Top Vulnerability Findings in OWASP A02 Cryptographic FailuresTop Vulnerability Findings in OWASP A02 Cryptographic Failures
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
OWASP A02: Cryptographic Failures
šŸ” OWASP A02 — Cryptographic Failures Assessment
Overview
Conducted a manual assessment focusing on the protection of sensitive data during storage and transmission.
What I Found
Sensitive information exposed inside JWTs
JWT information disclosure
Missing Secure, HttpOnly, and SameSite cookie attributes
HTTP used instead of HTTPS
Stack trace and debug information disclosure
Application version disclosure
Impact
Sensitive information leakage can assist attackers in account compromise, session theft, and application reconnaissance.
Mitigation
Avoid storing sensitive data inside JWTs.
Enforce HTTPS across the application.
Configure cookies with Secure, HttpOnly, and SameSite.
Disable verbose error messages in production.
Minimize unnecessary information disclosure.
Tools Used
Burp Suite Professional
JWT Decoder
Browser Developer Tools
Post image
Post image
Post image
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started