| Protection Mechanism Failure | |
| Cleartext Transmission of Sensitive Information | [2.0.0,2.16.1)[3.0.0,3.0.12) |
| Cleartext Transmission of Sensitive Information | [2.0.0,2.16.1)[3.0.0,3.0.13) |
| Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) | [2.0.0,2.16.1)[3.0.0,3.0.12) |
| Incorrect Implementation of Authentication Algorithm | |
| Sensitive Cookie with Improper SameSite Attribute | [2.0.0,2.16.1)[3.0.0,3.0.13) |
| Origin Validation Error | |
| Cleartext Transmission of Sensitive Information | [2.0.0,2.16.1)[3.0.0.Beta1,3.0.13) |
| Origin Validation Error | [2.0.0,2.16.1)[3.0.0,3.0.13) |
| Denial of Service (DoS) | |
| Cleartext Transmission of Sensitive Information | [2.0.0,2.16.1)[3.0.0,3.0.12) |
| Session Fixation | |
| Improper Authentication | |
| Insufficient Verification of Data Authenticity | [2.0.0,2.16.1)[3.0.0,3.0.12) |
| Detection of Error Condition Without Action | |
| Insufficiently Protected Credentials | [2.14.5,2.16.1)[3.0.9,3.0.12) |
| Improper Resource Shutdown or Release | |
| Cleartext Transmission of Sensitive Information | [,2.16.1)[3.0.0.Beta1,3.0.12) |
| Insufficiently Protected Credentials | [,2.16.1)[3.0.0.Beta1,3.0.12) |
| Improper Handling of Highly Compressed Data (Data Amplification) | [,2.16.1)[3.0.0.Beta1,3.0.12) |
| Sensitive Cookie with Improper SameSite Attribute | [,2.16.0)[3.0.0.Beta1,3.0.11) |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere | [,2.15.0)[3.0.0.Beta1,3.0.10) |
| Origin Validation Error | [,2.14.5)[3.0.0.Beta1,3.0.9) |
| Improper Authentication | [2.1.0,2.12.4)[3.0.0.Beta1,3.0.1) |
| Server Side Request Forgery (SSRF) | |