTTP instead of HTTPS.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
