AWS logo
Amazon QDetector LibrarySign in to Amazon Q
AWSbreadcrumb dividerDocumentationbreadcrumb dividerAmazon Qbreadcrumb dividerDetector Librarybreadcrumb dividerPythonbreadcrumb dividerTagsFeedbackFeedback icon

Q

Detector Library

Python detectors (131/131)

Improper privilege managementSpawning a process without main moduleInteger overflowCatch and swallow exceptionInsufficient Logging CDKUnauthenticated LDAP requestsPath traversalLoose file permissionsExposure of Sensitive Information CDKFile injectionIncorrect use of Process.terminate APIXML External EntityPytorch use nondeterministic algoritmSet SNS Return Subscription ARNTensorflow enable ops determinismOutdated subprocess module APIImproper input validationImproper authenticationMissing paginationSemaphore overflow preventionInsecure cookieUsage of an API that is not recommended - Low SeveritySocket connection timeoutAWS client not reused in a Lambda functionPytorch assign in place modLeaky subprocess timeoutPytorch disable gradient calculationRisky use of dict get methodXPath injectionMissing authorizationMultidimensional list initialization using replication is error proneSQL injectionPytorch miss call to evalAWS AppConfigImproper certificate validationURL redirection to untrusted siteMutually exclusive callNotebook best practice violationStack trace exposureUse of a deprecated methodAWS api logging disabled cdkOS command injectionAWS credentials loggedMissing Authorization CDKZip bomb attackSensitive data stored unencrypted due to partial encryptionSynchronous publication of AWS Lambda metricsUnrestricted upload of dangerous file typePytorch redundant softmaxInsecure connection using unencrypted protocolUnauthenticated Amazon SNS unsubscribe requests might succeedInsecure Socket BindInsecure CORS policyCross-site request forgeryGarbage collection prevention in multiprocessingCatch and rethrow exceptionWeak algorithm used for Password HashingMissing none check on response metadataSensitive information leakClient-side KMS reencryptionOverride of reserved variable names in a Lambda functionDocker arbitrary container runDirect dict object modificationCatastrophic backtracking regexResource management errors cdkResource leakTensorflow redundant softmaxAWS insecure transmission CDKPublic method parameter validationImproper error handlingTime zone aware datetimesPytorch control sources of randomnessDeadlocks caused by improper multiprocessing API usageLow maintainability with low class cohesionUntrusted AMI imagesNotebook invalid execution orderConfusion between equality and identity in conditional expressionPytorch sigmoid before bcelossPytorch data loader with multiple workersPytorch avoid softmax with nlllossPytorch miss call to zero gradError prone sequence modificationAWS missing encryption of sensitive data cdkBad exception handlingUse of Default Credentials CDKNotebook variable redefinitionDo not pass generic exception ruleUsage of an API that is not recommended - High SeverityInsecure cryptographyS3 partial encrypt CDKCross-site scriptingMutable objects as default arguments of functionsImproper Access Control CDKViolation of PEP8 programming recommendationsInsecure temporary file or directoryComplex code hard to maintainaws kmskey encryption cdkUsage of an API that is not recommendedEnabling and overriding debug featureDeserialization of untrusted objectUse of an inefficient or incorrect APIAvoid using nondeterministic Tensorflow APIInefficient string concatenation inside loopImproper sanitization of wildcards or matching symbolsInsecure hashingUsing AutoAddPolicy or WarningPolicyLog injectionWeak obfuscation of web requestSocket close platform compatibilityUnsanitized input is run as codeBatch request with unchecked failuresInefficient polling of AWS resourceHardcoded interface bindingHardcoded IP addressHardcoded credentialsServer-side request forgeryModule injectionUnnecessary iterationTensorflow control sources of randomnessMissing Authentication for Critical Function CDKUsage of an API that is not recommended - Medium SeverityUnsafe Cloudpickle LoadIncorrect binding of SNS publish operationsPyTorch create tensors directly on deviceInefficient new method from hashlibDangerous global variablesMultiple values in return statement is prone to errorLDAP injectionClear text credentialsMissing S3 bucket owner conditionAWS missing encryption CDK

Tags

a
# access-control# amazon-ec2# amazon-s3# amazon-sns# availability# aws-cdk# aws-kms# aws-lambda# aws-python-sdk
b
# batch-operations
c
# concurrency# configuration# consistency# cookies# correctness# cryptography
d
# data-integrity# deserialization
e
# efficiency
i
# information-leak# injection
l
# ldap
m
# machine-learning# maintainability
n
# networking# null-check
o
# owasp-top10
r
# race-condition# resource-leak
s
# secrets# security-context# sql# subprocess
t
# top25-cwes
x
# xml