Paulo can access data in transit that is not encrypted, even though the channel is encrypted
Paulo can access data in transit that is not encrypted, even though the channel is encrypted
OWASP SCP
37,88,143,214
OWASP ASVS
8.3.4,9.1.1
OWASP AppSensor
CAPEC
-
SAFECODE
14,29,30
Data may be use encryption in transit like Transport Layer Security (TLS). However, an attacker may have legitimate access to this (e.g. viewing SSL content in a web browser). Consider whether the data transmitted also needs to be encrypted itself, not just sent using an encrypted protocol.
OWASP ASVS (4.0): 8.3.4 ,9.1.1
OWASP SCP: 37,88,143,214
OWASP Appsensor:
Safecode: 14,29,30
ASVS V8.3 - Sensitive Private Data
ASVS V9.1 - Communications Security Requirements
No suitable mappings were found.