Loading...
Loading...
Compare original and translation side by side
/security-review/security-review <path>/security-review/security-review <path>/security-review src/auth/references/language-patterns.md/security-review src/auth/references/language-patterns.mdpackage.jsonpackage-lock.jsonrequirements.txtpyproject.tomlPipfilepom.xmlbuild.gradleGemfile.lockCargo.tomlgo.sumreferences/vulnerable-packages.mdpackage.jsonpackage-lock.jsonrequirements.txtpyproject.tomlPipfilepom.xmlbuild.gradleGemfile.lockCargo.tomlgo.sumreferences/vulnerable-packages.md.envreferences/secret-patterns.md.envreferences/secret-patterns.mdreferences/vuln-categories.mdreferences/vuln-categories.mdreferences/report-format.mdreferences/report-format.md| Severity | Meaning | Example |
|---|---|---|
| 🔴 CRITICAL | Immediate exploitation risk, data breach likely | SQLi, RCE, auth bypass |
| 🟠 HIGH | Serious vulnerability, exploit path exists | XSS, IDOR, hardcoded secrets |
| 🟡 MEDIUM | Exploitable with conditions or chaining | CSRF, open redirect, weak crypto |
| 🔵 LOW | Best practice violation, low direct risk | Verbose errors, missing headers |
| ⚪ INFO | Observation worth noting, not a vulnerability | Outdated dependency (no CVE) |
| 严重等级 | 含义 | 示例 |
|---|---|---|
| 🔴 CRITICAL | 存在即时被利用的风险,大概率引发数据泄露 | SQLi、RCE、认证绕过 |
| 🟠 HIGH | 严重漏洞,存在明确的利用路径 | XSS、IDOR、硬编码密钥 |
| 🟡 MEDIUM | 满足特定条件或组合利用时可被攻击 | CSRF、开放重定向、弱加密 |
| 🔵 LOW | 不符合最佳实践,直接风险低 | 冗余错误信息、缺失安全头 |
| ⚪ INFO | 值得注意的观察项,不属于漏洞 | 无CVE的过时依赖 |
references/vuln-categories.mdSQL injectionXSScommand injectionSSRFBOLAIDORJWTCSRFsecretscryptographyrace conditionpath traversalreferences/secret-patterns.mdAPI keytokenprivate keyconnection stringentropy.envGitHub ActionsDockerTerraformreferences/language-patterns.mdExpressReactNext.jsDjangoFlaskFastAPISpring BootPHPGoRailsRustreferences/vulnerable-packages.mdlodashaxiosjsonwebtokenPillowlog4jnokogiriCVEreferences/report-format.mdreportformattemplatefindingpatchsummaryconfidencereferences/vuln-categories.mdSQL injectionXSScommand injectionSSRFBOLAIDORJWTCSRFsecretscryptographyrace conditionpath traversalreferences/secret-patterns.mdAPI keytokenprivate keyconnection stringentropy.envGitHub ActionsDockerTerraformreferences/language-patterns.mdExpressReactNext.jsDjangoFlaskFastAPISpring BootPHPGoRailsRustreferences/vulnerable-packages.mdlodashaxiosjsonwebtokenPillowlog4jnokogiriCVEreferences/report-format.mdreportformattemplatefindingpatchsummaryconfidence