UNPKG

mcp-server-semgrep

Version:

MCP Server for Semgrep Integration - static code analysis with AI

42 lines (41 loc) 1.66 kB
rules: - id: insecure-cipher-algorithm-idea message: >- IDEA (International Data Encryption Algorithm) is a block cipher created in 1991. It is an optional component of the OpenPGP standard. This cipher is susceptible to attacks when using weak keys. It is recommended that you do not use this cipher for new applications. Use a strong symmetric cipher such as EAS instead. With the `cryptography` package it is recommended to use `Fernet` which is a secure implementation of AES in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES algorithm instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures bandit-code: B304 references: - https://tools.ietf.org/html/rfc5469 - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#cryptography.hazmat.primitives.ciphers.algorithms.IDEA category: security technology: - cryptography subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::symmetric-algorithm::cryptography severity: WARNING languages: - python patterns: - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$IDEA($KEY) - metavariable-regex: metavariable: $IDEA regex: ^(IDEA)$ - focus-metavariable: $IDEA fix: AES