Amazon Q
Detector Library
Sign in to Amazon Q
AWS
Documentation
Amazon Q
Detector Library
Kotlin
Severity
Severity Critical
Feedback
Q
Detector Library
Kotlin detectors
(23/23)
Insecure cookie
Cookie Without Http Only Flag
Improper Authentication
Cryptographic key generator
Weak pseudorandom number generation
Path traversal
Cross-site scripting
Reusing Nonce and key in encryption
Code Injection
Server-side request forgery
Cross-site request forgery
Log injection
Hardcoded credentials
Enabling and overriding debug feature
Null Pointer Dereference
Insecure hashing
Missing encryption of sensitive data
Improper verification of Intent
Insecure connection using unencrypted protocol
OS Command Injection
Insecure Bean Validation
SQL injection
Incorrect Type Conversion
Critical
Showing all detectors for the Kotlin language with critical severity.
Code Injection
Code injection occurs when an application executes untrusted code from an attacker.
Hardcoded credentials
Hardcoded credentials can be intercepted by malicious actors.