Skip to main content

✅ Escape Security Reference

NameCategoryGraphQL SupportREST SupportDefault SeverityOWASP 2023
Private dataAccess ControlHIGHA03:2023
Tenant isolationAccess ControlHIGHA05:2023
Expired tokenAccess ControlHIGHA02:2023
Private fieldsAccess ControlHIGHA01:2023
Public unsafe mutation endpointAccess ControlMEDIUMA05:2023
Broken Object Level AuthorizationAccess ControlMEDIUMA01:2023
Authenticated route bypassAccess ControlLOWA02:2023
Automatic Persisted QueriesConfigurationLOWA08:2023
Proxy DisclosureConfigurationLOWA05:2023
GraphQL IDEConfigurationLOWA07:2023
Directory listingConfigurationLOWA01:2023
Unhandled endpointConfigurationINFOA02:2023
Error type inconsistencyConfigurationINFOA08:2023
Data leakInformation DisclosureHIGHA01:2023
Source code disclosureInformation DisclosureHIGHA07:2023
Debug modeInformation DisclosureMEDIUMA07:2023
StacktracesInformation DisclosureMEDIUMA07:2023
Field suggestionInformation DisclosureMEDIUMA07:2023
File disclosureInformation DisclosureLOWA07:2023
Private IPInformation DisclosureLOWA01:2023
Introspection enabledInformation DisclosureINFOA07:2023
Improper Input Validation InjectionInjectionHIGHA08:2019
File inclusionInjectionHIGHA08:2019
XXE InjectionInjectionHIGHA08:2019
Directory traversalInjectionHIGHA08:2019
Stored Improper Input Validation InjectionInjectionHIGHA08:2019
File uploadInjectionHIGHA07:2023
NoSQL InjectionInjectionHIGHA09:2023
SQL Injection StoredInjectionHIGHA09:2023
Command InjectionInjectionHIGHA08:2019
NoSQL Injection StoredInjectionHIGHA09:2023
SQL InjectionInjectionHIGHA09:2023
CRLF InjectionInjectionMEDIUMA08:2019
HeartBleedProtocolHIGHA07:2023
Server ErrorProtocolHIGHA05:2023
SSL CertificateProtocolHIGHA02:2023
SSL enforcedProtocolMEDIUMA02:2023
CORSProtocolLOWA07:2023
Content-Type headerProtocolLOWA07:2023
Header leakProtocolLOWA07:2023
Content Security Policy HeaderProtocolLOWA07:2023
HeadersProtocolLOWA02:2023
Access-Control-Allow-Origin HeaderProtocolLOWA07:2023
X-Frame-Options headerProtocolLOWA07:2023
Cookie SecurityProtocolLOWA07:2023
Strict Transport SecurityProtocolLOWA07:2023
Cache Control HeaderProtocolLOWA07:2023
X-Content-Type-OptionsProtocolLOWA07:2023
Content typeProtocolLOWA07:2023
Server Side Request ForgeryRequest ForgeryHIGHA06:2023
GET based CSRFRequest ForgeryHIGHA02:2023
Partial SSRFRequest ForgeryHIGHA06:2023
Open redirection ForgeryRequest ForgeryHIGHA03:2023
POST based CSRFRequest ForgeryMEDIUMA02:2023
SSRF Injection in headersRequest ForgeryLOWA10:2023
Security timeoutResource LimitationHIGHA07:2023
Recursive FragmentResource LimitationMEDIUMA08:2023
Depth limitResource LimitationMEDIUMA04:2023
Large JSON inputResource LimitationMEDIUMA04:2023
Field limitResource LimitationMEDIUMA04:2023
Directive overloadingResource LimitationMEDIUMA08:2023
Character limitResource LimitationLOWA08:2023
Unreachable serverResource LimitationLOWA08:2023
Alias limitResource LimitationLOWA05:2023
Width limitResource LimitationLOWA04:2023
Batch LimitResource LimitationLOWA08:2023
Pagination missingResource LimitationLOWA08:2023
Cyclic queryResource LimitationLOWA07:2023
Response sizeResource LimitationLOWA07:2023
Query cost analysisResource LimitationLOWA08:2023
Circular introspectionResource LimitationINFOA08:2023
Typing misconfigurationSchemaMEDIUMA08:2019
Stored invalid inputSchemaMEDIUMA03:2023
Zombie objectSchemaLOWA09:2023
Self compliant specSchemaLOWA02:2023
Response type mismatchSchemaINFOA08:2019
Required argument misconfigurationSchemaINFOA08:2023
Weak JSON typingSchemaINFOA08:2019
Undefined objectsSchemaINFOA09:2023
Custom security checksUnspecifiedINFOA08:2023