Details
Alert Id 10094
Alert Type Passive Scan Rule
Status alpha
Risk
CWE
WASC

Summary

Base64 encoded data was disclosed by the application/web server. Note: in the interests of performance not all base64 strings in the response were analyzed individually, the entire response should be looked at by the analyst/security team/developer(s).

Solution

Manually confirm that the Base64 data does not leak sensitive information, and that the data cannot be aggregated/used to exploit other vulnerabilities.

References

Code

org/zaproxy/zap/extension/pscanrulesAlpha/Base64Disclosure.java