Researcher finds 13 vulnerabilities in OWASP Juice Shop, files zero issues — intentionally
A security researcher identified 13 vulnerabilities in OWASP Juice Shop v20.2.0, including SQL injection, eval misuse, wildcard CORS, and a hardcoded JWT RSA key, mapped against ASVS requirements with exact file locations. An additional 11 findings were catalogued in WebGoat under similar categories. Despite the volume and specificity of findings, the researcher deliberately chose not to file any issues against either project. Both Juice Shop and WebGoat are intentionally insecure applications maintained by OWASP as training labs, meaning their vulnerabilities are features, not gaps. The researcher argues that submitting findings against purpose-built vulnerable apps conflates volume with value, and that the real skill is knowing which findings warrant action in production codebases.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in