<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-345 on ZAP</title>
    <link>/alerttags/cwe-345/</link>
    <description>Recent content in CWE-345 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-345/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Content-Type Header Empty</title>
      <link>/docs/alerts/10019-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10019-2/</guid>
      <description>&lt;p&gt;The Content-Type header was either missing or empty.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Content-Type Header Missing</title>
      <link>/docs/alerts/10019-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10019-1/</guid>
      <description>&lt;p&gt;The Content-Type header was either missing or empty.&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (Authorization header)</title>
      <link>/docs/alerts/200003-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-6/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (Cookie)</title>
      <link>/docs/alerts/200003-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-4/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (Form body param)</title>
      <link>/docs/alerts/200003-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-5/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (JSON body)</title>
      <link>/docs/alerts/200003-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-7/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT Probe (Authorization &#43; JWT cookies removed)</title>
      <link>/docs/alerts/200003-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-1/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT Probe (Authorization header removed)</title>
      <link>/docs/alerts/200003-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-2/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT Probe (JWT cookies removed)</title>
      <link>/docs/alerts/200003-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-3/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>postMessage to cross-origin target with tainted payload</title>
      <link>/docs/alerts/210010-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210010-2/</guid>
      <description>&lt;p&gt;Tainted data sent via window.postMessage to a different origin.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>postMessage to wildcard origin with tainted payload</title>
      <link>/docs/alerts/210010-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210010-1/</guid>
      <description>&lt;p&gt;Tainted data sent via window.postMessage to wildcard &amp;lsquo;*&amp;rsquo; targetOrigin.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sub Resource Integrity Attribute Missing</title>
      <link>/docs/alerts/90003/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90003/</guid>
      <description>&lt;p&gt;The integrity attribute is missing on a script or link tag served by an external server. The integrity tag prevents an attacker who have gained access to this server from injecting a malicious content.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
