mcp-server-semgrep
Version:
MCP Server for Semgrep Integration - static code analysis with AI
36 lines • 1.18 kB
YAML
rules:
- id: swift-user-defaults
message: Potentially sensitive data was observed to be stored in UserDefaults,
which is not adequate protection of sensitive information. For data of a
sensitive nature, applications should leverage the Keychain.
severity: WARNING
metadata:
likelihood: LOW
impact: HIGH
confidence: MEDIUM
category: security
cwe:
- "CWE-311: Missing Encryption of Sensitive Data"
masvs:
- "MASVS-STORAGE-1: The app securely stores sensitive data"
owasp:
- A03:2017 - Sensitive Data Exposure
- A04:2021 - Insecure Design
references:
- https://developer.apple.com/library/archive/documentation/Security/Conceptual/SecureCodingGuide/Articles/ValidatingInput.html
- https://mas.owasp.org/MASVS/controls/MASVS-STORAGE-1/
subcategory:
- vuln
technology:
- ios
- macos
vulnerability_class:
- Cryptographic Issues
languages:
- swift
options:
# ruleid: metadata-incorrect-option
taint_propagation: true
# ruleid: metadata-incorrect-option
value: 2
patterns: