blst-security/cherrybomb
Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.
RustApache-2.0
Pinned issues
Issues
- 4
Passive mode fails with dns error
#157 opened by qrilka - 1
blstsecurity.com redirecting to gambling site
#158 opened by su-anonymous - 0
Unable to load the website
#156 opened by muizzhaque - 0
Add missing binaries in v1.0.1
#153 opened by nikolay - 1
support arm cpu
#136 opened by egege - 1
External $ref
#151 opened by jayvdb - 6
Publish crate as a library
#126 opened by Kinrany - 2
cherrybomb 1.0.0 release build failure
#149 opened by chenrui333 - 2
TLS error when scanning an internal API
#94 opened by TmmmmmR - 2
Spelling error in Lib.rs
#84 opened by DeliciousBounty - 4
YAML support broken?
#111 opened by rngtng - 3
- 2
- 0
Build problem TOML
#139 opened by DeliciousBounty - 4
include/exclude Seem to Have no Effect
#140 opened by afrazkhan - 1
Cherrybomb throwing stackover error
#143 opened by abnair24 - 5
Cherrybomb error - Invalid peer certificate: Expired
#147 opened by abnair24 - 1
unable to install cherrybomb
#148 opened by andyaspellclark-moj - 2
cherrybomb is not working
#145 opened by anirudh-hegde - 5
Schema not recognised by cherry bomb
#125 opened by kraktus - 0
min/maxItems unnecessary alert
#137 opened by GuyL99 - 1
api key is not able to generate
#135 opened by kpreety - 0
Active Profile
#133 opened by DeliciousBounty - 1
Parameters without schema causing crash
#129 opened by DJ4ddi - 1
minor text bug: space&bracket missing in README.md
#103 opened by nikitakoselev - 4
Passive Test / JWT Security
#70 opened by DeliciousBounty - 1
Servers _override
#119 opened by DeliciousBounty - 2
- 1
- 5
- 0
Authentication is not send
#109 opened by DeliciousBounty - 1
- 0
Bug in the parser
#55 opened by DeliciousBounty - 1
EMPTY JSON PATH
#54 opened by DeliciousBounty - 0
`attacker::attack`
#98 opened by DeliciousBounty - 1
Authorization input validation - Error handling
#86 opened by RoyB99 - 1
- 3
Clearer mechianism to disable active scans
#78 opened by jayvdb - 10
- 2
Active Test / Cross Site Scripting
#74 opened by DeliciousBounty - 2
Failure while trying to install cherrybomb
#80 opened by Arthurdw - 3
Active Test / JWT Token
#71 opened by DeliciousBounty - 3
- 0
Active Test / SQLI
#73 opened by DeliciousBounty - 1
- 0
Active/Passive Checks Needed
#69 opened by RazMag - 0
New passive checks
#62 opened by RazMag - 0
XML bomb active check
#60 opened by RazMag - 0
SSRF active check
#61 opened by RazMag - 1
The CONTRIBUTING.md file specifies a branch called "canary" to pull requests from - this seems absent. What branch does one use instead?
#51 opened by agatekartik