Supported Fixes
A "fix" is defined as a code remediation that has been validated and tested by Mobb engineers.
All fixes must meet the following criteria:
The fix addresses the security issue as identified by the SAST tool
The fix should be recognized by the SAST tool (The SAST tool should recognize the finding as fixed upon re-scan)
Here are the categories of fixes that Mobb currently supports. If there is a category you'd like to see Mobb support that is not listed here, please email us at support@mobb.ai.
If you'd like us to support a SAST tool that is not listed here, please tell us by submitting it here.
Since different SAST vendors often name issues differently, the issue names in parentheses are the Mobb normalized names.
List of Supported Issue Types for Snyk
C#
Cross-site Scripting (XSS)
GO
Command Injection
SQL Injection
Java
JavaScript / TypeScript
Python
Cross Site Scripting (XSS)
List of Supported Issue Types for Fortify
CPP
C#
Cross-Site Scripting: Persistent
DOCKERFILE
GO
Java
JavaScript / TypeScript
PHP
Python
XML
List of Supported Issue Types for Checkmarx
C#
Declaration Of Catch For Generic Exception
Deserialization of Untrusted Data
Dynamic SQL Queries
HttpOnlyCookies
Improper Exception Handling
Improper Resource Shutdown or Release
Improper Restriction of XXE Ref
Information Exposure Through an Error Message
Information Exposure via Headers
Insecure Cookie
Insufficient Logging of Exceptions
Insufficient Logging of Sensitive Operations
Just One of Equals and Hash code Defined
Log Forging
Path Traversal
Reflected XSS
Reflected XSS All Clients
SQL Injection
SSRF
Stored XSS
Trust Boundary Violation in Session Variables
Unsafe Object Binding
Unvalidated Arguments Of Public Methods
Use of Insufficiently Random Values
Value Shadowing
GO
Command Injection
Log Forging
Privacy Violation
Second Order SQL Injection
SQL Injection
SSL Verification Bypass
Use of Cryptographically Weak PRNG
Java
Absolute Path Traversal
Command Injection
Confusing Naming
Declaration Of Catch For Generic Exception
Detection of Error Condition Without Action
Frameable loging page
HttpOnlyCookies
Improper Resource Shutdown or Release
Improper Restriction of Stored XXE Ref
Improper Restriction of XXE Ref
Information Exposure Through an Error Message
Log Forging
Portability Flaw Locale Dependent Comparison
Privacy Violation
Race Condition Format Flaw
ReDoS From Regex Injection
Reflected XSS All Clients
Relative Path Traversal
SQL Injection
SQL Injection Evasion Attack
SSRF
Stored Absolute Path Traversal
Stored Log Forging
Stored XSS
Trust Boundary Violation in Session Variables
Unchecked Input for Loop Condition
Use of Hard coded Cryptographic Key
Use of Non Cryptographic Random
Use of Wrong Operator in String Comparison
JavaScript / TypeScript
Absolute Path Traversal
Client DOM Code Injection
Client DOM Open Redirect
Client DOM Stored XSS
Client DOM XSS
Client Hardcoded Domain
Client Insecure Randomness
Client JQuery Deprecated Symbols
Client Password In Comment
Client Potential XSS
Client Regex Injection
Client Use Of Iframe Without Sandbox
Command Injection
Hardcoded password in Connection String
Information Exposure Through an Error Message
JWT Use Of Hardcoded Secret
Log Forging
Open Redirect
Prototype Pollution
Relative Path Traversal
Secret_Leak
Server DoS by loop
Server DoS by Loop
SQL Injection
SSRF
Stored XSS
Unchecked Input For Loop Condition
Unprotected Cookie
Unsafe Use Of Target blank
Use of Deprecated or Obsolete Functions
Use Of Hardcoded Password
Use of Insufficiently Random Values
PHP
Use of Non Cryptographic Random
Python
Command Argument Injection
SQL
List of Supported Issue Types for SonarQube
C#
DOCKERFILE
GO
Constructing arguments of system commands from user input is security-sensitive
Database queries should not be vulnerable to injection attacks
Formatting SQL queries is security-sensitive
Java
JavaScript / TypeScript
PHP
Python
YAML
List of Supported Issue Types for CodeQL
CPP
C#
SQL Injection
SQL Injection
GO
Command Injection
SQL Injection
Stored cross-site scripting
Java
JavaScript / TypeScript
Python
YAML
List of Supported Issue Types for Semgrep/Opengrep
C#
Cookie "HttpOnly" attribute is not set to true
Cookie "HttpOnly" attribute is not set to true
Cookie "HttpOnly" attribute is not set to true
Cookie "HttpOnly" attribute is not set to true
Cookie "Secure" attribute is not set to true
Cross-site Scripting
Cross-site Scripting
Deserialization of untrusted data
Improper Resource Shutdown or Release
Information Exposure via Headers
Missing cross-site request forgery token validation
Missing HSTS Header
Open Redirect
Open Redirect
Path Traversal
Path Traversal
Regex Missing Timeout
SSRF
SSRF
System Information Leak
System Information Leak
System Information Leak
XXE
Zip Slip
DOCKERFILE
GO
HCL
Java
Denial of Service: StringBuilder
File Path Traversal in HttpServlet
find_sec_bugs.XSS_REQUEST_PARAMETER_TO_SERVLET_WRITER-1
find_sec_bugs.XSS_SERVLET-2.XSS_SERVLET_PARAMETER-1
Frameable Login Page (Clickjacking)
HTTP Parameter Pollution (query-string concatenation audit)
HTTP Parameter Pollution (tainted value into URL / query string)
Improper Resource Shutdown or Release
java.mobb.custom_injection
java/mobb.pt_find_transitives
lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer
Log Forging
Log Forging
Missing Check Against Null
Missing Check Against Null
Often Misused: Boolean.getBoolean()
Open Redirect (Servlet / JAX-RS)
Path Traversal
Path Traversal
Poor Logging Practice: Use of a System Output Stream
Race Condition Format Flaw
Reflected XSS (Servlet / JAX-RS)
Regular Expression Injection
Relative File Path Traversal in HttpServlet
SQL Injection
System information leak via printStackTrace (Mobb)
Tainted File Path
Use of Hard coded Cryptographic Key
Zip Slip
JavaScript / TypeScript
Clear text transmission of sensitive cookie
Clear text transmission of sensitive cookie
Client DOM Stored Code Injection
GraphQL Depth Limit
Iframe Without Sandbox
Incomplete Hostname Regex
Incomplete Hostname Regex
Incomplete URL scheme check
Incomplete URL Substring Sanitization
javascript.lang.security.audit.detect-redos-mobb.detect-redos-mobb
javascript.mobb.log_forging
javascript.mobb.system-information-leak-external
Open redirect via function call (location/href)
Prototype pollution loop (Mobb variant)
Sensitive server cookie exposed to the client
Sensitive server cookie exposed to the client
Type Confusion Through Parameter Tampering
Unsafe Use of target=_blank
Python
Improper Resource Shutdown or Release
Incomplete URL Substring Sanitization
Insecure Temporary File
Log Forging
Log Forging
Modified Default Parameter
Regex Injection
Regex Injection
Regex Injection
Request without certificate validation
System Information Leak
YAML
List of Supported Issue Types for Datadog
GO
SQL Injection
Java
XSS Protection
JavaScript / TypeScript
Command Injection
Path traversal
SQL Injection
SQL Injection
Python
Path Traversal
Last updated