OWASP / OWASP/www-project-api-security-testing-framework
VAmPI row 9 (JWT weak signing key) may be permanently unverifiable — consider reclassifying
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 150
- Forks
- 41
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 3
Description
Tracked in docs/TRACEABILITY.md, VAmPI row 9.
VAmPI's own documentation doesn't name an endpoint or mechanism for its "JWT weak signing key" vulnerability — there's nothing to verify against without guessing at what the target's own docs meant. This isn't a tool gap; it's a documentation gap on VAmPI's side, similar in spirit to the 🚫 Not in Scope items added in #113, but for a different reason (target-side ambiguity rather than tool-category mismatch).
Worth deciding whether this gets its own explicit tag/note distinguishing "we can't verify because the target never told us what to check" from a genuine miss, so the 58-item ceiling is understood accurately rather than implying all 58 are equally closeable.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with docs/TRACEABILITY.md and inspect VAmPI row 9, then compare the proposed distinction with the Not in Scope items added in #113. Determine whether the existing documentation supports a separate tag or note for target-side ambiguity; done means the classification decision and its traceability wording are recorded.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100